Fast IPsec: a high-performance IPsec implementation

  • Authors:
  • Samuel J. Leffler

  • Affiliations:
  • Errno Consulting

  • Venue:
  • BSDC'03 Proceedings of the BSD Conference 2003 on BSD Conference
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Fast IPsec is an implementation of the IPsec protocols [Kent & Atkinson, 1998a] for FreeBSD that was designed for high performance. In particular the protocols use the OpenBSD Cryptographic Framework, as ported to FreeBSD [Leffler, 2003], so any cryptographic hardware is automatically used to accelerate their operation. Fast IPsec, running on a uniprocessor system with a single Broadcom BCM5822 cryptographic processor, has demonstrated throughput of more than 400 megabits/second when acting as an IPsec terminator. This is more than 50% higher than any other freely available IPsec implementation.