RedHat has published the results of performance testing for IPsec.

Red Hat has published the results of benchmarking the performance of encrypted communication channels established using the IPsec protocol on modern hardware, comparing the throughput of IPsec based on AES-GCM and AES-SHA1 authenticated encryption algorithms.

The testing was conducted in RHEL 9.4 on a server equipped with two 4th generation Intel Xeon Scalable processors (28 cores and 56 logical cores per CPU), connected to the network via a 100-gigabit Intel E810 network adapter. Hardware acceleration for IPsec via offloading operations to the network card or Intel QAT was disabled to provide insights into the performance of the software stack. The system settings were configured according to the 'throughput-performance' profile, the firewalld firewall was disabled, and the iperf3 traffic generation process and the network card's interrupt handler were pinned to the first CPU core (to avoid performance degradation caused by the migration of interrupt handlers to NUMA nodes unrelated to the network card).

In a single-threaded test of IPsec for both IPv4 and IPv6 using one CPU core for the iperf3 process, a performance of 6 Gbit/s was observed for AES-GCM and 3.75 Gbit/s for AES-SHA1, indicating that AES-SHA1 was approximately 40% slower than AES-GCM.
During testing with multiple parallel streams (each iperf3 instance was attached to a separate CPU core), the peak throughput using AES-GCM reached 50 Gbit/s for both IPv4 and IPv6, demonstrating the capability to fully utilize the available bandwidth on a typical server system with two 25-gigabit or one 40-gigabit link without the use of hardware acceleration (or half the throughput of the 100-gigabit link used during testing).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster