A kernel module has been introduced that can significantly speed up OpenVPN.

The developers of the OpenVPN package for creating virtual private networks have introduced the ovpn-dco kernel module, significantly enhancing VPN performance. Although the module is still being developed with a focus only on the linux-next branch and carries an experimental status, it has already achieved a level of stability that permits its use in the OpenVPN Cloud service.

Compared to a configuration based on the tun interface, using the module on both the client and server side with the AES-256-GCM cipher has resulted in an eightfold increase in throughput (from 370 Mbit/s to 2950 Mbit/s). When using the module solely on the client side, the outgoing traffic throughput increased threefold, while the incoming traffic remained unchanged. When applying the module only on one side, server the throughput increased fourfold for incoming traffic and by 35% for outgoing traffic.

A kernel module has been introduced that can significantly speed up OpenVPN.

The acceleration is achieved by offloading all encryption operations, packet processing, and channel management to the Linux kernel, eliminating the overhead associated with context switching, optimizing performance through direct access to the kernel's internal APIs, and avoiding slow data transfer between the kernel and user space (encryption, decryption, and routing are performed by the module without sending traffic to the user space handler).

It is noted that the negative impact on performance VPN is primarily due to resource-intensive encryption operations and delays caused by context switching. To accelerate encryption, processor extensions such as Intel AES-NI were utilized, but context switching remained a bottleneck until the advent of ovpn-dco. In addition to leveraging the processor's instructions for speeding up encryption, the ovpn-dco module has also implemented the division of encryption operations into separate segments and their processing in a multithreaded mode, allowing all available CPU cores to be utilized.

Among the current implementation limitations, which will be addressed in the future, only AEAD and 'none' (no authentication) modes and the AES-GCM and CHACHA20POLY1305 ciphers are supported. Support for DCO is planned to be included in the release of OpenVPN 2.6, scheduled for the 4th quarter of this year. Currently, the module is undergoing beta testing in the OpenVPN3 Linux client and in experimental builds of the OpenVPN server for Linux. A similar ovpn-dco-win module is also being developed for the Windows kernel.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster