[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IPSec performance statistics



> Does anyone have metrics for SA setup costs, with and without IKE?
> I've seen claims of about 1 setup (w/out IKE?) per second in
> hardware.

That's really kind of pessimistic.  

I'm reluctant to quote exact numbers on a product not yet shipping,
but the IPsec/IKE product I'm currently working on, running without
any specialized hardware, does considerably better than that when the
peers are "close" as the packet flies..

I can readily believe 1 second setup time *including* the IKE exchange
when the round trip time between peers is in the 100-200ms range.

Main mode + quick mode + first-user-traffic winds up being about 5
round trips, so network latency winds up being a dominant factor in
how long it takes to get things flowing..

						- Bill


Follow-Ups: References: