[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: IPSec performance statistics
> Does anyone have metrics for SA setup costs, with and without IKE?
> I've seen claims of about 1 setup (w/out IKE?) per second in
> hardware.
That's really kind of pessimistic.
I'm reluctant to quote exact numbers on a product not yet shipping,
but the IPsec/IKE product I'm currently working on, running without
any specialized hardware, does considerably better than that when the
peers are "close" as the packet flies..
I can readily believe 1 second setup time *including* the IKE exchange
when the round trip time between peers is in the 100-200ms range.
Main mode + quick mode + first-user-traffic winds up being about 5
round trips, so network latency winds up being a dominant factor in
how long it takes to get things flowing..
- Bill
Follow-Ups:
References: