Hello everybody, I am looking for an advice regarding IPSec throughput on ASR1102-HX. According to datasheet about ESP, the router can do up to 39Gbps IPSec with integrated ESP (ESP100 sort-of) see table 15: https://www.cisco.com/c/en/us/products/collateral/routers/asr-1000-series-aggregation-services-routers/datasheet-c78-731640.html
According to other datasheet, 1002-HX supports embedded hardware-based encryption up to 25Gbps (see table 5): https://www.cisco.com/c/en/us/products/collateral/routers/asr-1000-series-aggregation-services-routers/datasheet-c78-731632.html When I check the router through commerce estimates, for 1002-HX I can order crypto HW module and software licenses: ASR1002HX-IPSECHW - Cisco ASR1002-HX Crypto Module with no default throughput FLSA1-2HXIPS8G - Crypto throughput License for ASR1002-HX 8G FLSA1-2HX8G16G - Crypto throughput upgrade from 8G to 16G for ASR1002-HX FLSA1-2HX8G25G - Crypto throughput upgrade from 8G to 25G for ASR1002-HX Seems to me that you need at least 8G license for HW module to start with. What about declared throughput of 39Gbps for IPSec in the first datasheet? Is it a typo or the integrated ESP can do this throughput on IPSec without crypto HW module? Is the crypto module mandatory? Thank you all for any insight and hands-on experience. Regards/S pozdravom, Miro Sturmankin _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
