Re: [IPsec] Discussion about solving ESP limitations with parallel processing, handling QoS classes etc.

2022-10-27 Thread Christian Hopps
I'm interested and would attend. Thanks, Chris. Steffen Klassert writes: Hi, over the last years, quite some work was done from different parties to overcome some limitations of ESP to handle parallel datapaths, QoS classes etc. Chronologically ordered, we have: November 2019: https://da

Re: [IPsec] Discussion about solving ESP limitations with parallel processing, handling QoS classes etc.

2022-10-27 Thread Paul Ponchon (pponchon)
Hello Steffen, Thanks for sharing these references. I would be very interested in discussing these matters during the next meeting. We have only been following the group activity since very recently, so please apologize us if the new ipsecme-anti-replay-subspaces ID felt like yet-another propo

Re: [IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance

2022-10-27 Thread Paul Ponchon (pponchon)
Hi, Tero Kivinen writes: > [Replying to this email, but commenting about the others also] > > Paul Wouters writes: > > On Oct 21, 2022, at 03:37, Steffen Klassert > > mailto:steffen.klass...@secunet.com>> wrote: > > > Another possibility would be to use the same keymat on all > > > percpu SAs > >

Re: [IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance

2022-10-27 Thread Paul Wouters
On Oct 27, 2022, at 08:40, Paul Ponchon (pponchon) wrote: > >  > > Is this requirement only based on not reusing the same IV on different cores > or is there an additional factor I missed? For AES-GCM there is a 2^32 max operations per private key as well. > > We're are currently facing s

Re: [IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance

2022-10-27 Thread Valery Smyslov
HI Tero, > In your discussion you were talking about cases where one device has > hundreds of cpus and other have few. Only case where such > configurations would be useful when other has lots of really low > powered cpus and other one has few very fast ones. My understanding is > that this is not