logoalt Hacker News

kosolamyesterday at 11:16 PM2 repliesview on HN

How is IPSec performance better than wg? I never heard this before, it sounds intriguing.


Replies

iscoelhoyesterday at 11:34 PM

At this time, there is no commercial offering for hardware/ASIC WireGuard implementations. The standard WireGuard implementation cannot reach 10G.

The fastest I am aware of is VPP (open-source) & Intel QAT [1], which while it is achieves impressive numbers for large packets (70Gbps @ 512 / 200Gbps @ 1420 on a $20k+ MSRP server), is still not comparable with commercial IPsec offerings [2][3][4] that can achieve 800Gbps+ on a single gateway (and come with the added benefit of relying on a commercial product with support).

[1] https://builders.intel.com/docs/networkbuilders/intel-qat-ac...

[2] https://www.juniper.net/content/dam/www/assets/datasheets/us...

[3] https://www.paloaltonetworks.com/apps/pan/public/downloadRes...

[4] https://www.fortinet.com/content/dam/fortinet/assets/data-sh...

show 1 reply
hdgvhicvyesterday at 11:18 PM

If you have an edge device which implements hardware IPsec at 10g+ but pushes WireGuard to software on an underpowered cpu then sure.

show 1 reply