4 ms·
>and much faster to connect and has excellent latency and bandwidth I have my own ipsec deployment and this argument always seems shaky to me. Here is how lon
by puzzlingcaptcha 7y ago
>and much faster to connect and has excellent latency and bandwidth
I have my own ipsec deployment and this argument always seems shaky to me.
Here is how long it takes to establish ipsec connection on my laptop:
https://streamable.com/27des https://streamable.com/27des
The cipher suite used is aes256gcm16-prfsha384-ecp384 for IKE and aes256gcm16-ecp384 for ESP which is in line with CNSA https://apps.nsa.gov/iaarchive/programs/iad-initiatives/cnsa-suite.cfm https://apps.nsa.gov/iaarchive/programs/iad-initiatives/cnsa... I'm using Strongswan which I highly recommend mostly due to their comprehensive set of tests for virtually every scenario https://www.strongswan.org/testing/testresults/ https://www.strongswan.org/testing/testresults/
I did not see any meaningful difference in bandwidth between ipsec and wireguard. As a bonus, ipsec is natively supported by Windows 10.
I don't use OpenVPN which I think is worse in that regard due to packet shuffling between the kernel and userspace but between ipsec and wireshark the only discernible difference for me is the effort in setting it up.