4 ms·
Very new Xeon at 3.5GHz. 5.75gbps. Kernel Wireguard is almost 3gbps. But Wireguard is mostly held back by the slow crypto implementation, which is CPU-bound.
by gonzo 5y ago
Very new Xeon at 3.5GHz. 5.75gbps.
Kernel Wireguard is almost 3gbps.
But Wireguard is mostly held back by the slow crypto implementation, which is CPU-bound.
AES-GCM IPsec on the same hardware is 19.5gbps, limited by the 25gbps NIC, using again, single-stream iperf with ipsec in VPP.
DPDK only needs dedicated cores for the poll mode drivers, and these days the Intel and mellanox NICs can be run in interrupt mode.
- SigmundA 5y agoI thought interrupt mode reduced performance, that was the tradeoff, is the throughput your quoting in interrupt or polling mode? Good numbers either way, but you again much more limited hardware support since the drivers need to be DPDK specific.
- gonzo 5y agoYou can also run VPP over AF_PACKET (slower, but faster than the kernel) of AF_XDP (almost as fast as DPDK interrupt mode.) But Wireguard is still crypto-limited, the AES-GCM result proves it.
- SigmundA 5y agoWireguard isn't doing to bad considering its not hardware accelerated like AES-GCM. Also looks like AF_PACKET and AF_XDP are basically an alternative to DPDK with similar functionality but built into the kernel using kernel drivers, new to me.