republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Virtual Private Networking » AES vs 3DES on Netgear FVS114
Search Topic:
Uniqs:
194
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
VPN tunnel issues with BT »
AuthorAll Replies

genekoh

join:2009-05-18
australia

AES vs 3DES on Netgear FVS114

Hi there

I've read up on AES vs 3DES encryption. Most of the articles that I have found suggest AES throughput would be greater than 3DES. Obviously this is still dependent on your hardware.

I decided that I would test this on the spare equipment we have at work. The setup involves 2 Netgear FVS114 units (to create the VPN tunnel) with a notebook at either end.

I used Qcheck to check for TCP throughput and ping. Here are the results that I obtained which was quite surprising considering what I have been reading.

3DES (SHA1) - It's 3DES as I skipped DES altogether
Ping Ave: 3ms
Throughput: 7.2Mbps

AES128 (SHA1)
Ping Ave: 5ms
Throughput: 1.7Mbps

AES192 (SHA1)
Ping Ave: 5ms
Throughput: 1.5Mbps

AES256(SHA1)
Ping Ave: 6ms
Throughput: 1.3Mbps

I am assuming that the Netgear FVS114 units are extremely bad at AES but this is purely an assumption. Can anyone shed any light on the Netgear FVS114 AES results? Thanks. Gene

rjs1003

join:2002-12-04
united kingd

I don't know but I can make an educated guess:

You are correct that 3DES encryption is more difficult to compute than AES... however, a lot of devices don't compute the encryption using their main processor - they offload the encryption to a specialist crypto chip. My guess is that (true for a lot of older routers) the crypto chip on that unit only supports DES & 3DES... therefore when you do either of those, it'll run at a reasonable speed (and probably the same speed for both DES & 3DES)...
AES is not supported by the crypto chip, so it has to be computed in the router's main processor and so not only goes slower but also slows down the stronger the encryption (and probably also slows down other routed traffic too if encryption is being used).

Having said all that, even your 3DES performance isn't great. If it has hardware acceleration it's pretty poor if it can't manage 20-30Mbps... so perhaps netgear just use very weedy processors!

Bob
-
Forums » Up and Running » Virtual Private NetworkingVPN tunnel issues with BT »


Friday, 27-Nov 15:47:32 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [119] Time Warner Cable Fires Broadside At Broadcasters
· [109] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [70] TiVo Sees Record Customer Losses
· [68] In-Flight Internet Headed For Bumpy Landing?
· [60] Thanksgiving Open Thread
· [44] Verizon CEO: Hulu Will Be Dead Soon
· [38] EFF Wages War On Fine Print
· [38] ICANN Slams DNS Redirection
Most people now reading
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Newegg Black Friday Sale started [Users Find Hot Deals]
· SSD [Computer Hardware Discussion/Reviews]
· Windows 7 boot manager editing questions [Microsoft Help]
· Bell Response to PIPEDA Request [TekSavvy]
· Bell offering 175M service :) [TekSavvy]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Leveling to 85 [World of Warcraft]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· Question for DSL Co CEO's - Competition Bureau do u use it? [Canadian Broadband]