netmap in GENERIC, by default, on HEAD

Eric L. Camachat eric.camachat at gmail.com
Wed Nov 5 16:07:00 UTC 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On 11/05/2014 07:52, Andrey V. Elsukov wrote:
> On 05.11.2014 18:39, George Neville-Neil wrote:
>> Howdy,
>>
>> Last night (Pacific Time) I committed a change so that GENERIC, on HEAD
>> has the netmap
>> device enabled.  This is to increase the breadth of our testing of that
>> feature prior
>> to the release of FreeBSD 11.
>>
>> In two weeks I will enable IPSec by default, again in preparation for 11.
> 
> Hi,
> 
> recently we did some IP forwarding tests and the GENERIC kernel is
> several times faster than GENERIC+IPSEC. Even when IPSEC has no SA.
> 
> I didn't do test on vanilla kernel, but our kernel is able forward
> IPv4/IPv6 on rate close to 8.6 Mpps. The same kernel compiled with IPSEC
> can forward only 180 kpps. I think this problem should be solved before
> enabling it in GENERIC.
> 
I think this is why we need IPSEC in GENERIC to let more tests involved.
Maybe it also helps in kernel SSL encryption (key per IP vs per TCP
session).

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iF4EAREIAAYFAlRaSyIACgkQSfBQu3oOwYwdfQEAvlvDjlH489YP7n7PYKkLbOfX
5Ew7+VdiJAC7BBkxnSwA/2y2V2sakpdPzlxEt5O4oQbKEmBUa40W7CU3gBzgJjTw
=EHh4
-----END PGP SIGNATURE-----


More information about the freebsd-net mailing list