Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Virtual Private Networking » AES vs 3DES on Netgear FVS114
Search Topic:
Uniqs:
199
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
VPN tunnel issues with BT »
AuthorAll Replies

genekoh

join:2009-05-18
australia

AES vs 3DES on Netgear FVS114

Hi there

I've read up on AES vs 3DES encryption. Most of the articles that I have found suggest AES throughput would be greater than 3DES. Obviously this is still dependent on your hardware.

I decided that I would test this on the spare equipment we have at work. The setup involves 2 Netgear FVS114 units (to create the VPN tunnel) with a notebook at either end.

I used Qcheck to check for TCP throughput and ping. Here are the results that I obtained which was quite surprising considering what I have been reading.

3DES (SHA1) - It's 3DES as I skipped DES altogether
Ping Ave: 3ms
Throughput: 7.2Mbps

AES128 (SHA1)
Ping Ave: 5ms
Throughput: 1.7Mbps

AES192 (SHA1)
Ping Ave: 5ms
Throughput: 1.5Mbps

AES256(SHA1)
Ping Ave: 6ms
Throughput: 1.3Mbps

I am assuming that the Netgear FVS114 units are extremely bad at AES but this is purely an assumption. Can anyone shed any light on the Netgear FVS114 AES results? Thanks. Gene

rjs1003

join:2002-12-04
united kingd

I don't know but I can make an educated guess:

You are correct that 3DES encryption is more difficult to compute than AES... however, a lot of devices don't compute the encryption using their main processor - they offload the encryption to a specialist crypto chip. My guess is that (true for a lot of older routers) the crypto chip on that unit only supports DES & 3DES... therefore when you do either of those, it'll run at a reasonable speed (and probably the same speed for both DES & 3DES)...
AES is not supported by the crypto chip, so it has to be computed in the router's main processor and so not only goes slower but also slows down the stronger the encryption (and probably also slows down other routed traffic too if encryption is being used).

Having said all that, even your 3DES performance isn't great. If it has hardware acceleration it's pretty poor if it can't manage 20-30Mbps... so perhaps netgear just use very weedy processors!

Bob
-
Forums » Up and Running » Virtual Private NetworkingVPN tunnel issues with BT »


Sunday, 29-Nov 04:18:14 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [73] Weekend Open Thread
· [72] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· So where do we level weapon skill now? [World of Warcraft]
· Blue Ray: Samsung BD-P3600 or LG BD390 [Audio/Video Chat]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· 3.2 Mage PVE [World of Warcraft]
· [Beta] Office 2010 Beta (Wow) [Microsoft Help]
· Child Porn Laws - The Traci Lords Argument [Canadian Chat]
· 1.6.2 Upgrade Thread [Verizon FIOS TV]