> I don't see the point with setting kern.usercrypto=1, all support for enc/dec > you get already from the hw+kernel. > IPSec stack already used the HW if supported, else you get software based > enc/dec. > > //mxb
I replied to my original email about 45 seconds after I wrote it, pointing that out. I also mentioned that my speed testing was done with OpenVPN, which is where that is advantageous. I also checked the aes enc type in the man page and found that he was already using aes-128 (I figured it would default to 256).