I'm terminating IPsec tunned in a VM. VM is assigned a VF from Intel X520.
Is it possible to offload IPsec computations on a VF? or is there any other way to offload the IPsec from a VM directly to physical NIC card (Intel X520)
Can you please point me to a relevant documentation to help on this mater.
Any help would be appreciated.--Thanks,Ali
Thank you for posting in Wired Communities. What is the exact X520 NIC you have? Please provide the exact model and operating systems. I will have to check on this.
Followings are the details of hw/sw I'm using.
- Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection (rev 01)
- Host Ubuntu Version: Ubuntu 17.04
- Host IXGBE driver version: 5.2.3
- Guest Ubuntu Version: Ubuntu 17.04
- Guest IXGBEVF driver version: 4.2.1
- Host Kernel version: 4.10.0-33-generic
- Guest Kernel version: 4.10.0-33-generic
Any help will be appreciated.
As an additional information. The Windows 2012 Hyper-V supports virtual
machine offloading the IPsec processing to the NIC on the host. Here are the steps
Start Device Manager.
Click Start, click Control Panel, click Hardware and Sound, and then click Device Manager.
In Device Manager, expand Network adapters, and then double-click the adapter that you want to check.
On the Properties dialog box, click the Advanced tab.
If IPsecOffloadV2 appears in the Property list, then the network adapter supports IPsec task offload.
As you are using Ubuntu, please check with Ubuntu support the process of offloading the IPsec processing to the physical NIC on the host.