3n-skx-xxv710

25ge2p1xxv710-avf-ethip4ipsec10000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  2.64       1.78 

3. 27 85 185 27 78 173
4. 120 228 286 92 217 242
5. 223 301 373 212 292 344

 1518b-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.80       9.88 

3. 58 100 190 58 99 190
4. 321 741 778 311 738 774
5. 898 1072 1197 831 1112 1221

 imix-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.72       5.15 

25ge2p1xxv710-avf-ethip4ipsec10000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.40       1.61 

3. 27 76 176 26 73 175
4. 132 272 357 132 274 321
5. 269 323 410 247 310 376

 1518b-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.70       8.60 

3. 50 78 165 50 75 165
4. 309 712 748 284 641 739
5. 993 1238 1338 979 1227 1330

 imix-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.61       4.82 

25ge2p1xxv710-avf-ethip4ipsec10000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.87       2.60 

3. 26 82 161 24 68 131
4. 57 147 175 57 150 179
5. 150 197 225 135 185 206

 1518b-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.56      19.24 

3. 28 63 97 28 60 93
4. 127 328 376 125 301 363
5. 294 396 439 282 390 434

 imix-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.89       8.64 

25ge2p1xxv710-avf-ethip4ipsec10000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.74       2.52 

3. 26 83 147 25 76 135
4. 82 179 207 83 181 206
5. 145 202 228 136 192 213

 1518b-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.34      16.44 

3. 29 59 94 28 55 88
4. 150 453 551 139 439 523
5. 393 499 556 378 489 553

 imix-2t1c-avf-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.64       7.89 

25ge2p1xxv710-avf-ethip4ipsec1000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  2.80       1.88 

3. 27 74 180 26 70 98
4. 164 285 304 155 276 297
5. 221 289 339 218 291 353

 64b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  5.46       3.67 

3. 28 111 133 27 98 123
4. 108 165 181 93 130 167
5. 183 230 280 138 173 205

 64b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2. 10.86       7.30 

3. 31 62 83 28 69 85
4. 62 79 93 55 78 89
5. 134 169 203 129 166 207

 1518b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.81      10.00 

3. 59 130 195 58 95 175
4. 315 737 793 301 716 787
5. 887 1080 1190 888 1066 1175

 1518b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.61      19.83 

3. 59 121 166 58 114 165
4. 188 354 435 177 348 408
5. 413 525 608 392 494 575

 1518b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.18      39.11 

3. 60 115 140 59 114 131
4. 135 202 235 140 199 233
5. 330 396 450 331 394 447

 imix-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.79       5.34 

 imix-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.53      10.56 

 imix-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  7.06      21.13 

25ge2p1xxv710-avf-ethip4ipsec1000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.49       1.68 

3. 27 84 183 26 74 178
4. 133 252 287 128 246 281
5. 242 315 384 213 288 332

 64b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  4.87       3.27 

3. 28 95 124 27 93 121
4. 97 150 178 73 142 158
5. 167 204 248 148 180 205

 64b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  9.87       6.63 

3. 24 36 50 23 33 42
4. 63 91 103 61 89 98
5. 116 146 172 110 137 169

 1518b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.71       8.73 

3. 50 116 176 49 72 157
4. 296 706 750 260 653 733
5. 928 1197 1301 931 1201 1310

 1518b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.41      17.30 

3. 51 92 140 50 88 130
4. 214 373 460 211 372 465
5. 384 497 565 371 479 540

 1518b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.77      34.13 

3. 51 92 114 50 89 108
4. 127 175 196 128 172 193
5. 251 312 374 249 306 366

 imix-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.67       5.00 

 imix-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  3.30       9.87 

 imix-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  6.54      19.57 

25ge2p1xxv710-avf-ethip4ipsec1000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.22       2.84 

3. 25 80 145 25 76 144
4. 113 179 194 82 175 188
5. 116 170 200 111 164 195

 64b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  8.13       5.47 

3. 24 63 98 20 27 31
4. 100 109 117 92 101 108
5. 105 135 163 84 110 125

 64b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 17.11      11.50 

3. 28 40 52 28 37 49
4. 42 58 66 40 55 62
5. 76 98 120 69 91 114

 1518b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.69      20.74 

3. 28 66 113 27 61 96
4. 147 290 330 124 297 329
5. 321 442 504 313 420 514

 1518b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.27      40.26 

3. 29 61 79 26 56 75
4. 67 117 135 62 115 131
5. 150 175 195 136 160 180

 1518b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.83      47.10 

3. 31 40 52 31 40 48
4. 37 70 79 44 66 73
5. 62 73 82 61 69 75

 imix-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.24       9.69 

 imix-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  6.47      19.34 

 imix-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 12.70      37.99 

25ge2p1xxv710-avf-ethip4ipsec1000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  4.11       2.76 

3. 25 81 139 24 75 145
4. 124 195 207 101 190 208
5. 135 192 216 137 193 222

 64b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  7.70       5.18 

3. 25 43 82 20 30 51
4. 31 72 102 30 51 72
5. 109 139 170 81 108 121

 64b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 16.52      11.10 

3. 28 47 57 28 46 58
4. 52 59 64 50 60 67
5. 75 96 118 68 89 108

 1518b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.42      17.44 

3. 28 61 105 28 58 82
4. 210 384 447 164 381 459
5. 380 478 538 373 469 529

 1518b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.71      33.37 

3. 29 56 78 29 52 65
4. 66 146 159 67 141 151
5. 158 194 220 152 191 218

 1518b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.83      47.10 

3. 31 45 60 31 42 51
4. 39 75 86 44 72 79
5. 67 79 90 66 75 84

 imix-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.01       9.00 

 imix-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.07      18.16 

 imix-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 11.83      35.39 

25ge2p1xxv710-avf-ethip4ipsec1000tnlsw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.76       0.51 

3. 34 49 155 33 48 170
4. 297 830 1224 250 759 1144
5. 935 1510 1810 877 1412 1791

 64b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.52       1.02 

3. 33 43 123 33 45 119
4. 88 301 464 74 283 462
5. 314 489 592 304 504 629

 64b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  3.01       2.02 

3. 32 103 223 31 87 196
4. 99 253 341 93 242 335
5. 293 446 554 271 423 525

 1518b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.49       6.01 

3. 62 119 203 61 70 156
4. 324 675 883 327 701 932
5. 1268 1780 2315 1347 1949 2517

 1518b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.98      12.08 

3. 63 133 233 61 106 204
4. 363 796 1012 357 764 1000
5. 686 962 1239 674 947 1221

 1518b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.91      23.45 

3. 63 121 172 62 113 163
4. 172 336 435 181 340 440
5. 372 511 631 368 502 614

 imix-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.66       1.96 

 imix-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.32       3.96 

 imix-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  2.62       7.84 

25ge2p1xxv710-avf-ethip4ipsec1000tnlsw-ip4base-policy-aes128cbc-hmac512sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.74       0.50 

3. 33 63 147 31 36 111
4. 304 822 1218 263 770 1147
5. 965 1478 1845 1007 1591 1931

 64b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.48       1.00 

3. 33 83 206 33 83 208
4. 145 437 653 131 443 687
5. 534 901 1136 502 849 1046

 64b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  2.92       1.96 

3. 31 88 207 31 84 203
4. 102 254 331 111 263 349
5. 255 414 517 255 422 528

 1518b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.45       5.55 

3. 54 103 181 52 60 127
4. 297 665 869 301 688 911
5. 1345 1972 2595 1237 1791 2339

 1518b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.91      11.17 

3. 54 114 207 53 76 155
4. 278 697 950 246 670 884
5. 696 1071 1331 702 1060 1305

 1518b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.77      21.78 

3. 55 98 146 53 91 141
4. 154 313 407 152 318 420
5. 341 485 599 344 490 604

 imix-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.64       1.92 

 imix-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.29       3.85 

 imix-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  2.56       7.66 

25ge2p1xxv710-avf-ethip4ipsec1000tnlsw-ip4base-policy-aes128gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  0.83       0.55 

3. 26 38 148 26 36 139
4. 267 775 1142 255 764 1164
5. 853 1362 1735 821 1394 1791

 64b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.65       1.11 

3. 27 77 205 27 69 189
4. 160 413 599 133 372 579
5. 471 804 987 441 756 970

 64b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  3.29       2.21 

3. 29 52 138 29 47 132
4. 76 202 290 69 185 276
5. 214 363 468 233 386 498

 1518b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  0.67       8.21 

3. 33 83 168 33 75 153
4. 242 643 878 224 651 903
5. 1076 1634 1966 1032 1557 1837

 1518b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.32      16.28 

3. 31 65 129 30 56 117
4. 111 469 650 108 471 653
5. 461 696 866 471 699 878

 1518b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  2.55      31.38 

3. 33 63 105 32 56 98
4. 67 187 272 62 190 275
5. 196 296 369 198 300 380

 imix-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  0.77       2.29 

 imix-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.57       4.70 

 imix-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  3.11       9.29 

25ge2p1xxv710-avf-ethip4ipsec1000tnlsw-ip4base-policy-aes256gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  0.82       0.55 

3. 26 85 208 26 39 135
4. 264 783 1170 240 755 1203
5. 859 1396 1768 907 1454 1790

 64b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.63       1.09 

3. 27 68 201 27 67 200
4. 155 413 598 84 347 560
5. 471 808 1006 452 767 970

 64b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  3.26       2.19 

3. 29 73 202 29 57 165
4. 89 225 323 84 217 313
5. 254 420 530 250 416 530

 1518b-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  0.63       7.77 

3. 34 64 130 33 40 100
4. 248 653 931 238 653 928
5. 1194 1707 2123 1186 1703 2093

 1518b-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.24      15.20 

3. 31 53 112 30 39 106
4. 157 489 697 160 501 712
5. 456 708 897 487 738 923

 1518b-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  2.42      29.80 

3. 33 61 106 32 52 97
4. 79 193 289 72 186 277
5. 203 309 391 197 307 384

 imix-2t1c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  0.75       2.25 

 imix-4t2c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.54       4.61 

 imix-8t4c-avf-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  3.04       9.09 

25ge2p1xxv710-avf-ethip4ipsec1tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.66       2.46 

3. 28 101 202 26 95 191
4. 126 221 255 132 219 243
5. 206 265 299 208 264 296

 64b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.72       2.50 

3. 29 58 124 28 56 126
4. 78 139 175 87 140 177
5. 195 234 264 196 236 273

 64b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.71       2.50 

3. 31 95 196 30 95 186
4. 123 214 245 128 219 249
5. 198 258 301 197 258 285

 1518b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.84      10.34 

3. 57 127 187 57 94 127
4. 287 719 746 283 698 742
5. 705 886 923 710 898 938

 1518b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.84      10.37 

3. 57 131 203 58 94 185
4. 305 722 752 283 680 745
5. 731 912 949 700 885 931

 1518b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.85      10.48 

3. 58 129 181 57 101 177
4. 290 681 736 284 640 753
5. 640 850 996 648 785 845

 imix-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.96       5.86 

 imix-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.97       5.89 

 imix-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  2.10       6.27 

25ge2p1xxv710-avf-ethip4ipsec1tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  3.30       2.22 

3. 27 90 194 26 92 180
4. 128 233 267 121 220 265
5. 216 279 320 218 284 317

 64b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  3.32       2.23 

3. 28 94 174 27 93 177
4. 121 226 262 113 223 268
5. 203 266 304 214 281 320

 64b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  3.47       2.33 

3. 30 88 187 29 91 176
4. 122 222 239 113 220 247
5. 210 267 305 209 268 304

 1518b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.73       8.97 

3. 49 114 177 49 73 155
4. 263 663 717 252 625 710
5. 807 1098 1227 820 1094 1183

 1518b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.73       9.02 

3. 49 112 174 49 76 169
4. 349 666 716 267 623 714
5. 820 1113 1236 790 1086 1227

 1518b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.93      11.39 

3. 49 110 163 49 86 161
4. 387 708 730 285 656 736
5. 567 729 800 544 741 821

 imix-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.83       5.47 

 imix-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.84       5.52 

 imix-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.85       5.53 

25ge2p1xxv710-avf-ethip4ipsec1tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  6.73       4.52 

3. 24 54 93 20 30 49
4. 66 114 138 65 113 133
5. 119 144 158 115 141 157

 64b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  6.78       4.55 

3. 26 65 107 23 41 76
4. 68 117 136 71 119 139
5. 120 146 158 124 148 159

 64b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  6.84       4.60 

3. 29 81 122 28 70 124
4. 67 116 133 66 114 135
5. 129 148 158 128 148 158

 1518b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.97      24.28 

3. 28 64 77 27 61 73
4. 126 284 322 137 277 312
5. 253 317 352 250 318 351

 1518b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.97      24.18 

3. 29 60 76 29 61 78
4. 125 278 313 140 272 300
5. 250 316 351 248 314 347

 1518b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.24      27.55 

3. 32 75 93 31 75 91
4. 141 237 285 139 233 279
5. 252 306 349 256 301 333

 imix-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.36      13.04 

 imix-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.33      12.95 

 imix-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.30      12.85 

25ge2p1xxv710-avf-ethip4ipsec1tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.46       4.34 

3. 25 54 70 24 59 76
4. 79 126 141 78 132 148
5. 119 145 160 118 145 160

 64b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.39       4.29 

3. 27 61 78 26 59 71
4. 76 130 147 74 133 150
5. 122 149 167 126 156 183

 64b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.53       4.39 

3. 29 51 68 28 50 68
4. 71 123 137 70 123 138
5. 120 148 165 123 151 167

 1518b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.56      19.23 

3. 29 60 100 27 57 89
4. 118 323 362 115 314 365
5. 309 411 467 312 413 468

 1518b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.56      19.23 

3. 30 59 108 28 55 100
4. 119 324 366 114 314 365
5. 306 406 464 315 413 468

 1518b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.56      19.23 

3. 32 58 98 31 45 80
4. 118 318 376 91 294 317
5. 269 372 406 214 320 347

 imix-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.87      11.57 

 imix-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.90      11.68 

 imix-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.93      11.75 

25ge2p1xxv710-avf-ethip4ipsec1tnlsw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  3.29       2.21 

3. 27 95 194 31 92 197
4. 123 224 261 120 224 256
5. 212 273 310 214 274 315

 64b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  3.31       2.22 

3. 28 48 81 27 63 82
4. 72 138 173 70 134 167
5. 189 238 269 172 218 250

 64b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  3.29       2.21 

3. 31 93 196 30 91 185
4. 121 231 263 102 217 238
5. 213 272 311 214 276 307

 1518b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.82      10.11 

3. 58 130 191 58 96 188
4. 286 713 738 289 698 744
5. 714 915 955 721 920 976

 1518b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.84      10.28 

3. 57 128 199 57 86 177
4. 381 714 740 290 629 739
5. 750 1001 1025 648 810 846

 1518b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.01      12.40 

3. 57 132 198 58 113 195
4. 326 685 787 325 684 794
5. 573 759 834 583 779 851

 imix-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.86       5.56 

 imix-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.85       5.54 

 imix-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.85       5.53 

25ge2p1xxv710-avf-ethip4ipsec1tnlsw-ip4base-policy-aes128cbc-hmac512sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  3.00       2.02 

3. 27 96 185 26 85 185
4. 110 230 249 111 231 259
5. 237 291 336 209 276 315

 64b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  3.01       2.02 

3. 28 88 183 27 84 177
4. 114 235 258 106 228 259
5. 230 286 329 228 278 320

 64b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  3.02       2.03 

3. 31 48 143 29 48 142
4. 68 156 179 66 165 198
5. 184 216 261 180 212 260

 1518b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.71       8.74 

3. 49 72 160 50 73 159
4. 254 675 709 246 633 704
5. 818 1089 1126 819 1088 1128

 1518b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.71       8.74 

3. 50 102 172 50 75 170
4. 288 674 719 250 604 715
5. 813 1082 1125 822 1087 1130

 1518b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.72       8.89 

3. 50 112 170 49 70 153
4. 326 653 694 256 621 703
5. 678 964 1084 713 951 1034

 imix-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.73       5.18 

 imix-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.75       5.24 

 imix-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.75       5.25 

25ge2p1xxv710-avf-ethip4ipsec1tnlsw-ip4base-policy-aes128gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  5.49       3.69 

3. 25 75 93 24 82 103
4. 92 149 159 89 130 163
5. 123 154 173 122 155 171

 64b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  5.47       3.68 

3. 26 78 116 25 85 107
4. 96 154 163 99 153 166
5. 123 155 173 130 162 187

 64b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  5.48       3.68 

3. 28 74 94 27 78 101
4. 97 155 166 93 132 163
5. 126 157 173 123 156 171

 1518b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.89      23.22 

3. 28 74 121 27 67 107
4. 146 275 310 156 274 301
5. 270 330 371 268 333 367

 1518b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.90      23.34 

3. 29 62 100 28 64 81
4. 118 258 287 142 264 300
5. 233 299 339 242 302 337

 1518b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  2.11      25.90 

3. 29 52 76 30 66 80
4. 115 200 230 128 240 282
5. 193 239 254 228 293 321

 imix-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  3.84      11.49 

 imix-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  3.83      11.45 

 imix-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  3.81      11.40 

25ge2p1xxv710-avf-ethip4ipsec1tnlsw-ip4base-policy-aes256gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  5.33       3.58 

3. 24 106 133 23 111 135
4. 72 121 143 64 120 133
5. 130 158 177 130 160 177

 64b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  5.33       3.58 

3. 25 32 40 25 33 46
4. 51 108 122 50 111 130
5. 102 124 140 96 117 134

 64b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  5.27       3.54 

3. 28 118 143 27 118 143
4. 80 126 141 76 122 138
5. 140 164 179 135 162 173

 1518b-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.48      18.27 

3. 28 58 85 27 55 79
4. 126 330 361 116 323 359
5. 301 430 492 305 430 485

 1518b-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.51      18.60 

3. 29 59 81 28 51 75
4. 119 331 373 97 287 355
5. 260 388 423 236 359 384

 1518b-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.51      18.59 

3. 32 52 79 31 57 72
4. 110 295 362 107 327 376
5. 229 351 379 263 393 431

 imix-2t1c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  3.47      10.37 

 imix-4t2c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  3.47      10.39 

 imix-8t4c-avf-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  3.54      10.60 

25ge2p1xxv710-avf-ethip4ipsec20000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  2.42       1.62 

3. 28 82 154 27 77 173
4. 129 276 320 124 274 325
5. 255 309 392 233 310 386

 1518b-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.79       9.67 

3. 58 103 196 58 101 195
4. 347 773 806 337 719 801
5. 847 1098 1232 837 1091 1137

 imix-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.59       4.75 

25ge2p1xxv710-avf-ethip4ipsec20000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.18       1.47 

3. 27 83 180 26 79 178
4. 143 323 389 151 335 405
5. 245 346 390 246 338 385

 1518b-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.67       8.30 

3. 50 75 163 50 74 157
4. 296 719 748 287 712 738
5. 1069 1280 1385 1046 1268 1381

 imix-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.46       4.38 

25ge2p1xxv710-avf-ethip4ipsec20000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.39       2.28 

3. 26 79 151 24 71 168
4. 88 191 231 80 196 234
5. 181 231 268 155 213 252

 1518b-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.40      17.29 

3. 29 61 96 28 56 96
4. 203 391 462 184 384 462
5. 358 457 518 350 441 504

 imix-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.42       7.23 

25ge2p1xxv710-avf-ethip4ipsec20000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.24       2.18 

3. 26 91 159 25 81 177
4. 123 206 255 103 208 237
5. 176 223 260 169 215 246

 1518b-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.19      14.70 

3. 29 54 97 28 50 103
4. 218 459 577 212 464 594
5. 447 601 674 428 588 657

 imix-2t1c-avf-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.21       6.61 

25ge2p1xxv710-avf-ethip4ipsec40000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  2.00       1.35 

3. 28 88 192 27 77 115
4. 149 324 382 119 319 372
5. 278 373 474 263 358 448

 1518b-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.76       9.31 

3. 58 108 198 59 104 199
4. 367 793 832 356 714 828
5. 901 1152 1227 894 1150 1223

 imix-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.37       4.10 

25ge2p1xxv710-avf-ethip4ipsec40000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.80       1.21 

3. 27 82 189 27 76 182
4. 166 358 400 160 341 398
5. 322 430 547 307 420 536

 1518b-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.65       8.05 

3. 50 117 180 50 77 171
4. 338 734 777 316 677 783
5. 1035 1331 1427 1006 1295 1372

 imix-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.27       3.79 

25ge2p1xxv710-avf-ethip4ipsec40000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.68       1.80 

3. 26 81 179 25 74 166
4. 101 210 242 91 206 233
5. 234 304 328 221 295 314

 1518b-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.27      15.57 

3. 29 62 101 28 55 85
4. 196 471 545 175 444 523
5. 412 541 644 392 512 568

 imix-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.98       5.93 

25ge2p1xxv710-avf-ethip4ipsec40000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.50       1.68 

3. 26 92 186 25 79 183
4. 118 243 287 115 244 288
5. 232 311 379 216 294 346

 1518b-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.10      13.54 

3. 29 57 114 28 50 95
4. 246 553 642 219 518 588
5. 481 666 762 470 638 742

 imix-2t1c-avf-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.83       5.48 

25ge2p1xxv710-avf-ethip4ipsec400tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  2.96       1.99 

3. 27 84 188 26 84 184
4. 126 247 278 131 251 271
5. 218 274 315 206 273 317

 64b-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  5.95       4.00 

3. 28 122 152 25 64 143
4. 85 133 150 80 136 149
5. 170 216 261 125 156 181

 64b-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2. 11.70       7.86 

3. 31 79 98 30 68 95
4. 66 90 101 63 88 98
5. 148 190 232 136 180 229

 1518b-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.82      10.04 

3. 59 171 193 58 96 187
4. 342 731 781 298 720 775
5. 888 1118 1175 888 1093 1179

 1518b-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.63      20.03 

3. 59 119 172 58 110 158
4. 185 354 412 161 351 408
5. 412 524 611 395 503 595

 1518b-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.22      39.67 

3. 59 115 137 58 113 129
4. 128 195 234 129 194 236
5. 315 375 424 316 375 426

 imix-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.83       5.48 

 imix-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.69      11.03 

 imix-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  7.30      21.84 

25ge2p1xxv710-avf-ethip4ipsec400tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.59       1.74 

3. 27 101 182 26 74 178
4. 124 234 266 111 235 260
5. 241 312 379 227 302 355

 64b-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  5.30       3.56 

3. 28 114 144 27 112 136
4. 97 137 160 90 130 151
5. 152 183 213 134 165 188

 64b-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2. 10.73       7.21 

3. 30 64 81 29 70 84
4. 59 82 97 53 79 89
5. 125 163 210 116 150 187

 1518b-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.71       8.74 

3. 51 159 180 50 151 181
4. 299 705 759 259 628 733
5. 907 1177 1283 900 1169 1273

 1518b-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.40      17.20 

3. 51 93 148 50 76 179
4. 207 367 454 165 387 514
5. 377 490 563 385 549 651

 1518b-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.80      34.50 

3. 51 92 144 50 89 115
4. 130 171 200 127 169 196
5. 248 304 363 236 292 346

 imix-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.71       5.11 

 imix-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  3.42      10.23 

 imix-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  6.86      20.53 

25ge2p1xxv710-avf-ethip4ipsec400tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.65       3.13 

3. 25 136 145 24 121 132
4. 88 161 173 79 159 174
5. 165 184 208 156 173 189

 64b-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  9.41       6.32 

3. 25 53 72 20 59 76
4. 65 86 96 62 83 91
5. 90 109 127 75 92 104

 64b-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 18.39      12.36 

3. 28 39 53 28 40 53
4. 41 55 62 41 56 64
5. 84 112 142 79 109 142

 1518b-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.73      21.27 

3. 28 68 104 28 64 90
4. 155 278 309 155 278 300
5. 312 401 470 301 390 448

 1518b-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.38      41.58 

3. 29 60 77 29 55 69
4. 67 118 136 67 111 127
5. 152 180 203 129 150 167

 1518b-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.83      47.10 

3. 31 40 50 31 40 49
4. 39 65 71 39 64 70
5. 59 67 74 59 66 72

 imix-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.50      10.45 

 imix-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  7.16      21.40 

 imix-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 13.96      41.76 

25ge2p1xxv710-avf-ethip4ipsec400tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  4.54       3.05 

3. 25 90 142 24 86 153
4. 90 169 192 86 161 186
5. 177 196 219 107 163 187

 64b-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  9.13       6.14 

3. 25 69 95 20 41 57
4. 62 94 103 56 86 94
5. 106 122 143 71 98 109

 64b-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 18.13      12.18 

3. 28 44 60 28 41 56
4. 42 58 67 40 56 65
5. 89 119 149 75 98 124

 1518b-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.41      17.36 

3. 28 63 103 28 57 91
4. 191 373 430 165 364 429
5. 360 463 531 351 453 522

 1518b-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.79      34.33 

3. 29 56 79 29 51 65
4. 88 134 147 83 130 141
5. 161 200 232 147 185 212

 1518b-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.83      47.10 

3. 31 44 57 31 42 50
4. 39 71 79 41 70 79
5. 64 74 82 64 73 81

 imix-2t1c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.21       9.61 

 imix-4t2c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.65      19.88 

 imix-8t4c-avf-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 11.24      33.61 

25ge2p1xxv710-avf-ethip4ipsec40tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.36       2.26 

3. 28 107 200 27 98 187
4. 116 218 255 110 220 259
5. 230 279 329 213 269 306

 64b-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  5.81       3.91 

3. 28 42 74 24 37 63
4. 79 132 168 72 126 166
5. 130 166 203 134 185 220

 64b-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2. 11.07       7.44 

3. 31 56 70 30 55 73
4. 64 89 99 64 90 101
5. 122 151 169 120 183 230

 1518b-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.83      10.20 

3. 58 129 190 58 95 188
4. 316 724 757 290 699 748
5. 793 943 1056 786 936 1042

 1518b-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.66      20.42 

3. 55 124 178 54 107 131
4. 193 341 383 179 330 372
5. 402 517 614 394 509 608

 1518b-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.29      40.46 

3. 58 116 145 59 114 130
4. 131 197 234 131 193 235
5. 340 396 443 339 397 446

 imix-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.92       5.75 

 imix-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.48      10.42 

 imix-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  4.17      12.49 

25ge2p1xxv710-avf-ethip4ipsec40tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.93       1.97 

3. 27 86 178 26 79 176
4. 128 245 267 133 254 278
5. 211 274 314 194 262 303

 64b-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  4.93       3.31 

3. 28 89 124 27 87 128
4. 61 122 146 54 114 140
5. 124 156 185 125 171 203

 64b-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2. 10.41       7.00 

3. 31 77 93 30 79 92
4. 61 84 95 62 84 95
5. 136 210 342 99 129 157

 1518b-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.72       8.86 

3. 49 109 174 49 68 156
4. 278 676 734 215 616 712
5. 837 1103 1158 835 1095 1153

 1518b-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.43      17.62 

3. 49 92 140 50 87 130
4. 198 347 437 195 350 441
5. 347 459 517 343 454 509

 1518b-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.02      12.60 

3. 49 72 126 49 54 64
4. 80 425 529 51 143 186
5. 281 461 513 63 168 213

 imix-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.80       5.39 

 imix-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  3.02       9.04 

 imix-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  4.44      13.27 

25ge2p1xxv710-avf-ethip4ipsec40tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  5.72       3.84 

3. 25 49 61 24 45 64
4. 71 129 143 71 130 144
5. 132 161 182 125 154 171

 64b-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  9.41       6.32 

3. 25 50 75 20 57 75
4. 64 88 99 60 80 88
5. 92 120 143 70 86 97

 64b-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 16.29      10.95 

3. 29 42 56 28 36 53
4. 52 60 66 28 40 58
5. 64 96 121 51 64 76

 1518b-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.89      23.28 

3. 29 62 107 27 57 97
4. 94 250 282 102 242 270
5. 240 300 335 233 294 328

 1518b-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.66      44.97 

3. 30 62 74 29 59 71
4. 71 108 121 69 106 117
5. 147 167 183 134 154 170

 1518b-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.83      47.10 

3. 32 43 56 31 41 48
4. 37 66 72 39 64 71
5. 60 68 75 59 66 71

 imix-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.02      12.02 

 imix-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  7.78      23.27 

 imix-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 10.92      32.64 

25ge2p1xxv710-avf-ethip4ipsec40tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  5.59       3.76 

3. 25 54 88 24 57 92
4. 85 144 157 90 145 159
5. 130 166 187 122 161 180

 64b-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  9.48       6.37 

3. 25 43 64 19 51 70
4. 63 86 96 55 79 86
5. 87 108 126 69 87 98

 64b-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 18.55      12.47 

3. 29 36 44 28 36 47
4. 44 56 62 42 54 61
5. 89 120 152 77 101 125

 1518b-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.53      18.87 

3. 28 64 106 28 58 95
4. 132 307 379 124 303 373
5. 324 441 492 312 437 492

 1518b-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.66      20.45 

3. 30 43 91 28 34 57
4. 87 212 240 30 91 114
5. 183 277 326 72 123 170

 1518b-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.83      47.10 

3. 32 41 53 31 42 51
4. 40 72 81 40 69 77
5. 65 76 85 64 73 80

 imix-2t1c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.69      11.04 

 imix-4t2c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  7.19      21.50 

 imix-8t4c-avf-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  8.74      26.13 

25ge2p1xxv710-avf-ethip4ipsec4tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.47       2.33 

3. 28 91 141 26 78 104
4. 123 208 235 102 209 245
5. 225 283 336 215 275 320

 64b-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.57       2.40 

3. 28 33 119 27 55 80
4. 34 125 142 77 174 193
5. 81 134 151 153 205 221

 64b-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.51       2.36 

3. 30 70 160 23 32 43
4. 82 180 196 37 128 149
5. 155 200 220 83 133 150

 1518b-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.84      10.28 

3. 57 128 205 58 96 187
4. 304 714 762 281 665 761
5. 726 921 958 719 913 952

 1518b-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.03      12.72 

3. 57 93 170 58 127 210
4. 162 460 536 350 723 795
5. 315 494 555 672 849 900

 1518b-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.07      13.18 

3. 57 78 148 58 85 158
4. 94 426 495 169 469 517
5. 278 430 492 353 509 564

 imix-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.93       5.77 

 imix-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  2.00       5.98 

 imix-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  4.39      13.13 

25ge2p1xxv710-avf-ethip4ipsec4tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  3.01       2.02 

3. 27 94 178 26 82 181
4. 109 227 261 108 228 257
5. 218 275 311 211 267 311

 64b-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  5.65       3.80 

3. 28 55 88 27 57 71
4. 79 141 156 84 140 154
5. 148 180 212 130 160 184

 64b-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  3.44       2.31 

3. 30 38 117 29 37 127
4. 35 113 127 39 142 157
5. 84 132 153 113 166 177

 1518b-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.72       8.91 

3. 49 99 116 49 93 106
4. 215 428 456 208 429 455
5. 504 637 664 503 636 668

 1518b-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.89      10.89 

3. 49 66 122 49 65 138
4. 51 274 344 144 504 555
5. 143 306 397 402 580 678

 1518b-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.45      17.80 

3. 49 81 114 49 57 69
4. 126 274 360 72 205 269
5. 245 386 446 148 261 310

 imix-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.82       5.45 

 imix-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.86       5.57 

 imix-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.10       6.28 

25ge2p1xxv710-avf-ethip4ipsec4tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  5.99       4.02 

3. 25 107 132 24 102 126
4. 78 121 136 69 130 145
5. 127 154 172 118 151 170

 64b-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 10.67       7.17 

3. 25 56 78 20 59 73
4. 50 75 84 41 68 76
5. 82 101 122 67 84 94

 64b-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  7.23       4.86 

3. 29 47 59 28 55 67
4. 35 75 88 40 83 93
5. 58 80 89 88 105 116

 1518b-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.94      23.87 

3. 29 65 80 27 63 81
4. 143 278 306 144 275 300
5. 261 331 364 254 334 367

 1518b-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.06      25.29 

3. 30 54 90 28 51 85
4. 102 224 252 97 221 248
5. 191 250 280 187 245 285

 1518b-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.83      47.10 

3. 32 40 49 31 49 63
4. 39 61 65 56 85 91
5. 59 64 68 85 96 105

 imix-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.24      12.67 

 imix-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.23      12.65 

 imix-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  8.35      24.96 

25ge2p1xxv710-avf-ethip4ipsec4tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  5.82       3.91 

3. 24 76 119 19 29 67
4. 86 135 155 77 131 149
5. 134 160 181 129 156 171

 64b-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.54       4.39 

3. 26 32 40 26 36 45
4. 30 66 79 48 95 108
5. 50 76 88 90 113 128

 64b-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 11.98       8.05 

3. 29 36 41 28 39 44
4. 36 45 52 43 57 67
5. 58 69 81 111 167 229

 1518b-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.52      18.76 

3. 29 57 83 27 55 75
4. 120 305 367 106 288 361
5. 304 428 470 301 424 472

 1518b-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.68      20.70 

3. 30 51 103 29 36 53
4. 118 238 272 31 96 114
5. 237 333 389 74 138 174

 1518b-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.30      40.58 

3. 32 52 67 31 40 49
4. 60 105 119 40 58 64
5. 105 131 146 58 66 72

 imix-2t1c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.78      11.31 

 imix-4t2c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.85      11.50 

 imix-8t4c-avf-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.67      19.93 

25ge2p1xxv710-avf-ethip4ipsec5000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  2.67       1.80 

3. 28 81 176 27 79 176
4. 129 239 306 104 211 277
5. 218 303 348 214 298 347

 64b-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  5.13       3.44 

3. 28 88 175 28 84 201
4. 96 160 186 73 172 228
5. 187 226 273 215 311 396

 64b-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  9.65       6.49 

3. 29 41 54 30 42 57
4. 70 93 107 67 92 103
5. 132 166 201 132 166 207

 1518b-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.81       9.95 

3. 59 131 193 58 97 189
4. 326 744 799 306 690 781
5. 904 1072 1185 904 1158 1202

 1518b-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.60      19.68 

3. 59 120 166 58 113 166
4. 192 369 432 177 362 430
5. 416 525 597 398 503 572

 1518b-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.10      38.17 

3. 60 116 136 59 114 130
4. 144 216 254 144 211 247
5. 325 384 442 320 379 438

 imix-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.75       5.25 

 imix-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  3.44      10.30 

 imix-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  6.56      19.63 

25ge2p1xxv710-avf-ethip4ipsec5000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.42       1.62 

3. 27 78 177 26 72 171
4. 130 271 311 120 270 315
5. 259 310 380 229 310 378

 64b-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  4.69       3.15 

3. 28 133 171 27 118 166
4. 92 168 186 86 159 174
5. 195 222 258 168 189 213

 64b-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  9.10       6.12 

3. 27 67 105 26 55 99
4. 69 102 112 66 100 113
5. 127 148 184 112 143 165

 1518b-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.70       8.67 

3. 49 103 177 50 76 165
4. 377 711 738 279 691 733
5. 951 1217 1321 981 1219 1327

 1518b-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.40      17.20 

3. 51 91 138 50 85 106
4. 218 381 468 213 383 469
5. 399 516 591 386 500 572

 1518b-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  2.68      33.02 

3. 52 93 135 50 90 123
4. 95 192 207 94 205 222
5. 238 291 336 236 288 335

 imix-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.63       4.88 

 imix-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  3.23       9.65 

 imix-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  6.10      18.25 

25ge2p1xxv710-avf-ethip4ipsec5000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.95       2.66 

3. 25 79 151 25 69 140
4. 65 145 169 52 143 174
5. 147 194 224 128 178 208

 64b-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  7.27       4.88 

3. 26 65 80 25 60 81
4. 58 105 122 57 96 112
5. 103 130 149 86 112 126

 64b-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 14.05       9.44 

3. 29 50 60 29 53 64
4. 46 64 72 42 60 68
5. 79 96 117 78 96 114

 1518b-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.64      20.22 

3. 28 64 107 28 62 89
4. 136 309 341 123 307 348
5. 319 402 468 308 392 459

 1518b-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.20      39.31 

3. 30 61 80 29 57 70
4. 70 126 142 71 121 136
5. 157 185 211 141 168 187

 1518b-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.83      47.10 

3. 32 41 50 31 42 49
4. 40 69 77 40 69 75
5. 63 72 80 63 72 80

 imix-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.03       9.07 

 imix-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  5.93      17.74 

 imix-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 10.95      32.75 

25ge2p1xxv710-avf-ethip4ipsec5000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.86       2.59 

3. 25 73 139 25 68 135
4. 70 153 185 61 156 185
5. 149 197 221 135 187 210

 64b-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  7.42       4.99 

3. 26 60 81 25 58 78
4. 49 95 114 45 92 109
5. 116 146 178 88 116 134

 64b-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 13.80       9.27 

3. 29 59 66 28 62 70
4. 44 64 73 47 67 76
5. 81 100 120 84 103 126

 1518b-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.38      17.02 

3. 29 61 103 28 57 91
4. 191 414 480 181 413 479
5. 383 478 545 374 472 536

 1518b-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.70      33.19 

3. 30 58 77 29 54 71
4. 61 157 173 51 163 175
5. 176 214 242 167 205 231

 1518b-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.83      47.10 

3. 32 45 60 31 44 54
4. 42 77 86 43 77 85
5. 70 82 91 71 82 90

 imix-2t1c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.82       8.43 

 imix-4t2c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  5.52      16.51 

 imix-8t4c-avf-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 10.26      30.67 

25ge2p1xxv710-avf-ethip4ipsec60000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.83       1.23 

3. 28 88 193 28 83 187
4. 185 382 437 186 381 436
5. 312 419 540 311 416 534

 1518b-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  0.74       9.16 

3. 59 140 209 59 109 202
4. 369 789 816 365 788 825
5. 966 1225 1340 1003 1257 1367

 imix-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes128cbc-hmac256sha-ndrpdr

 2.  1.29       3.86 

25ge2p1xxv710-avf-ethip4ipsec60000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.67       1.12 

3. 28 87 192 27 74 182
4. 197 400 470 153 338 428
5. 318 439 524 331 462 536

 1518b-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  0.66       8.09 

3. 50 119 184 51 81 167
4. 365 757 794 334 755 791
5. 1077 1382 1505 1059 1350 1411

 imix-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes128cbc-hmac512sha-ndrpdr

 2.  1.21       3.61 

25ge2p1xxv710-avf-ethip4ipsec60000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.45       1.64 

3. 26 90 188 25 79 183
4. 128 268 312 123 267 307
5. 240 303 345 236 301 353

 1518b-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.22      15.04 

3. 29 60 109 28 53 94
4. 217 440 568 218 451 576
5. 439 571 632 411 554 620

 imix-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.85       5.52 

25ge2p1xxv710-avf-ethip4ipsec60000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.31       1.55 

3. 26 88 185 25 83 183
4. 155 300 346 140 267 309
5. 305 403 470 294 348 441

 1518b-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.07      13.22 

3. 29 58 111 28 49 99
4. 301 573 662 258 558 621
5. 496 668 766 478 641 737

 imix-2t1c-avf-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.71       5.12 

25ge2p1xxv710-ethip4ipsec10000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.50       1.68 

3. 23 81 176 23 78 172
4. 126 247 285 123 242 279
5. 254 333 400 236 313 390

 1518b-2t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.77       9.45 

3. 53 131 194 53 133 195
4. 363 787 832 345 710 822
5. 885 1126 1317 864 1119 1306

 imix-2t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.60       4.77 

25ge2p1xxv710-ethip4ipsec10000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.26       1.52 

3. 23 76 176 22 71 170
4. 115 301 361 116 296 358
5. 292 353 446 280 345 417

 1518b-2t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.66       8.15 

3. 45 80 173 44 77 170
4. 306 725 761 293 713 747
5. 1013 1313 1424 1061 1291 1405

 imix-2t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.51       4.50 

25ge2p1xxv710-ethip4ipsec10000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.55       2.39 

3. 19 73 152 19 51 74
4. 78 171 204 70 163 205
5. 154 208 240 149 199 230

 1518b-2t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.40      17.23 

3. 24 59 77 24 56 76
4. 207 414 519 200 409 505
5. 395 491 554 384 478 533

 imix-2t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.52       7.54 

25ge2p1xxv710-ethip4ipsec10000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.49       2.35 

3. 19 81 164 19 63 159
4. 101 190 224 90 182 206
5. 170 224 262 163 218 254

 1518b-2t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.19      14.66 

3. 25 53 90 24 55 85
4. 216 513 614 211 461 573
5. 461 621 702 448 609 678

 imix-2t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.36       7.05 

25ge2p1xxv710-ethip4ipsec1000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.66       1.79 

3. 23 85 177 23 78 172
4. 149 219 307 110 214 286
5. 247 327 386 235 322 361

 64b-4t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  5.25       3.53 

3. 23 141 172 23 137 169
4. 98 141 164 81 140 160
5. 171 203 247 165 197 233

 64b-8t4c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2. 10.29       6.91 

3. 24 89 100 24 88 99
4. 74 94 105 73 94 103
5. 132 167 201 129 166 200

 1518b-2t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.79       9.68 

3. 53 158 194 53 145 191
4. 351 765 796 336 758 796
5. 835 1042 1235 799 1029 1244

 1518b-4t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.52      18.69 

3. 53 117 178 53 113 171
4. 201 395 485 192 364 460
5. 385 508 574 378 506 571

 1518b-8t4c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.93      35.99 

3. 54 115 148 54 114 141
4. 146 210 261 153 196 258
5. 256 310 350 248 299 340

 imix-2t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.67       4.99 

 imix-4t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.30       9.86 

 imix-8t4c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  6.46      19.32 

25ge2p1xxv710-ethip4ipsec1000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.39       1.61 

3. 23 79 174 22 70 171
4. 134 276 332 122 280 328
5. 287 352 437 262 350 433

 64b-4t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  4.72       3.17 

3. 23 137 166 23 121 155
4. 84 162 179 94 166 186
5. 175 202 231 170 196 224

 64b-8t4c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  9.31       6.26 

3. 23 71 93 23 74 92
4. 74 94 104 73 95 104
5. 113 139 172 111 136 169

 1518b-2t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.68       8.41 

3. 44 114 179 44 82 166
4. 313 711 759 286 654 750
5. 1038 1255 1370 1024 1259 1375

 1518b-4t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.33      16.40 

3. 45 92 154 44 87 132
4. 138 431 520 148 429 502
5. 394 510 604 387 498 587

 1518b-8t4c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.59      31.84 

3. 45 91 135 45 89 126
4. 99 196 220 102 199 227
5. 204 252 288 202 256 291

 imix-2t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.57       4.71 

 imix-4t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  3.08       9.22 

 imix-8t4c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  6.05      18.10 

25ge2p1xxv710-ethip4ipsec1000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.93       2.64 

3. 19 71 142 19 63 158
4. 55 136 165 40 128 158
5. 154 197 224 139 191 220

 64b-4t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  7.73       5.19 

3. 19 39 81 19 38 81
4. 33 69 101 34 57 88
5. 100 126 148 96 123 142

 64b-8t4c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 15.62      10.50 

3. 19 49 71 19 52 74
4. 37 52 63 43 58 68
5. 71 93 115 67 85 105

 1518b-2t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.58      19.44 

3. 24 66 83 24 63 77
4. 144 344 396 138 341 397
5. 346 453 514 342 449 506

 1518b-4t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.87      35.31 

3. 24 62 84 24 59 76
4. 94 125 154 92 122 149
5. 139 175 198 137 172 193

 1518b-8t4c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.83      47.10 

3. 25 51 73 25 47 74
4. 49 74 85 53 75 85
5. 67 77 85 67 78 88

 imix-2t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.91       8.70 

 imix-4t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  5.75      17.19 

 imix-8t4c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 11.09      33.17 

25ge2p1xxv710-ethip4ipsec1000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.88       2.61 

3. 19 71 141 19 60 83
4. 61 148 179 53 145 176
5. 152 207 233 139 194 223

 64b-4t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  7.53       5.06 

3. 19 56 79 19 54 79
4. 43 84 102 50 90 114
5. 105 131 150 95 120 137

 64b-8t4c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 15.09      10.14 

3. 19 41 72 19 41 71
4. 44 61 70 41 60 70
5. 72 90 111 70 91 113

 1518b-2t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.31      16.14 

3. 24 59 83 24 55 75
4. 167 476 588 165 460 564
5. 403 509 572 394 497 555

 1518b-4t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.49      30.59 

3. 24 56 95 24 55 82
4. 82 165 195 78 164 192
5. 161 207 238 157 202 229

 1518b-8t4c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.83      47.10 

3. 25 53 74 25 49 76
4. 50 81 90 54 82 91
5. 74 87 99 75 86 96

 imix-2t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.74       8.20 

 imix-4t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  5.34      15.98 

 imix-8t4c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 10.40      31.11 

25ge2p1xxv710-ethip4ipsec1000tnlsw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.75       0.50 

3. 27 88 191 27 51 134
4. 323 864 1227 295 825 1217
5. 1000 1558 1878 1004 1565 1897

 64b-4t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.48       1.00 

3. 28 72 129 28 72 127
4. 124 340 504 101 324 519
5. 298 472 615 300 478 626

 64b-8t4c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  2.93       1.97 

3. 28 92 204 28 89 205
4. 97 251 330 100 253 336
5. 283 453 569 271 442 550

 1518b-2t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.48       5.85 

3. 57 136 199 57 76 169
4. 327 696 916 315 712 939
5. 1386 2014 2571 1259 1824 2341

 1518b-4t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.94      11.58 

3. 58 131 220 57 113 208
4. 368 757 986 367 749 985
5. 679 970 1255 677 970 1245

 1518b-8t4c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.80      22.12 

3. 58 120 174 58 115 165
4. 173 336 436 172 345 450
5. 361 501 611 356 496 608

 imix-2t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.64       1.92 

 imix-4t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.29       3.85 

 imix-8t4c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  2.52       7.55 

25ge2p1xxv710-ethip4ipsec1000tnlsw-ip4base-policy-aes128cbc-hmac512sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.73       0.49 

3. 27 82 166 26 35 134
4. 318 832 1175 295 817 1170
5. 887 1477 1812 895 1482 1815

 64b-4t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.45       0.98 

3. 27 73 194 27 72 187
4. 163 470 717 158 484 742
5. 431 732 939 425 743 957

 64b-8t4c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  2.87       1.93 

3. 27 90 201 27 88 200
4. 109 259 339 108 258 342
5. 258 421 530 261 418 529

 1518b-2t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.44       5.45 

3. 49 116 183 48 60 160
4. 300 666 872 310 707 931
5. 1332 1895 2429 1246 1792 2291

 1518b-4t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.87      10.67 

3. 49 106 195 49 87 167
4. 289 698 940 257 677 900
5. 692 1002 1258 676 973 1204

 1518b-8t4c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.67      20.59 

3. 50 101 167 49 94 150
4. 153 307 409 139 313 421
5. 335 492 619 335 490 614

 imix-2t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.63       1.89 

 imix-4t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.26       3.77 

 imix-8t4c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  2.48       7.41 

25ge2p1xxv710-ethip4ipsec1000tnlsw-ip4base-policy-aes128gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  0.82       0.55 

3. 23 39 152 23 30 139
4. 272 797 1157 266 782 1189
5. 801 1368 1706 797 1411 1780

 64b-4t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.62       1.09 

3. 23 69 191 23 65 193
4. 140 385 591 111 383 577
5. 421 700 910 427 713 925

 64b-8t4c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  3.22       2.17 

3. 23 75 195 23 73 194
4. 83 215 324 81 217 330
5. 220 362 469 223 375 482

 1518b-2t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  0.65       7.94 

3. 28 62 125 28 34 93
4. 259 667 935 250 671 951
5. 1123 1644 2002 1094 1642 1995

 1518b-4t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.22      15.06 

3. 28 64 133 28 56 114
4. 154 490 690 154 497 697
5. 483 737 930 462 714 898

 1518b-8t4c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  2.35      28.97 

3. 29 64 109 29 58 99
4. 80 188 286 77 190 290
5. 184 295 391 189 304 396

 imix-2t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  0.76       2.28 

 imix-4t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.51       4.52 

 imix-8t4c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  2.98       8.90 

25ge2p1xxv710-ethip4ipsec1000tnlsw-ip4base-policy-aes256gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  0.81       0.54 

3. 23 82 197 23 36 127
4. 284 818 1175 266 783 1215
5. 813 1396 1730 792 1399 1762

 64b-4t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.60       1.08 

3. 23 54 168 23 53 162
4. 121 391 579 114 373 576
5. 462 754 968 464 749 964

 64b-8t4c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  3.19       2.15 

3. 23 77 194 23 66 177
4. 79 218 333 71 230 346
5. 244 416 527 239 404 515

 1518b-2t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  0.61       7.48 

3. 28 51 125 28 40 97
4. 250 668 965 262 702 1011
5. 1213 1727 2173 1119 1627 2075

 1518b-4t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.17      14.34 

3. 29 65 138 28 55 118
4. 133 531 739 153 524 741
5. 503 774 1004 488 753 975

 1518b-8t4c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  2.23      27.49 

3. 30 66 113 29 61 95
4. 78 226 324 79 214 295
5. 214 345 454 205 331 432

 imix-2t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  0.75       2.24 

 imix-4t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.49       4.45 

 imix-8t4c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  2.92       8.74 

25ge2p1xxv710-ethip4ipsec1tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.54       2.38 

3. 23 100 195 23 92 135
4. 127 223 249 119 218 248
5. 218 272 312 217 270 305

 64b-4t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.73       2.51 

3. 23 98 200 22 98 138
4. 117 210 246 119 213 244
5. 198 254 287 203 260 289

 64b-8t4c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.71       2.49 

3. 23 103 200 22 104 202
4. 122 214 246 139 230 256
5. 195 254 285 203 261 293

 1518b-2t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.81       9.98 

3. 52 98 185 52 98 186
4. 383 711 772 277 645 742
5. 755 945 1119 745 939 1136

 1518b-4t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.00      12.27 

3. 52 147 197 52 112 182
4. 388 733 810 354 732 798
5. 570 740 826 580 744 833

 1518b-8t4c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.00      12.29 

3. 52 144 196 52 114 179
4. 307 710 813 342 719 820
5. 570 736 827 574 739 838

 imix-2t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.86       5.55 

 imix-4t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.01       6.00 

 imix-8t4c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.00       5.99 

25ge2p1xxv710-ethip4ipsec1tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  3.20       2.15 

3. 22 86 185 22 82 107
4. 122 237 276 107 230 315
5. 229 290 332 226 291 335

 64b-4t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  3.39       2.28 

3. 22 86 97 22 83 95
4. 78 156 188 75 156 192
5. 205 262 307 199 249 279

 64b-8t4c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  3.39       2.28 

3. 22 100 182 22 99 184
4. 107 210 257 108 220 260
5. 229 277 334 211 268 297

 1518b-2t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.71       8.72 

3. 44 78 159 44 78 160
4. 272 685 736 248 616 718
5. 860 1121 1192 861 1115 1182

 1518b-4t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.88      10.79 

3. 43 107 173 43 91 163
4. 335 714 773 305 683 772
5. 630 816 908 630 824 908

 1518b-8t4c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.88      10.83 

3. 43 109 174 43 83 151
4. 327 701 774 279 692 780
5. 625 810 903 623 803 896

 imix-2t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.76       5.26 

 imix-4t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.93       5.77 

 imix-8t4c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.91       5.72 

25ge2p1xxv710-ethip4ipsec1tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  6.35       4.27 

3. 19 66 90 18 70 93
4. 75 126 144 78 124 144
5. 123 149 166 121 149 164

 64b-4t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  6.47       4.34 

3. 18 48 67 18 49 67
4. 73 124 139 75 126 142
5. 115 142 159 120 146 165

 64b-8t4c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  6.48       4.36 

3. 19 49 76 18 48 74
4. 45 66 77 45 65 80
5. 93 113 128 100 120 142

 1518b-2t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.80      22.15 

3. 23 75 94 23 93 112
4. 91 225 250 90 217 243
5. 264 339 377 258 330 363

 1518b-4t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.04      25.05 

3. 23 67 99 23 67 93
4. 134 294 329 118 283 328
5. 228 295 328 229 295 332

 1518b-8t4c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.05      25.21 

3. 23 65 79 23 61 79
4. 122 285 321 109 283 319
5. 227 295 328 227 293 327

 imix-2t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.78      11.31 

 imix-4t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.97      11.89 

 imix-8t4c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.98      11.89 

25ge2p1xxv710-ethip4ipsec1tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.12       4.11 

3. 19 90 113 18 99 130
4. 89 131 147 72 120 129
5. 125 157 177 126 157 179

 64b-4t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.42       4.31 

3. 18 59 76 18 61 85
4. 74 126 146 76 133 148
5. 127 155 180 126 154 181

 64b-8t4c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.39       4.29 

3. 18 60 78 18 59 74
4. 74 128 147 75 130 151
5. 122 148 167 124 150 167

 1518b-2t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.48      18.23 

3. 24 46 68 23 47 71
4. 145 320 385 151 319 390
5. 300 362 396 287 354 380

 1518b-4t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.81      22.25 

3. 23 63 79 23 61 81
4. 145 292 338 158 295 338
5. 275 343 378 267 346 378

 1518b-8t4c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.81      22.27 

3. 23 65 91 23 63 86
4. 151 294 341 142 290 332
5. 275 341 375 267 340 371

 imix-2t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.48      10.41 

 imix-4t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.70      11.06 

 imix-8t4c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.66      10.95 

25ge2p1xxv710-ethip4ipsec1tnlsw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  3.17       2.13 

3. 23 96 190 23 85 132
4. 108 232 312 107 235 313
5. 215 285 322 222 287 322

 64b-4t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  3.26       2.19 

3. 23 86 187 23 86 177
4. 126 232 262 102 225 269
5. 211 268 306 210 274 308

 64b-8t4c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  3.27       2.20 

3. 23 90 190 23 87 188
4. 119 229 263 108 219 256
5. 214 272 314 217 272 309

 1518b-2t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.80       9.78 

3. 53 125 193 53 115 191
4. 291 715 752 290 660 745
5. 783 957 1084 750 983 1166

 1518b-4t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.96      11.83 

3. 53 137 201 52 117 198
4. 395 753 795 371 708 788
5. 597 770 844 609 779 857

 1518b-8t4c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  0.96      11.86 

3. 53 157 202 52 110 182
4. 378 753 790 373 707 787
5. 601 772 840 601 772 835

 imix-2t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.76       5.26 

 imix-4t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.87       5.60 

 imix-8t4c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 2.  1.87       5.59 

25ge2p1xxv710-ethip4ipsec1tnlsw-ip4base-policy-aes128cbc-hmac512sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  2.91       1.96 

3. 23 86 186 23 86 188
4. 130 250 277 130 250 283
5. 230 289 390 225 290 377

 64b-4t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  3.02       2.03 

3. 22 91 191 22 88 190
4. 115 236 257 109 229 262
5. 236 289 337 205 266 303

 64b-8t4c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  3.03       2.04 

3. 22 91 189 22 90 188
4. 117 234 259 118 236 261
5. 234 288 338 220 271 311

 1518b-2t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.69       8.52 

3. 45 76 165 44 77 164
4. 349 685 711 261 676 708
5. 882 1151 1199 878 1139 1196

 1518b-4t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.85      10.49 

3. 44 104 172 44 95 168
4. 423 755 806 356 694 803
5. 718 876 992 717 877 995

 1518b-8t4c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  0.86      10.57 

3. 44 104 172 44 95 168
4. 376 755 795 342 695 793
5. 703 865 978 681 852 963

 imix-2t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.64       4.90 

 imix-4t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.80       5.39 

 imix-8t4c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 2.  1.79       5.36 

25ge2p1xxv710-ethip4ipsec1tnlsw-ip4base-policy-aes128gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  5.23       3.52 

3. 19 119 147 19 125 154
4. 74 132 147 74 144 158
5. 132 159 170 128 153 168

 64b-4t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  5.29       3.55 

3. 19 111 130 19 111 130
4. 73 128 140 61 127 141
5. 134 160 180 133 159 177

 64b-8t4c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  5.32       3.58 

3. 19 111 129 19 108 141
4. 95 131 145 58 124 135
5. 133 158 174 134 160 177

 1518b-2t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.74      21.37 

3. 24 70 104 24 67 94
4. 164 286 301 162 291 313
5. 299 377 435 293 371 433

 1518b-4t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.91      23.53 

3. 24 65 78 23 64 77
4. 148 284 318 148 279 319
5. 239 302 343 237 307 350

 1518b-8t4c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  1.92      23.61 

3. 24 62 92 23 62 82
4. 140 285 317 152 280 316
5. 239 301 341 239 300 346

 imix-2t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  3.42      10.22 

 imix-4t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  3.49      10.44 

 imix-8t4c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 2.  3.49      10.44 

25ge2p1xxv710-ethip4ipsec1tnlsw-ip4base-policy-aes256gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  5.10       3.43 

3. 19 61 119 19 54 78
4. 83 143 164 73 144 163
5. 135 172 190 138 174 193

 64b-4t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  5.20       3.50 

3. 19 112 153 19 124 152
4. 72 134 151 70 142 159
5. 140 168 184 137 170 189

 64b-8t4c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  5.16       3.47 

3. 19 117 143 19 76 141
4. 79 141 159 73 140 155
5. 139 168 185 137 168 185

 1518b-2t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.43      17.53 

3. 24 57 86 24 56 89
4. 166 333 411 174 356 445
5. 346 459 518 338 443 508

 1518b-4t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.69      20.81 

3. 24 72 109 24 69 83
4. 169 308 350 155 312 356
5. 300 415 474 301 410 473

 1518b-8t4c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  1.71      21.02 

3. 24 70 84 24 67 82
4. 176 309 346 162 315 354
5. 300 412 473 303 398 467

 imix-2t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  3.13       9.37 

 imix-4t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  3.27       9.79 

 imix-8t4c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 2.  3.25       9.73 

25ge2p1xxv710-ethip4ipsec20000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.24       1.50 

3. 24 84 182 23 78 169
4. 123 312 367 117 291 350
5. 262 354 392 231 330 382

 1518b-2t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.74       9.11 

3. 54 112 196 53 108 193
4. 361 775 825 360 725 833
5. 946 1175 1336 939 1162 1311

 imix-2t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.45       4.35 

25ge2p1xxv710-ethip4ipsec20000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.01       1.35 

3. 23 77 177 23 71 172
4. 145 321 360 109 307 358
5. 287 380 438 273 367 425

 1518b-2t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.64       7.92 

3. 45 80 169 45 79 169
4. 321 731 784 298 668 764
5. 1042 1343 1487 979 1288 1421

 imix-2t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.36       4.06 

25ge2p1xxv710-ethip4ipsec20000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.03       2.04 

3. 19 75 164 19 70 162
4. 104 212 233 97 217 245
5. 203 263 303 184 246 277

 1518b-2t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.25      15.42 

3. 24 58 95 24 55 97
4. 196 466 552 210 475 552
5. 415 547 618 406 529 598

 imix-2t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.15       6.43 

25ge2p1xxv710-ethip4ipsec20000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.92       1.96 

3. 19 77 177 19 74 174
4. 122 241 264 118 238 262
5. 201 265 315 186 257 305

 1518b-2t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.10      13.50 

3. 25 50 101 24 50 90
4. 246 541 616 237 531 598
5. 511 675 764 471 631 757

 imix-2t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.01       6.00 

25ge2p1xxv710-ethip4ipsec40000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.86       1.25 

3. 24 83 184 24 76 175
4. 173 369 432 172 367 425
5. 299 414 522 299 419 543

 1518b-2t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.72       8.88 

3. 54 176 202 53 112 194
4. 370 784 818 358 778 818
5. 1008 1212 1348 987 1185 1289

 imix-2t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.28       3.82 

25ge2p1xxv710-ethip4ipsec40000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.70       1.14 

3. 23 77 179 23 72 172
4. 188 384 463 165 381 457
5. 341 451 518 322 447 518

 1518b-2t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.63       7.69 

3. 45 141 172 45 68 156
4. 318 737 777 303 682 772
5. 987 1351 1511 995 1329 1471

 imix-2t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.19       3.57 

25ge2p1xxv710-ethip4ipsec40000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.40       1.61 

3. 20 68 169 19 64 163
4. 115 267 314 105 262 334
5. 253 314 371 242 306 400

 1518b-2t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.16      14.27 

3. 25 56 86 25 51 84
4. 171 521 619 170 518 619
5. 452 635 711 434 618 701

 imix-2t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.80       5.39 

25ge2p1xxv710-ethip4ipsec40000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.35       1.58 

3. 20 81 184 19 76 179
4. 145 311 393 136 295 363
5. 291 382 448 258 339 413

 1518b-2t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.03      12.66 

3. 25 61 99 25 48 78
4. 258 603 715 201 602 700
5. 488 660 736 470 640 721

 imix-2t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.70       5.08 

25ge2p1xxv710-ethip4ipsec400tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.78       1.87 

3. 23 93 191 23 81 107
4. 166 286 316 163 279 305
5. 240 311 381 229 298 367

 64b-4t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  5.73       3.85 

3. 23 59 80 23 58 75
4. 82 139 158 88 146 163
5. 166 205 255 159 196 237

 64b-8t4c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2. 11.45       7.69 

3. 24 54 69 24 51 74
4. 67 88 100 66 90 99
5. 142 180 225 133 167 207

 1518b-2t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.79       9.74 

3. 53 149 194 53 108 189
4. 338 749 781 321 746 783
5. 830 1020 1211 794 1002 1212

 1518b-4t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.55      19.04 

3. 53 118 174 53 115 178
4. 198 377 463 196 379 467
5. 388 499 562 380 502 567

 1518b-8t4c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.00      36.91 

3. 54 114 152 54 113 141
4. 139 213 253 136 217 251
5. 247 297 335 244 294 332

 imix-2t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.71       5.11 

 imix-4t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.39      10.13 

 imix-8t4c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  6.77      20.24 

25ge2p1xxv710-ethip4ipsec400tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.47       1.66 

3. 22 91 174 22 73 169
4. 125 245 289 121 253 298
5. 260 327 388 230 305 352

 64b-4t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  5.09       3.42 

3. 23 67 103 22 63 85
4. 88 149 173 81 147 170
5. 152 191 223 149 188 218

 64b-8t4c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2. 10.30       6.92 

3. 23 72 90 23 71 91
4. 63 83 96 63 86 96
5. 112 144 174 103 132 160

 1518b-2t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.69       8.50 

3. 44 81 164 44 80 163
4. 290 714 756 278 644 736
5. 1012 1240 1355 990 1239 1351

 1518b-4t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.35      16.56 

3. 44 90 137 44 83 123
4. 138 422 505 133 424 512
5. 380 492 571 372 481 554

 1518b-8t4c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.66      32.68 

3. 45 89 118 45 88 109
4. 89 186 204 87 193 212
5. 208 257 301 205 255 298

 imix-2t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.63       4.86 

 imix-4t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  3.20       9.56 

 imix-8t4c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  6.35      18.98 

25ge2p1xxv710-ethip4ipsec400tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.29       2.88 

3. 19 131 177 19 77 159
4. 118 165 180 85 161 176
5. 116 170 203 113 159 190

 64b-4t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  9.22       6.19 

3. 19 74 93 19 70 90
4. 66 91 100 64 91 100
5. 102 119 147 97 113 129

 64b-8t4c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 17.82      11.98 

3. 19 52 69 19 48 68
4. 45 58 65 43 56 63
5. 76 100 130 70 97 130

 1518b-2t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.63      20.10 

3. 24 74 112 23 67 87
4. 136 321 369 137 328 377
5. 359 438 509 335 421 481

 1518b-4t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.05      37.58 

3. 24 63 78 24 58 75
4. 73 141 168 79 134 159
5. 139 164 185 131 161 180

 1518b-8t4c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.83      47.10 

3. 25 50 73 24 46 74
4. 49 71 83 54 72 83
5. 64 73 82 65 74 82

 imix-2t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.09       9.24 

 imix-4t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  6.35      19.00 

 imix-8t4c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 12.00      35.88 

25ge2p1xxv710-ethip4ipsec400tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  4.15       2.79 

3. 19 112 166 19 77 141
4. 117 188 199 89 186 197
5. 135 189 219 125 180 207

 64b-4t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  8.92       5.99 

3. 19 59 74 19 51 77
4. 44 69 80 44 70 80
5. 73 95 111 64 81 98

 64b-8t4c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 17.37      11.67 

3. 19 49 73 19 47 64
4. 49 64 72 42 59 69
5. 77 102 131 73 100 133

 1518b-2t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.36      16.68 

3. 24 62 105 24 54 87
4. 165 437 528 138 437 520
5. 398 493 557 388 492 552

 1518b-4t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.59      31.84 

3. 24 56 92 24 55 81
4. 65 164 184 61 163 182
5. 153 194 219 152 202 233

 1518b-8t4c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.83      47.10 

3. 25 52 74 25 48 75
4. 49 76 85 53 77 86
5. 69 80 89 70 81 90

 imix-2t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.91       8.69 

 imix-4t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  5.86      17.51 

 imix-8t4c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 11.27      33.70 

25ge2p1xxv710-ethip4ipsec40tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.20       2.15 

3. 23 99 193 23 84 126
4. 122 233 308 104 227 307
5. 230 295 349 220 286 335

 64b-4t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  5.25       3.53 

3. 23 105 151 23 111 140
4. 74 127 147 59 123 142
5. 146 203 259 129 157 179

 64b-8t4c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2. 10.41       6.99 

3. 24 82 98 23 78 91
4. 68 88 101 65 84 94
5. 142 207 274 94 117 143

 1518b-2t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.80       9.88 

3. 53 148 194 52 106 188
4. 324 731 755 298 728 754
5. 796 972 1163 787 977 1163

 1518b-4t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.49      18.34 

3. 53 114 175 53 106 165
4. 180 355 461 166 344 436
5. 361 498 570 328 456 513

 1518b-8t4c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.83      34.87 

3. 53 110 142 53 105 134
4. 147 187 236 145 181 218
5. 236 303 366 201 252 304

 imix-2t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.81       5.42 

 imix-4t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.23       9.66 

 imix-8t4c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  6.24      18.66 

25ge2p1xxv710-ethip4ipsec40tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.81       1.89 

3. 22 88 178 22 77 173
4. 159 277 293 162 274 294
5. 232 298 354 217 293 338

 64b-4t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  4.71       3.16 

3. 23 109 152 22 109 135
4. 70 146 165 67 140 157
5. 161 202 249 139 159 179

 64b-8t4c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  9.18       6.17 

3. 23 69 95 23 56 89
4. 64 92 103 62 88 96
5. 118 156 197 89 103 116

 1518b-2t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.71       8.68 

3. 44 85 167 44 74 154
4. 369 700 731 277 681 730
5. 913 1167 1286 915 1165 1282

 1518b-4t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.28      15.79 

3. 44 87 147 44 79 127
4. 148 422 511 122 408 471
5. 346 497 629 335 458 582

 1518b-8t4c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.50      30.77 

3. 45 83 106 45 76 100
4. 108 186 225 101 184 215
5. 191 248 288 174 222 255

 imix-2t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.71       5.11 

 imix-4t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.99       8.94 

 imix-8t4c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  5.73      17.14 

25ge2p1xxv710-ethip4ipsec40tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  5.33       3.58 

3. 19 95 126 18 107 136
4. 89 122 148 84 117 128
5. 143 172 195 133 162 183

 64b-4t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  8.69       5.84 

3. 19 65 86 19 60 82
4. 52 74 85 52 74 84
5. 80 120 150 74 94 109

 64b-8t4c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 16.96      11.39 

3. 19 47 77 19 47 67
4. 44 58 66 44 56 65
5. 92 146 227 59 74 94

 1518b-2t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.74      21.37 

3. 23 110 151 23 89 132
4. 148 271 301 155 281 312
5. 295 400 473 293 387 450

 1518b-4t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.88      35.40 

3. 24 55 75 24 49 74
4. 76 109 139 73 106 131
5. 112 153 173 100 127 146

 1518b-8t4c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.83      47.10 

3. 25 50 73 24 46 74
4. 48 73 83 54 71 83
5. 65 76 83 65 74 82

 imix-2t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.57      10.68 

 imix-4t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  5.84      17.48 

 imix-8t4c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 10.92      32.64 

25ge2p1xxv710-ethip4ipsec40tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  5.18       3.48 

3. 19 98 147 18 76 136
4. 77 136 155 69 142 161
5. 151 179 201 138 171 188

 64b-4t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  8.49       5.70 

3. 19 72 89 19 64 88
4. 74 91 104 75 89 98
5. 89 127 164 72 93 107

 64b-8t4c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 16.30      10.95 

3. 19 48 63 19 37 70
4. 54 64 71 49 59 68
5. 79 116 157 58 73 89

 1518b-2t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.45      17.82 

3. 24 77 111 24 54 78
4. 165 336 380 148 350 389
5. 349 476 541 339 462 529

 1518b-4t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.44      30.03 

3. 24 46 68 24 43 64
4. 68 137 173 63 133 164
5. 124 162 201 111 146 180

 1518b-8t4c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.83      47.10 

3. 25 52 73 25 47 75
4. 48 79 89 55 77 87
5. 71 84 94 69 80 90

 imix-2t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.30       9.86 

 imix-4t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  5.48      16.39 

 imix-8t4c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 10.46      31.27 

25ge2p1xxv710-ethip4ipsec4tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.32       2.23 

3. 23 99 197 23 90 116
4. 118 225 264 111 224 259
5. 226 288 340 220 285 337

 64b-4t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.36       2.26 

3. 23 58 143 23 28 57
4. 68 169 196 32 115 142
5. 170 213 233 74 117 134

 64b-8t4c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.69       2.48 

3. 23 41 133 23 24 54
4. 51 150 167 24 77 90
5. 125 177 199 41 80 92

 1518b-2t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.81       9.92 

3. 53 145 193 52 108 188
4. 316 728 753 293 720 749
5. 779 962 1141 766 947 1108

 1518b-4t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.97      11.95 

3. 53 101 172 52 69 122
4. 169 502 587 58 334 444
5. 382 540 605 213 387 424

 1518b-8t4c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.03      12.71 

3. 53 86 150 53 62 106
4. 157 484 522 54 141 192
5. 296 469 501 65 166 209

 imix-2t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.84       5.49 

 imix-4t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.04       6.10 

 imix-8t4c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.16       6.46 

25ge2p1xxv710-ethip4ipsec4tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.89       1.95 

3. 22 84 181 22 77 178
4. 142 262 289 147 268 294
5. 227 294 396 209 287 369

 64b-4t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.99       2.01 

3. 22 45 144 22 23 52
4. 50 170 192 23 118 146
5. 129 173 211 46 97 108

 64b-8t4c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  3.20       2.15 

3. 22 29 126 22 23 69
4. 28 137 168 23 61 82
5. 113 172 185 46 69 82

 1518b-2t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.71       8.73 

3. 44 122 177 44 93 177
4. 288 697 748 253 632 727
5. 879 1134 1219 901 1147 1233

 1518b-4t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.85      10.41 

3. 44 77 154 44 54 107
4. 182 502 545 48 317 372
5. 451 633 708 171 357 439

 1518b-8t4c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.90      11.08 

3. 44 70 131 44 48 76
4. 128 451 501 45 139 180
5. 339 519 595 51 149 185

 imix-2t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.74       5.19 

 imix-4t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.91       5.72 

 imix-8t4c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.02       6.03 

25ge2p1xxv710-ethip4ipsec4tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  5.61       3.77 

3. 19 53 81 18 52 87
4. 78 138 153 87 145 159
5. 140 170 193 125 164 183

 64b-4t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  5.75       3.86 

3. 19 33 63 19 24 46
4. 47 101 118 31 72 89
5. 103 126 146 59 82 93

 64b-8t4c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  6.44       4.33 

3. 19 42 54 19 40 56
4. 48 63 75 32 54 73
5. 79 96 109 33 49 61

 1518b-2t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.79      22.02 

3. 24 60 76 23 60 76
4. 137 274 310 146 281 317
5. 289 366 422 276 360 400

 1518b-4t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.92      23.57 

3. 24 43 66 23 39 50
4. 65 211 232 24 105 124
5. 166 227 254 77 113 126

 1518b-8t4c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.02      24.80 

3. 24 45 85 24 41 51
4. 60 221 252 24 61 75
5. 155 214 230 52 65 76

 imix-2t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.73      11.16 

 imix-4t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.84      11.50 

 imix-8t4c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  4.15      12.40 

25ge2p1xxv710-ethip4ipsec4tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  5.45       3.66 

3. 19 84 112 18 82 106
4. 94 151 165 90 132 158
5. 136 166 191 124 157 185

 64b-4t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  5.60       3.76 

3. 19 40 52 19 26 44
4. 54 116 127 42 87 98
5. 108 136 155 57 88 102

 64b-8t4c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.31       4.24 

3. 19 44 51 19 30 48
4. 43 89 101 31 59 79
5. 85 103 115 39 60 72

 1518b-2t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.47      18.03 

3. 24 58 99 24 55 100
4. 133 340 366 117 325 365
5. 335 465 526 333 454 517

 1518b-4t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.56      19.22 

3. 24 47 77 24 40 57
4. 47 242 269 25 125 158
5. 160 236 258 93 121 141

 1518b-8t4c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.73      21.26 

3. 24 43 92 24 28 47
4. 90 206 258 25 60 85
5. 187 266 318 40 63 69

 imix-2t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.40      10.18 

 imix-4t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.55      10.62 

 imix-8t4c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.84      11.50 

25ge2p1xxv710-ethip4ipsec5000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.56       1.72 

3. 23 93 190 23 75 176
4. 133 251 284 120 237 275
5. 251 333 419 235 318 403

 64b-4t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  4.89       3.29 

3. 23 90 119 23 91 130
4. 99 153 177 95 149 176
5. 158 192 227 156 189 221

 64b-8t4c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  9.36       6.29 

3. 24 72 91 24 75 92
4. 81 100 110 81 104 113
5. 130 167 194 129 166 191

 1518b-2t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.78       9.61 

3. 53 149 199 53 115 195
4. 369 782 813 351 776 809
5. 868 1088 1284 843 1071 1272

 1518b-4t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.48      18.19 

3. 53 118 181 53 112 170
4. 210 386 486 198 387 489
5. 393 520 591 386 510 577

 1518b-8t4c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  2.81      34.63 

3. 54 118 162 54 116 146
4. 161 196 225 156 198 219
5. 268 327 384 264 321 374

 imix-2t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.63       4.88 

 imix-4t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  3.17       9.47 

 imix-8t4c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  6.00      17.95 

25ge2p1xxv710-ethip4ipsec5000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.33       1.56 

3. 23 82 175 22 72 166
4. 144 287 311 132 283 342
5. 296 363 453 254 345 457

 64b-4t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  4.51       3.03 

3. 23 81 175 23 80 174
4. 86 162 183 86 159 179
5. 184 208 238 112 169 203

 64b-8t4c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  8.41       5.65 

3. 23 77 89 23 68 90
4. 79 95 106 82 97 107
5. 98 121 145 96 119 141

 1518b-2t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.68       8.33 

3. 45 125 183 44 79 165
4. 312 726 762 297 722 753
5. 1069 1288 1403 995 1290 1408

 1518b-4t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.30      16.00 

3. 45 95 146 45 86 133
4. 165 442 504 165 429 499
5. 409 535 650 397 523 645

 1518b-8t4c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.49      30.69 

3. 46 90 122 46 86 109
4. 120 205 237 119 203 239
5. 205 255 294 206 258 295

 imix-2t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.54       4.61 

 imix-4t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  2.98       8.92 

 imix-8t4c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  5.59      16.70 

25ge2p1xxv710-ethip4ipsec5000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.71       2.49 

3. 19 77 166 19 69 151
4. 81 177 204 82 177 205
5. 148 206 236 134 194 221

 64b-4t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  7.10       4.77 

3. 19 74 96 19 80 104
4. 63 106 121 58 102 117
5. 105 134 157 100 127 147

 64b-8t4c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2. 13.26       8.91 

3. 20 42 65 19 21 42
4. 50 66 75 48 66 75
5. 69 93 109 79 106 123

 1518b-2t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.51      18.53 

3. 24 72 109 24 66 88
4. 169 377 429 141 368 414
5. 374 502 555 366 495 547

 1518b-4t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.59      31.89 

3. 24 58 90 24 55 77
4. 62 167 185 66 164 185
5. 150 191 217 147 195 222

 1518b-8t4c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  3.83      47.10 

3. 25 54 73 25 49 74
4. 51 82 92 54 82 92
5. 74 86 97 75 87 98

 imix-2t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.67       7.98 

 imix-4t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  5.13      15.35 

 imix-8t4c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  9.39      28.08 

25ge2p1xxv710-ethip4ipsec5000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.64       2.44 

3. 19 99 170 19 72 164
4. 93 188 219 94 182 201
5. 164 220 256 155 210 240

 64b-4t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  6.94       4.66 

3. 19 89 113 19 85 108
4. 58 105 122 48 102 118
5. 105 131 152 99 125 145

 64b-8t4c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2. 12.82       8.62 

3. 20 45 59 19 38 51
4. 50 68 77 50 69 79
5. 77 95 117 76 95 116

 1518b-2t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.29      15.92 

3. 24 67 110 24 60 92
4. 210 497 616 220 504 565
5. 454 573 652 434 550 636

 1518b-4t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.26      27.84 

3. 25 53 93 24 51 82
4. 85 193 248 93 172 232
5. 194 252 318 188 240 292

 1518b-8t4c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  3.83      47.10 

3. 26 56 73 25 54 75
4. 56 90 102 63 91 103
5. 87 102 116 88 103 115

 imix-2t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.52       7.52 

 imix-4t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  4.88      14.59 

 imix-8t4c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  8.91      26.66 

25ge2p1xxv710-ethip4ipsec60000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.75       1.17 

3. 24 83 182 24 78 175
4. 179 372 432 171 368 428
5. 326 468 574 310 449 567

 1518b-2t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  0.71       8.78 

3. 54 162 204 54 117 198
4. 370 789 821 359 781 815
5. 1030 1228 1363 1000 1196 1294

 imix-2t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 2.  1.22       3.65 

25ge2p1xxv710-ethip4ipsec60000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.58       1.06 

3. 24 74 180 23 67 170
4. 137 346 429 127 326 406
5. 394 528 673 371 504 589

 1518b-2t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  0.63       7.77 

3. 45 149 181 45 82 167
4. 341 749 787 324 739 782
5. 1115 1392 1558 1057 1343 1491

 imix-2t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 2.  1.15       3.44 

25ge2p1xxv710-ethip4ipsec60000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  2.25       1.52 

3. 20 74 176 20 72 175
4. 110 299 357 101 276 315
5. 291 347 437 225 297 352

 1518b-2t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.13      13.94 

3. 25 59 105 25 48 100
4. 201 565 643 204 525 609
5. 464 660 754 453 646 737

 imix-2t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 2.  1.70       5.08 

25ge2p1xxv710-ethip4ipsec60000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-2t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  2.17       1.46 

3. 20 62 93 20 53 86
4. 157 352 411 154 350 403
5. 247 343 393 245 344 398

 1518b-2t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.02      12.53 

3. 25 61 104 25 51 87
4. 224 627 729 227 616 717
5. 498 677 750 477 656 735

 imix-2t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 2.  1.61       4.82