3n-hsw-xl710

40ge2p1xl710-ethip4ipsec10000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.58       1.84 
2. 1.59 1.85

3. 29 67 104 29 60 72
4. 150 253 272 197 306 320
5. 225 277 322 248 304 367

 64b-2t2c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  2.95       3.44 
2. 2.99 3.49

3. 30 75 94 30 72 93
4. 62 78 91 68 94 112
5. 149 177 210 125 160 200

 1518b-1t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.34       4.34 
2. 0.34 4.37

3. 70 129 153 76 101 131
4. 217 382 439 215 348 451
5. 751 986 1438 752 1040 1406

 1518b-2t2c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.65       8.36 
2. 0.66 8.40

3. 68 106 115 68 148 162
4. 247 465 555 231 475 579
5. 445 592 692 599 795 879

 imix-1t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.83       2.90 
2. 0.84 2.91

 imix-2t2c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.61       5.63 
2. 1.65 5.74

40ge2p1xl710-ethip4ipsec10000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.27       1.64 
2. 1.27 1.65

3. 29 67 99 29 86 115
4. 88 217 240 84 172 248
5. 229 330 430 226 325 429

 64b-2t2c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.38       3.09 
2. 2.42 3.13

3. 29 77 85 29 49 83
4. 54 76 94 62 106 128
5. 140 201 264 129 155 191

 1518b-1t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.27       3.49 
2. 0.27 3.51

3. 60 97 120 60 86 115
4. 144 381 470 181 308 391
5. 574 830 1018 616 793 1020

 1518b-2t2c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.52       6.76 
2. 0.53 6.80

3. 59 95 166 59 70 106
4. 367 725 820 259 568 638
5. 655 820 1171 596 782 1038

 imix-1t1c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.70       2.52 
2. 0.70 2.53

 imix-2t2c-ethip4ipsec10000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.36       4.91 
2. 1.38 4.98

40ge2p1xl710-ethip4ipsec10000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.32       2.56 
2. 2.33 2.58

3. 25 59 82 25 46 56
4. 63 88 98 50 159 168
5. 120 166 198 138 179 205

 64b-2t2c-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  4.19       4.62 
2. 4.21 4.64

3. 26 55 79 26 63 82
4. 49 63 74 55 75 84
5. 72 93 110 68 86 103

 1518b-1t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.80      10.16 
2. 0.80 10.21

3. 29 55 71 29 53 81
4. 65 167 250 90 240 295
5. 242 315 392 228 323 405

 1518b-2t2c-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.59      20.19 
2. 1.59 20.29

3. 29 57 73 29 37 55
4. 87 108 128 110 190 229
5. 170 237 277 117 147 178

 imix-1t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.53       5.24 
2. 1.54 5.27

 imix-2t2c-ethip4ipsec10000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.09      10.57 
2. 3.12 10.67

40ge2p1xl710-ethip4ipsec10000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.30       2.54 
2. 2.31 2.55

3. 25 54 115 25 75 98
4. 65 97 143 73 135 160
5. 130 177 195 131 181 205

 64b-2t2c-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  4.19       4.63 
2. 4.21 4.65

3. 34 64 87 26 60 89
4. 47 59 73 49 73 86
5. 70 84 100 83 109 134

 1518b-1t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.69       8.73 
2. 0.69 8.78

3. 29 63 83 30 53 79
4. 54 170 217 86 185 255
5. 299 442 594 306 423 556

 1518b-2t2c-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.37      17.43 
2. 1.38 17.60

3. 30 66 89 29 64 85
4. 75 157 200 73 158 212
5. 194 251 302 136 195 267

 imix-1t1c-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.45       4.95 
2. 1.45 4.98

 imix-2t2c-ethip4ipsec10000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.88       9.87 
2. 2.91 9.97

40ge2p1xl710-ethip4ipsec1000tnlhw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.58       1.85 
2. 1.59 1.86

3. 29 59 73 29 45 56
4. 141 241 275 140 256 315
5. 222 269 310 225 292 343

 64b-2t2c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  2.94       3.44 
2. 2.99 3.49

3. 30 78 109 29 65 89
4. 81 135 154 77 118 151
5. 131 155 175 105 132 151

 1518b-1t1c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.34       4.35 
2. 0.34 4.37

3. 68 102 115 68 94 130
4. 203 481 536 227 449 541
5. 765 970 1108 783 1000 1286

 1518b-2t2c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.66       8.40 
2. 0.66 8.44

3. 68 138 162 68 105 144
4. 267 560 644 310 512 621
5. 568 730 854 482 610 711

 imix-1t1c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.84       2.91 
2. 0.84 2.93

 imix-2t2c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.62       5.66 
2. 1.65 5.74

40ge2p1xl710-ethip4ipsec1000tnlhw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.27       1.64 
2. 1.27 1.65

3. 29 66 99 29 90 116
4. 87 206 224 106 230 305
5. 230 330 379 227 316 376

 64b-2t2c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.37       3.07 
2. 2.40 3.10

3. 29 80 85 29 93 112
4. 67 110 126 86 155 196
5. 108 137 155 139 181 217

 1518b-1t1c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.27       3.50 
2. 0.27 3.51

3. 59 98 126 59 63 85
4. 170 277 338 130 344 451
5. 644 826 884 632 781 945

 1518b-2t2c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.52       6.77 
2. 0.53 6.81

3. 59 95 128 59 100 115
4. 278 564 615 202 418 528
5. 634 806 917 404 566 663

 imix-1t1c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.70       2.52 
2. 0.70 2.54

 imix-2t2c-ethip4ipsec1000tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.36       4.93 
2. 1.39 5.03

40ge2p1xl710-ethip4ipsec1000tnlhw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.15       2.37 
2. 2.16 2.39

3. 45 60 68 45 115 143
4. 128 205 242 130 217 240
5. 196 232 267 198 239 281

 64b-2t2c-ethip4ipsec1000tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.26       3.60 
2. 3.33 3.67

3. 45 69 83 45 82 94
4. 65 90 104 59 90 106
5. 139 165 188 108 125 143

 1518b-1t1c-ethip4ipsec1000tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.99      25.31 
2. 2.00 25.44

3. 53 61 86 53 61 89
4. 84 113 123 90 120 136
5. 313 346 367 305 336 367

 1518b-2t2c-ethip4ipsec1000tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.15      40.06 
2. 3.16 40.26

3. 54 81 94 52 103 114
4. 90 110 120 65 110 116
5. 199 221 233 168 188 203

 imix-1t1c-ethip4ipsec1000tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.91       6.55 
2. 1.92 6.58

 imix-2t2c-ethip4ipsec1000tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.02      10.34 
2. 3.06 10.47

40ge2p1xl710-ethip4ipsec1000tnlhw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.15       2.37 
2. 2.16 2.39

3. 46 61 70 46 61 73
4. 90 176 196 96 137 155
5. 220 256 291 219 253 286

 64b-2t2c-ethip4ipsec1000tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.27       3.61 
2. 3.32 3.67

3. 45 76 83 45 73 93
4. 71 97 120 69 101 121
5. 139 173 198 104 122 141

 1518b-1t1c-ethip4ipsec1000tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.97      25.07 
2. 1.98 25.20

3. 53 61 71 54 78 101
4. 78 120 139 88 127 151
5. 292 325 351 289 317 343

 1518b-2t2c-ethip4ipsec1000tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.10      39.52 
2. 3.13 39.91

3. 53 72 83 53 75 88
4. 61 80 89 69 83 93
5. 165 183 198 152 171 185

 imix-1t1c-ethip4ipsec1000tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.93       6.61 
2. 1.94 6.64

 imix-2t2c-ethip4ipsec1000tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.01      10.32 
2. 3.07 10.50

40ge2p1xl710-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.43       0.51 
2. 0.44 0.51

3. 44 93 118 44 67 122
4. 179 502 729 168 521 724
5. 1628 2411 2961 1541 2273 2883

 64b-2t2c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.78       0.91 
2. 0.79 0.92

3. 43 86 109 42 64 131
4. 110 307 541 92 277 435
5. 459 899 1121 509 859 1056

 1518b-1t1c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.22       2.77 
2. 0.22 2.77

3. 75 92 113 75 94 113
4. 192 316 424 199 341 427
5. 1509 2333 3163 1583 2589 3501

 1518b-2t2c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.42       5.38 
2. 0.42 5.43

3. 73 101 159 73 78 131
4. 373 822 1033 434 902 1155
5. 1007 1396 1663 1117 1688 2071

 imix-1t1c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.34       1.20 
2. 0.35 1.20

 imix-2t2c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.65       2.26 
2. 0.65 2.27

40ge2p1xl710-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac512sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.40       0.52 
2. 0.41 0.53

3. 43 65 96 44 76 143
4. 186 514 697 151 514 736
5. 1770 2551 3091 1832 2565 3075

 64b-2t2c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.73       0.94 
2. 0.73 0.95

3. 43 95 113 42 73 109
4. 99 251 376 94 322 483
5. 458 837 1039 607 1030 1249

 1518b-1t1c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.19       2.40 
2. 0.19 2.41

3. 65 70 103 65 70 73
4. 139 244 324 151 272 377
5. 954 1545 2065 978 1628 2081

 1518b-2t2c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.36       4.72 
2. 0.37 4.76

3. 64 120 159 64 98 141
4. 369 773 994 248 644 848
5. 1198 1822 2343 1077 1614 1979

 imix-1t1c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.32       1.16 
2. 0.32 1.17

 imix-2t2c-ethip4ipsec1000tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.60       2.17 
2. 0.61 2.19

40ge2p1xl710-ethip4ipsec1000tnlhw-ip4base-policy-aes128gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.39       0.43 
2. 0.40 0.44

3. 50 72 115 49 54 73
4. 168 547 832 174 535 851
5. 2447 3933 4903 2333 3983 4995

 64b-2t2c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.86       0.95 
2. 0.87 0.96

3. 49 82 197 49 61 95
4. 195 775 1016 143 533 832
5. 646 1288 1463 794 1397 1633

 1518b-1t1c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.39       4.96 
2. 0.40 5.04

3. 57 94 130 58 104 117
4. 146 423 710 142 365 612
5. 1148 2595 4111 1129 2605 4151

 1518b-2t2c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.84      10.70 
2. 0.84 10.75

3. 55 76 110 56 91 153
4. 183 578 797 127 603 839
5. 851 1528 1807 531 1120 1338

 imix-1t1c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.35       1.20 
2. 0.38 1.28

 imix-2t2c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.87       2.97 
2. 0.87 2.99

40ge2p1xl710-ethip4ipsec1000tnlhw-ip4base-policy-aes256gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.39       0.43 
2. 0.40 0.44

3. 51 88 118 50 65 88
4. 161 434 671 171 473 726
5. 2455 4211 5279 2527 4159 5159

 64b-2t2c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.88       0.97 
2. 0.89 0.98

3. 49 136 299 50 91 197
4. 231 909 1253 141 665 1003
5. 748 1451 1664 526 1102 1380

 1518b-1t1c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.39       4.95 
2. 0.39 5.02

3. 58 73 108 59 85 110
4. 115 387 543 118 548 789
5. 863 1801 2589 760 2145 2885

 1518b-2t2c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.86      10.98 
2. 0.87 11.09

3. 57 89 113 58 95 115
4. 120 392 687 108 293 463
5. 774 1459 1686 680 1371 1611

 imix-1t1c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.37       1.26 
2. 0.38 1.31

 imix-2t2c-ethip4ipsec1000tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.86       2.93 
2. 0.86 2.96

40ge2p1xl710-ethip4ipsec1000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.57       1.84 
2. 1.59 1.85

3. 29 67 99 29 64 76
4. 136 235 331 106 231 302
5. 241 314 397 239 310 409

 64b-2t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  2.99       3.49 
2. 3.04 3.55

3. 30 81 98 29 44 60
4. 66 77 91 74 130 154
5. 135 166 190 134 160 181

 1518b-1t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.34       4.35 
2. 0.34 4.37

3. 78 117 151 76 111 119
4. 207 276 320 178 338 366
5. 759 986 1132 759 985 1097

 1518b-2t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.66       8.40 
2. 0.66 8.45

3. 68 115 129 68 115 152
4. 227 469 520 210 509 556
5. 581 747 830 463 585 699

 imix-1t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.83       2.90 
2. 0.84 2.93

 imix-2t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.62       5.65 
2. 1.65 5.76

40ge2p1xl710-ethip4ipsec1000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.27       1.64 
2. 1.27 1.65

3. 29 57 73 29 64 80
4. 74 151 183 77 139 173
5. 231 285 338 285 358 400

 64b-2t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.39       3.10 
2. 2.42 3.13

3. 29 66 82 29 54 70
4. 70 96 110 66 116 146
5. 133 176 200 165 205 230

 1518b-1t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.27       3.49 
2. 0.27 3.52

3. 59 95 117 59 91 115
4. 135 334 390 181 297 353
5. 740 995 1168 720 1004 1219

 1518b-2t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.52       6.78 
2. 0.53 6.81

3. 59 77 119 59 131 159
4. 212 525 559 238 537 637
5. 396 513 563 627 786 875

 imix-1t1c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.70       2.53 
2. 0.71 2.55

 imix-2t2c-ethip4ipsec1000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.37       4.96 
2. 1.39 5.04

40ge2p1xl710-ethip4ipsec1000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.33       2.57 
2. 2.34 2.59

3. 25 58 72 26 45 58
4. 94 114 124 49 87 108
5. 123 171 194 131 182 202

 64b-2t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  4.18       4.61 
2. 4.22 4.66

3. 26 63 76 25 38 70
4. 48 63 79 47 91 109
5. 81 102 116 84 111 130

 1518b-1t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.81      10.30 
2. 0.81 10.35

3. 29 56 75 29 38 53
4. 91 174 246 96 239 278
5. 248 345 411 256 351 381

 1518b-2t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.57      20.06 
2. 1.59 20.26

3. 29 63 81 29 45 51
4. 80 94 105 102 151 169
5. 137 182 225 178 214 247

 imix-1t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.54       5.29 
2. 1.55 5.31

 imix-2t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.11      10.65 
2. 3.16 10.81

40ge2p1xl710-ethip4ipsec1000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.29       2.53 
2. 2.30 2.54

3. 25 63 95 25 85 108
4. 59 90 153 56 96 163
5. 127 173 193 116 156 180

 64b-2t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  4.19       4.62 
2. 4.23 4.67

3. 26 57 84 26 53 74
4. 54 71 83 56 101 126
5. 86 107 152 80 107 122

 1518b-1t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.70       8.85 
2. 0.70 8.90

3. 29 62 92 29 58 77
4. 82 236 329 74 223 294
5. 307 422 455 302 397 486

 1518b-2t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.39      17.66 
2. 1.39 17.75

3. 29 60 78 29 48 65
4. 76 114 150 103 206 245
5. 186 238 273 235 319 360

 imix-1t1c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.45       4.97 
2. 1.47 5.02

 imix-2t2c-ethip4ipsec1000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.91       9.95 
2. 2.95 10.10

40ge2p1xl710-ethip4ipsec1000tnlsw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.43       0.50 
2. 0.43 0.50

3. 44 71 102 44 72 113
4. 186 535 746 205 566 808
5. 1822 2537 3049 1900 2625 3145

 64b-2t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.78       0.91 
2. 0.79 0.92

3. 42 86 111 43 71 97
4. 129 357 583 122 285 422
5. 401 794 1010 354 537 689

 1518b-1t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.22       2.76 
2. 0.22 2.79

3. 75 93 108 75 88 100
4. 225 406 559 219 413 622
5. 1513 2361 3235 1574 2583 3567

 1518b-2t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.42       5.42 
2. 0.43 5.48

3. 73 118 160 73 115 131
4. 435 867 1060 209 442 587
5. 1146 1640 2005 721 1141 1390

 imix-1t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.35       1.21 
2. 0.35 1.21

 imix-2t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.65       2.27 
2. 0.66 2.29

40ge2p1xl710-ethip4ipsec1000tnlsw-ip4base-policy-aes128cbc-hmac512sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.41       0.52 
2. 0.41 0.53

3. 43 81 129 43 56 106
4. 208 512 710 231 532 781
5. 1779 2573 3105 1847 2593 3123

 64b-2t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.73       0.95 
2. 0.73 0.95

3. 42 79 133 42 63 88
4. 96 395 614 107 348 610
5. 521 953 1208 468 763 954

 1518b-1t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.19       2.41 
2. 0.19 2.42

3. 65 70 97 65 70 71
4. 170 350 485 179 370 454
5. 1047 1532 1942 1049 1611 2087

 1518b-2t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.37       4.73 
2. 0.37 4.78

3. 66 112 131 64 110 136
4. 243 529 738 361 813 1045
5. 829 1272 1555 1099 1617 1932

 imix-1t1c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.32       1.16 
2. 0.32 1.17

 imix-2t2c-ethip4ipsec1000tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.59       2.13 
2. 0.59 2.15

40ge2p1xl710-ethip4ipsec1000tnlsw-ip4base-policy-aes128gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.47       0.52 
2. 0.48 0.53

3. 32 75 112 32 51 121
4. 197 473 654 184 503 727
5. 1767 2493 2951 1767 2445 2947

 64b-2t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.86       0.95 
2. 0.86 0.95

3. 31 65 120 30 48 99
4. 111 408 614 101 391 635
5. 499 854 1020 342 653 843

 1518b-1t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.34       4.34 
2. 0.34 4.36

3. 43 105 111 40 61 89
4. 132 308 455 111 326 460
5. 1650 2357 2885 1639 2315 2849

 1518b-2t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.65       8.33 
2. 0.66 8.37

3. 35 62 85 37 57 77
4. 90 304 452 130 503 772
5. 558 961 1155 437 890 1137

 imix-1t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.43       1.47 
2. 0.44 1.49

 imix-2t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.79       2.71 
2. 0.80 2.72

40ge2p1xl710-ethip4ipsec1000tnlsw-ip4base-policy-aes256gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.47       0.52 
2. 0.48 0.53

3. 33 62 97 32 60 120
4. 281 669 1002 272 710 1024
5. 1642 2409 2919 1690 2381 2877

 64b-2t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.89       0.98 
2. 0.90 0.99

3. 31 71 104 30 63 76
4. 87 226 341 97 257 425
5. 338 707 875 339 619 808

 1518b-1t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.32       4.11 
2. 0.32 4.13

3. 45 81 114 44 77 106
4. 139 462 666 130 442 612
5. 1725 2463 2987 1714 2461 2959

 1518b-2t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.61       7.76 
2. 0.62 7.84

3. 40 78 93 37 74 102
4. 107 277 406 103 226 295
5. 531 758 944 464 844 1050

 imix-1t1c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.42       1.44 
2. 0.42 1.45

 imix-2t2c-ethip4ipsec1000tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.78       2.67 
2. 0.79 2.69

40ge2p1xl710-ethip4ipsec1tnlhw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.81       2.11 
2. 1.82 2.12

3. 36 85 93 36 50 72
4. 84 153 182 83 116 145
5. 245 291 322 250 299 329

 64b-2t2c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  3.42       3.99 
2. 3.48 4.06

3. 37 76 101 36 73 97
4. 65 112 129 63 78 104
5. 138 166 197 114 142 166

 1518b-1t1c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.35       4.47 
2. 0.35 4.48

3. 88 116 150 75 121 172
4. 235 402 480 228 360 444
5. 828 1090 1249 865 1133 1317

 1518b-2t2c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.67       8.57 
2. 0.67 8.60

3. 75 100 119 73 110 123
4. 177 317 371 158 295 339
5. 388 507 597 360 444 530

 imix-1t1c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.91       3.17 
2. 0.91 3.19

 imix-2t2c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.74       6.06 
2. 1.77 6.18

40ge2p1xl710-ethip4ipsec1tnlhw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.40       1.82 
2. 1.41 1.83

3. 35 69 100 35 64 81
4. 78 130 171 63 159 201
5. 212 265 304 217 263 294

 64b-2t2c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.68       3.47 
2. 2.71 3.51

3. 35 74 92 35 107 126
4. 71 107 136 92 147 181
5. 145 179 203 148 205 235

 1518b-1t1c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.28       3.58 
2. 0.28 3.60

3. 66 96 135 66 97 121
4. 162 252 358 162 302 321
5. 546 705 767 548 705 776

 1518b-2t2c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.53       6.91 
2. 0.54 6.94

3. 66 108 145 66 96 115
4. 305 548 587 206 480 524
5. 452 558 623 500 649 759

 imix-1t1c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.75       2.71 
2. 0.75 2.72

 imix-2t2c-ethip4ipsec1tnlhw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.46       5.29 
2. 1.47 5.30

40ge2p1xl710-ethip4ipsec1tnlhw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.01       3.32 
2. 3.01 3.32

3. 52 82 88 52 93 108
4. 81 120 143 91 118 152
5. 198 219 240 201 225 242

 64b-2t2c-ethip4ipsec1tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  5.02       5.54 
2. 5.09 5.62

3. 55 78 100 52 69 97
4. 64 77 91 68 91 104
5. 121 143 153 108 124 142

 1518b-1t1c-ethip4ipsec1tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.83      48.76 
2. 3.83 48.76

3. 58 82 101 59 80 97
4. 134 156 167 130 150 164
5. 183 196 207 184 197 208

 1518b-2t2c-ethip4ipsec1tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.83      48.76 
2. 3.83 48.76

3. 58 73 91 58 87 107
4. 67 85 94 67 85 97
5. 76 80 83 75 79 83

 imix-1t1c-ethip4ipsec1tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.78       9.50 
2. 2.78 9.53

 imix-2t2c-ethip4ipsec1tnlhw- 
ip4base-int-aes128gcm-ndrpdr

 1.  4.76      16.30 
2. 4.82 16.48

40ge2p1xl710-ethip4ipsec1tnlhw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.01       3.32 
2. 3.01 3.32

3. 52 85 93 52 77 113
4. 79 95 108 76 103 120
5. 198 221 242 198 221 242

 64b-2t2c-ethip4ipsec1tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  5.02       5.55 
2. 5.10 5.63

3. 52 72 96 52 71 82
4. 63 73 85 65 91 103
5. 133 146 157 124 148 158

 1518b-1t1c-ethip4ipsec1tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.83      48.76 
2. 3.83 48.76

3. 60 85 99 61 79 93
4. 138 161 181 137 163 178
5. 185 196 206 185 197 208

 1518b-2t2c-ethip4ipsec1tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.83      48.76 
2. 3.83 48.76

3. 55 69 86 57 81 114
4. 78 101 111 71 88 98
5. 81 85 90 80 85 89

 imix-1t1c-ethip4ipsec1tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.78       9.51 
2. 2.79 9.53

 imix-2t2c-ethip4ipsec1tnlhw- 
ip4base-int-aes256gcm-ndrpdr

 1.  4.78      16.36 
2. 4.83 16.55

40ge2p1xl710-ethip4ipsec1tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  1.72       2.01 
2. 1.74 2.03

3. 36 76 96 36 61 92
4. 83 119 155 83 119 151
5. 243 291 326 242 283 318

 64b-2t2c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  3.22       3.76 
2. 3.26 3.81

3. 45 81 104 36 67 86
4. 68 87 123 73 133 161
5. 112 143 167 135 164 184

 1518b-1t1c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.35       4.43 
2. 0.35 4.45

3. 79 130 159 81 107 120
4. 238 440 499 211 508 561
5. 747 964 1121 787 970 1116

 1518b-2t2c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.66       8.43 
2. 0.66 8.47

3. 75 111 118 75 94 119
4. 212 393 538 186 415 501
5. 433 564 657 464 553 613

 imix-1t1c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.88       3.08 
2. 0.90 3.12

 imix-2t2c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  1.66       5.80 
2. 1.69 5.90

40ge2p1xl710-ethip4ipsec1tnlhw-ip4base-policy-aes128cbc-hmac512sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  1.35       1.75 
2. 1.36 1.76

3. 39 82 103 45 81 89
4. 95 203 269 96 175 216
5. 234 281 329 227 266 321

 64b-2t2c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  2.59       3.36 
2. 2.63 3.41

3. 35 83 92 35 53 88
4. 66 88 129 77 134 165
5. 165 200 216 106 134 162

 1518b-1t1c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.27       3.54 
2. 0.28 3.57

3. 67 80 102 66 82 96
4. 148 389 452 164 323 408
5. 668 921 1110 698 912 1093

 1518b-2t2c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.53       6.82 
2. 0.53 6.85

3. 66 119 145 65 83 95
4. 273 506 581 200 585 628
5. 485 644 709 499 691 776

 imix-1t1c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.73       2.65 
2. 0.74 2.68

 imix-2t2c-ethip4ipsec1tnlhw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  1.42       5.13 
2. 1.43 5.18

40ge2p1xl710-ethip4ipsec1tnlhw-ip4base-policy-aes128gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  3.38       3.73 
2. 3.43 3.79

3. 55 80 112 51 81 111
4. 79 104 119 79 104 123
5. 167 191 208 167 191 209

 64b-2t2c-ethip4ipsec1tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  6.80       7.50 
2. 6.90 7.62

3. 51 70 97 47 67 84
4. 65 79 89 59 75 88
5. 129 146 161 134 150 164

 1518b-1t1c-ethip4ipsec1tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  3.83      48.76 
2. 3.83 48.76

3. 57 77 90 59 81 108
4. 109 129 143 112 134 147
5. 131 138 147 131 139 147

 1518b-2t2c-ethip4ipsec1tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  3.83      48.76 
2. 3.83 48.76

3. 54 75 94 55 80 106
4. 66 83 98 64 79 86
5. 73 77 81 72 76 80

 imix-1t1c-ethip4ipsec1tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  3.12      10.68 
2. 3.13 10.71

 imix-2t2c-ethip4ipsec1tnlhw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  6.17      21.13 
2. 6.25 21.39

40ge2p1xl710-ethip4ipsec1tnlhw-ip4base-policy-aes256gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  3.40       3.75 
2. 3.43 3.79

3. 52 85 110 51 75 96
4. 77 102 117 78 96 111
5. 171 196 215 173 197 215

 64b-2t2c-ethip4ipsec1tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  6.82       7.53 
2. 6.92 7.64

3. 51 75 100 51 67 83
4. 60 75 89 60 74 84
5. 130 147 161 124 140 154

 1518b-1t1c-ethip4ipsec1tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  3.83      48.76 
2. 3.83 48.76

3. 60 87 118 58 75 92
4. 109 136 151 117 144 161
5. 131 138 147 131 139 147

 1518b-2t2c-ethip4ipsec1tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  3.83      48.76 
2. 3.83 48.76

3. 58 72 106 58 80 101
4. 69 85 100 67 84 96
5. 79 83 88 78 83 88

 imix-1t1c-ethip4ipsec1tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  3.11      10.65 
2. 3.12 10.68

 imix-2t2c-ethip4ipsec1tnlhw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  6.18      21.14 
2. 6.25 21.39

40ge2p1xl710-ethip4ipsec1tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.80       2.10 
2. 1.81 2.11

3. 36 72 88 36 56 71
4. 83 117 141 79 113 134
5. 245 286 315 240 282 317

 64b-2t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  3.41       3.98 
2. 3.46 4.04

3. 36 78 97 46 72 97
4. 60 101 113 68 111 133
5. 123 148 173 111 132 150

 1518b-1t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.35       4.47 
2. 0.35 4.48

3. 75 137 174 75 113 141
4. 247 430 492 213 386 427
5. 817 1088 1296 804 1013 1167

 1518b-2t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.67       8.56 
2. 0.67 8.63

3. 75 158 192 75 102 119
4. 305 708 771 210 378 448
5. 609 752 861 436 565 628

 imix-1t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.91       3.17 
2. 0.91 3.18

 imix-2t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.76       6.14 
2. 1.78 6.21

40ge2p1xl710-ethip4ipsec1tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.42       1.84 
2. 1.42 1.84

3. 35 67 90 35 57 73
4. 76 140 158 72 141 170
5. 216 256 283 214 259 282

 64b-2t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.71       3.52 
2. 2.74 3.55

3. 35 78 91 35 77 114
4. 69 102 124 74 150 180
5. 166 209 256 120 152 174

 1518b-1t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.28       3.58 
2. 0.28 3.59

3. 66 103 137 66 80 115
4. 205 324 380 179 313 415
5. 801 1119 1331 862 1160 1314

 1518b-2t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.53       6.90 
2. 0.54 6.92

3. 66 115 146 65 69 92
4. 230 526 596 189 286 357
5. 462 573 621 277 361 405

 imix-1t1c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.75       2.72 
2. 0.75 2.73

 imix-2t2c-ethip4ipsec1tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.45       5.23 
2. 1.46 5.27

40ge2p1xl710-ethip4ipsec1tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.78       3.06 
2. 2.79 3.08

3. 32 55 84 32 43 62
4. 59 84 110 55 81 95
5. 158 186 209 160 189 207

 64b-2t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  4.60       5.08 
2. 4.66 5.15

3. 32 57 80 32 78 91
4. 56 69 86 32 44 53
5. 68 84 100 65 82 93

 1518b-1t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.86      10.95 
2. 0.86 11.00

3. 36 64 92 36 54 83
4. 98 171 259 74 212 279
5. 213 257 308 196 260 276

 1518b-2t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.65      20.96 
2. 1.66 21.17

3. 36 53 64 35 56 76
4. 81 107 129 67 110 128
5. 163 215 242 127 167 195

 imix-1t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.74       5.97 
2. 1.75 5.99

 imix-2t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.36      11.48 
2. 3.38 11.57

40ge2p1xl710-ethip4ipsec1tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.69       2.96 
2. 2.71 2.99

3. 41 70 89 32 62 86
4. 62 92 111 60 82 100
5. 161 190 206 165 192 210

 64b-2t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  4.58       5.06 
2. 4.65 5.13

3. 32 53 70 29 50 80
4. 56 76 84 55 74 87
5. 68 87 103 67 85 101

 1518b-1t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.74       9.39 
2. 0.74 9.43

3. 37 70 96 37 62 92
4. 71 120 170 76 124 162
5. 261 346 403 252 345 411

 1518b-2t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.43      18.24 
2. 1.44 18.38

3. 36 61 99 36 60 77
4. 61 134 198 61 94 122
5. 119 148 175 146 190 226

 imix-1t1c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.62       5.56 
2. 1.63 5.58

 imix-2t2c-ethip4ipsec1tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.18      10.87 
2. 3.20 10.95

40ge2p1xl710-ethip4ipsec1tnlsw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  1.71       2.00 
2. 1.74 2.03

3. 36 76 96 43 80 95
4. 87 121 150 83 120 180
5. 275 325 359 271 310 359

 64b-2t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  3.24       3.78 
2. 3.32 3.88

3. 37 75 102 35 60 86
4. 66 83 110 84 152 182
5. 119 144 162 137 168 207

 1518b-1t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.35       4.43 
2. 0.35 4.45

3. 76 112 151 76 111 122
4. 220 404 482 248 426 482
5. 766 956 1056 786 991 1173

 1518b-2t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.66       8.43 
2. 0.66 8.47

3. 75 142 158 75 136 164
4. 240 587 658 364 665 735
5. 461 624 726 562 713 815

 imix-1t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  0.88       3.08 
2. 0.89 3.10

 imix-2t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac256sha-ndrpdr

 1.  1.69       5.89 
2. 1.70 5.93

40ge2p1xl710-ethip4ipsec1tnlsw-ip4base-policy-aes128cbc-hmac512sha-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  1.36       1.76 
2. 1.37 1.78

3. 36 70 101 36 46 63
4. 82 123 191 74 136 167
5. 247 289 325 239 275 301

 64b-2t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  2.60       3.37 
2. 2.64 3.42

3. 35 91 125 35 73 86
4. 80 144 183 78 128 156
5. 115 147 165 132 184 219

 1518b-1t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.28       3.56 
2. 0.28 3.57

3. 67 104 137 67 102 136
4. 158 282 312 186 298 319
5. 730 904 1068 707 962 1194

 1518b-2t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.53       6.82 
2. 0.53 6.85

3. 66 105 137 66 89 119
4. 299 545 623 427 771 803
5. 538 716 865 705 807 929

 imix-1t1c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  0.73       2.66 
2. 0.74 2.68

 imix-2t2c-ethip4ipsec1tnlsw-ip4base- 
policy-aes128cbc-hmac512sha-ndrpdr

 1.  1.40       5.05 
2. 1.42 5.15

40ge2p1xl710-ethip4ipsec1tnlsw-ip4base-policy-aes128gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  2.57       2.83 
2. 2.59 2.86

3. 34 64 76 32 58 78
4. 78 105 135 51 116 136
5. 149 190 213 144 183 198

 64b-2t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  4.12       4.55 
2. 4.18 4.62

3. 32 60 82 32 58 91
4. 55 79 97 51 70 84
5. 71 88 101 68 86 101

 1518b-1t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  0.84      10.75 
2. 0.85 10.80

3. 36 70 87 36 53 80
4. 87 178 209 79 222 251
5. 256 348 418 279 393 427

 1518b-2t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  1.59      20.30 
2. 1.60 20.42

3. 36 58 80 36 56 73
4. 86 131 157 51 111 141
5. 113 152 180 122 166 194

 imix-1t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  1.67       5.71 
2. 1.68 5.75

 imix-2t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes128gcm-ndrpdr

 1.  3.09      10.58 
2. 3.13 10.71

40ge2p1xl710-ethip4ipsec1tnlsw-ip4base-policy-aes256gcm-ndrpdr

IPv4 IPsec tunnel mode performance test suite.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  2.50       2.76 
2. 2.53 2.79

3. 33 63 69 34 57 79
4. 65 83 97 65 89 105
5. 157 173 189 150 173 203

 64b-2t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  4.14       4.58 
2. 4.20 4.63

3. 36 62 88 38 72 92
4. 51 73 90 51 67 80
5. 71 91 104 69 86 99

 1518b-1t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  0.73       9.24 
2. 0.73 9.27

3. 37 76 93 36 51 60
4. 92 202 260 83 212 239
5. 254 337 394 245 313 354

 1518b-2t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  1.39      17.64 
2. 1.40 17.80

3. 36 64 85 36 96 108
4. 64 126 150 70 144 185
5. 109 145 188 164 225 252

 imix-1t1c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  1.56       5.33 
2. 1.57 5.37

 imix-2t2c-ethip4ipsec1tnlsw- 
ip4base-policy-aes256gcm-ndrpdr

 1.  2.93      10.03 
2. 2.97 10.17

40ge2p1xl710-ethip4ipsec20000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.45       1.69 
2. 1.47 1.72

3. 29 67 97 29 93 115
4. 116 227 337 102 220 300
5. 285 370 2261 292 373 1653

 64b-2t2c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  2.64       3.08 
2. 2.68 3.14

3. 29 88 100 29 79 109
4. 79 125 144 76 144 171
5. 169 198 259 137 194 225

 1518b-1t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.32       4.15 
2. 0.33 4.17

3. 69 121 174 69 97 116
4. 228 395 453 230 314 356
5. 810 1055 1282 851 1095 1373

 1518b-2t2c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.63       8.09 
2. 0.64 8.13

3. 69 162 188 72 104 132
4. 290 596 760 281 532 606
5. 446 577 662 460 592 669

 imix-1t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.77       2.69 
2. 0.78 2.72

 imix-2t2c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.49       5.20 
2. 1.52 5.30

40ge2p1xl710-ethip4ipsec20000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.17       1.52 
2. 1.18 1.53

3. 29 68 109 29 78 104
4. 151 310 388 145 308 371
5. 225 324 2647 233 333 2263

 64b-2t2c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.13       2.76 
2. 2.16 2.79

3. 29 80 87 29 125 155
4. 61 94 113 81 150 169
5. 137 189 350 104 132 167

 1518b-1t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.26       3.32 
2. 0.26 3.34

3. 60 95 101 60 68 83
4. 172 440 493 163 464 530
5. 622 876 961 696 892 1064

 1518b-2t2c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.50       6.52 
2. 0.51 6.56

3. 60 93 118 59 71 96
4. 238 501 553 352 659 716
5. 408 559 656 526 722 804

 imix-1t1c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.64       2.32 
2. 0.65 2.34

 imix-2t2c-ethip4ipsec20000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.25       4.52 
2. 1.27 4.60

40ge2p1xl710-ethip4ipsec20000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.08       2.29 
2. 2.10 2.32

3. 26 77 95 26 80 105
4. 92 177 234 93 179 238
5. 128 190 368 146 205 272

 64b-2t2c-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.83       4.23 
2. 3.87 4.28

3. 25 54 78 25 55 86
4. 60 110 135 53 88 116
5. 119 142 173 107 143 180

 1518b-1t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.73       9.26 
2. 0.73 9.32

3. 29 52 73 29 49 79
4. 63 227 262 75 183 292
5. 341 461 602 331 452 616

 1518b-2t2c-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.43      18.19 
2. 1.44 18.28

3. 29 53 64 29 58 81
4. 72 155 197 84 181 216
5. 140 188 230 141 177 213

 imix-1t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.39       4.74 
2. 1.40 4.79

 imix-2t2c-ethip4ipsec20000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.69       9.21 
2. 2.73 9.34

40ge2p1xl710-ethip4ipsec20000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.95       2.15 
2. 2.04 2.25

3. 26 99 142 26 55 83
4. 97 160 195 93 182 224
5. 149 200 596 149 190 350

 64b-2t2c-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.86       4.27 
2. 3.90 4.31

3. 26 63 80 25 55 76
4. 49 64 80 48 66 87
5. 86 105 124 83 101 116

 1518b-1t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.61       7.83 
2. 0.62 7.86

3. 30 62 101 30 74 82
4. 90 221 249 100 195 238
5. 248 354 427 262 346 415

 1518b-2t2c-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.22      15.54 
2. 1.23 15.70

3. 30 63 75 30 72 83
4. 66 119 136 70 154 209
5. 208 305 374 138 196 233

 imix-1t1c-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.29       4.42 
2. 1.30 4.47

 imix-2t2c-ethip4ipsec20000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.42       8.29 
2. 2.49 8.51

40ge2p1xl710-ethip4ipsec40000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.13       1.32 
2. 1.14 1.33

3. 30 75 105 30 66 94
4. 150 275 367 150 318 382
5. 265 362 509 281 366 523

 64b-2t2c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  2.07       2.41 
2. 2.10 2.45

3. 30 84 90 30 80 106
4. 83 119 142 80 150 175
5. 144 186 222 137 184 223

 1518b-1t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.31       3.97 
2. 0.31 3.99

3. 69 122 147 69 89 105
4. 212 364 398 147 345 387
5. 759 951 1054 786 943 1115

 1518b-2t2c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.61       7.76 
2. 0.61 7.80

3. 72 120 130 68 126 161
4. 198 338 382 270 487 505
5. 424 525 589 560 734 804

 imix-1t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.66       2.29 
2. 0.67 2.33

 imix-2t2c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.23       4.27 
2. 1.25 4.36

40ge2p1xl710-ethip4ipsec40000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.94       1.22 
2. 0.94 1.22

3. 29 88 100 30 81 104
4. 120 293 318 102 238 319
5. 336 451 530 318 438 532

 64b-2t2c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.73       2.25 
2. 1.76 2.28

3. 36 63 93 36 75 97
4. 107 190 248 76 180 250
5. 198 258 301 148 213 268

 1518b-1t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.25       3.23 
2. 0.25 3.26

3. 60 94 101 60 70 104
4. 254 493 534 225 498 586
5. 718 1019 1099 756 1073 1316

 1518b-2t2c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.49       6.28 
2. 0.49 6.35

3. 60 106 127 60 96 114
4. 239 350 467 185 322 414
5. 552 707 805 353 468 542

 imix-1t1c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.57       2.05 
2. 0.57 2.08

 imix-2t2c-ethip4ipsec40000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.07       3.87 
2. 1.09 3.94

40ge2p1xl710-ethip4ipsec40000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.61       1.78 
2. 1.64 1.81

3. 26 57 85 26 47 56
4. 81 183 220 88 144 170
5. 181 228 444 177 239 456

 64b-2t2c-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.00       3.32 
2. 3.05 3.37

3. 32 67 85 32 64 110
4. 71 117 152 69 117 125
5. 147 185 229 99 129 159

 1518b-1t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.67       8.57 
2. 0.68 8.61

3. 30 58 104 30 45 64
4. 79 437 523 131 376 458
5. 353 478 559 347 459 606

 1518b-2t2c-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.31      16.64 
2. 1.31 16.64

3. 30 61 134 30 141 188
4. 107 252 321 157 291 362
5. 256 332 369 250 330 354

 imix-1t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.14       3.90 
2. 1.16 3.97

 imix-2t2c-ethip4ipsec40000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.12       7.26 
2. 2.17 7.43

40ge2p1xl710-ethip4ipsec40000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.58       1.74 
2. 1.59 1.76

3. 32 69 77 32 104 134
4. 111 155 171 126 233 252
5. 224 288 380 221 288 398

 64b-2t2c-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.00       3.31 
2. 3.02 3.33

3. 32 111 191 32 80 141
4. 94 163 184 87 135 165
5. 167 201 256 137 169 200

 1518b-1t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.59       7.56 
2. 0.60 7.59

3. 38 74 91 37 71 94
4. 96 203 258 107 219 304
5. 230 306 348 224 282 315

 1518b-2t2c-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.15      14.60 
2. 1.16 14.79

3. 37 80 94 37 68 86
4. 82 121 151 57 219 256
5. 165 224 266 151 203 240

 imix-1t1c-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.06       3.63 
2. 1.07 3.67

 imix-2t2c-ethip4ipsec40000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.96       6.71 
2. 2.00 6.86

40ge2p1xl710-ethip4ipsec400tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.58       1.84 
2. 1.59 1.86

3. 29 63 80 29 65 82
4. 179 287 313 130 240 268
5. 242 333 428 245 328 401

 64b-2t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  2.97       3.47 
2. 3.02 3.53

3. 30 64 79 33 72 89
4. 67 108 131 71 105 116
5. 133 162 188 134 159 186

 1518b-1t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.34       4.36 
2. 0.34 4.38

3. 68 100 156 68 103 121
4. 259 484 586 254 606 668
5. 838 1115 1278 810 1035 1271

 1518b-2t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.66       8.41 
2. 0.66 8.45

3. 68 106 115 68 103 140
4. 195 409 557 254 408 471
5. 418 580 671 589 778 862

 imix-1t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.84       2.92 
2. 0.85 2.95

 imix-2t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.65       5.74 
2. 1.67 5.83

40ge2p1xl710-ethip4ipsec400tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.27       1.65 
2. 1.28 1.66

3. 29 66 97 29 66 88
4. 81 207 237 98 220 275
5. 227 328 371 230 331 387

 64b-2t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.43       3.14 
2. 2.45 3.18

3. 29 106 124 29 60 81
4. 65 84 145 69 99 119
5. 107 155 189 147 180 206

 1518b-1t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.27       3.50 
2. 0.27 3.52

3. 59 103 118 59 70 94
4. 154 350 432 191 287 363
5. 783 1032 1117 795 1089 1257

 1518b-2t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.53       6.80 
2. 0.53 6.80

3. 59 97 120 59 90 101
4. 278 538 582 212 514 622
5. 456 567 623 510 712 811

 imix-1t1c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.70       2.54 
2. 0.71 2.56

 imix-2t2c-ethip4ipsec400tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.38       4.98 
2. 1.40 5.06

40ge2p1xl710-ethip4ipsec400tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.33       2.57 
2. 2.34 2.59

3. 25 58 64 25 47 60
4. 76 91 106 78 108 134
5. 114 163 198 124 157 194

 64b-2t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  4.23       4.67 
2. 4.25 4.69

3. 25 53 72 25 47 73
4. 45 64 79 44 63 84
5. 76 100 112 61 77 89

 1518b-1t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.81      10.28 
2. 0.81 10.34

3. 29 55 72 29 61 82
4. 52 106 130 65 137 157
5. 227 293 350 220 298 331

 1518b-2t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.60      20.37 
2. 1.61 20.47

3. 29 52 74 29 83 115
4. 115 170 203 106 212 231
5. 160 220 275 124 168 201

 imix-1t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.56       5.33 
2. 1.57 5.36

 imix-2t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.14      10.76 
2. 3.18 10.87

40ge2p1xl710-ethip4ipsec400tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.29       2.53 
2. 2.31 2.55

3. 26 55 62 26 48 59
4. 93 180 212 94 176 212
5. 127 175 191 127 178 198

 64b-2t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  4.22       4.66 
2. 4.24 4.69

3. 26 67 75 25 47 65
4. 47 68 84 48 72 91
5. 74 90 106 77 98 113

 1518b-1t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.70       8.91 
2. 0.70 8.95

3. 30 70 78 32 53 63
4. 95 140 209 69 170 272
5. 321 467 524 323 430 524

 1518b-2t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.39      17.72 
2. 1.40 17.81

3. 29 64 81 29 51 105
4. 52 113 160 64 131 160
5. 182 231 275 126 175 209

 imix-1t1c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.47       5.02 
2. 1.48 5.05

 imix-2t2c-ethip4ipsec400tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.94      10.05 
2. 2.97 10.15

40ge2p1xl710-ethip4ipsec40tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.68       1.96 
2. 1.69 1.98

3. 36 88 106 36 85 134
4. 117 211 265 115 219 245
5. 233 313 380 238 317 381

 64b-2t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  3.18       3.71 
2. 3.22 3.77

3. 36 67 94 36 58 123
4. 71 105 130 68 123 156
5. 152 187 226 151 191 232

 1518b-1t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.34       4.39 
2. 0.35 4.43

3. 75 124 150 75 118 198
4. 290 435 517 224 551 630
5. 784 1037 1238 761 972 1064

 1518b-2t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.66       8.48 
2. 0.67 8.51

3. 74 95 118 75 135 161
4. 169 269 311 166 338 386
5. 462 560 622 400 486 556

 imix-1t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.87       3.03 
2. 0.88 3.06

 imix-2t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.71       5.96 
2. 1.72 5.99

40ge2p1xl710-ethip4ipsec40tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.34       1.74 
2. 1.35 1.75

3. 35 88 124 35 91 112
4. 114 255 266 119 228 283
5. 215 264 309 213 279 311

 64b-2t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.53       3.27 
2. 2.56 3.32

3. 35 68 96 36 91 169
4. 111 169 183 73 118 129
5. 140 152 182 163 226 269

 1518b-1t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.27       3.53 
2. 0.28 3.56

3. 66 93 137 66 85 105
4. 203 374 452 174 497 591
5. 822 1044 1177 882 1183 1402

 1518b-2t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.53       6.87 
2. 0.53 6.89

3. 66 106 146 66 91 115
4. 207 363 419 187 416 582
5. 430 569 611 545 712 749

 imix-1t1c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.73       2.62 
2. 0.73 2.64

 imix-2t2c-ethip4ipsec40tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.41       5.11 
2. 1.44 5.20

40ge2p1xl710-ethip4ipsec40tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.55       2.81 
2. 2.56 2.83

3. 32 67 84 32 98 125
4. 70 101 120 68 103 118
5. 162 211 225 162 218 229

 64b-2t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  4.44       4.90 
2. 4.48 4.95

3. 32 56 90 32 58 82
4. 38 54 64 49 71 85
5. 67 83 94 72 95 112

 1518b-1t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.83      10.58 
2. 0.83 10.62

3. 36 56 74 36 53 74
4. 91 207 236 90 199 238
5. 252 341 426 245 326 365

 1518b-2t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.63      20.80 
2. 1.64 20.88

3. 35 51 73 36 55 72
4. 63 82 98 68 142 160
5. 183 224 252 139 189 220

 imix-1t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.64       5.63 
2. 1.66 5.67

 imix-2t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.27      11.19 
2. 3.29 11.27

40ge2p1xl710-ethip4ipsec40tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.49       2.75 
2. 2.50 2.76

3. 32 66 86 32 76 119
4. 97 156 201 100 186 201
5. 127 202 217 161 208 232

 64b-2t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  4.45       4.91 
2. 4.49 4.96

3. 33 57 84 30 58 91
4. 51 86 106 42 61 81
5. 68 87 104 67 84 100

 1518b-1t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.72       9.11 
2. 0.72 9.15

3. 37 77 95 36 46 63
4. 70 146 179 78 151 180
5. 283 390 493 274 355 417

 1518b-2t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.42      18.08 
2. 1.43 18.20

3. 36 69 85 36 64 83
4. 66 169 201 60 143 168
5. 219 287 319 123 165 206

 imix-1t1c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.53       5.25 
2. 1.55 5.29

 imix-2t2c-ethip4ipsec40tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.09      10.56 
2. 3.12 10.67

40ge2p1xl710-ethip4ipsec4tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.78       2.08 
2. 1.80 2.11

3. 35 99 127 35 117 139
4. 73 189 230 94 168 191
5. 250 316 369 256 320 383

 64b-2t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  3.44       4.02 
2. 3.49 4.08

3. 36 85 103 35 101 144
4. 74 102 110 70 96 112
5. 128 155 175 136 167 204

 1518b-1t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.35       4.45 
2. 0.35 4.47

3. 78 113 158 75 119 171
4. 191 327 395 188 405 490
5. 746 885 1005 734 903 988

 1518b-2t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.67       8.54 
2. 0.67 8.57

3. 75 113 122 72 96 121
4. 167 253 281 156 256 289
5. 424 536 624 366 451 553

 imix-1t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.90       3.15 
2. 0.91 3.16

 imix-2t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.75       6.11 
2. 1.78 6.19

40ge2p1xl710-ethip4ipsec4tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.41       1.82 
2. 1.41 1.83

3. 35 72 103 35 74 123
4. 121 202 232 116 260 299
5. 230 292 335 221 289 345

 64b-2t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.72       3.53 
2. 2.75 3.56

3. 35 78 128 35 40 68
4. 90 160 177 83 154 201
5. 157 187 235 163 218 276

 1518b-1t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.28       3.56 
2. 0.28 3.59

3. 73 102 137 66 102 135
4. 106 390 500 188 316 380
5. 554 714 819 589 752 867

 1518b-2t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.53       6.88 
2. 0.53 6.91

3. 66 103 126 64 96 138
4. 188 283 303 177 395 529
5. 316 401 463 399 520 616

 imix-1t1c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.75       2.69 
2. 0.75 2.71

 imix-2t2c-ethip4ipsec4tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.45       5.26 
2. 1.46 5.29

40ge2p1xl710-ethip4ipsec4tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.75       3.04 
2. 2.76 3.05

3. 32 78 108 32 77 116
4. 82 118 143 63 121 144
5. 148 182 225 123 196 221

 64b-2t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  4.59       5.07 
2. 4.63 5.12

3. 32 53 59 32 69 92
4. 68 80 87 30 50 69
5. 71 91 101 68 87 100

 1518b-1t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.85      10.85 
2. 0.85 10.89

3. 36 70 99 36 54 72
4. 85 222 251 92 191 226
5. 205 261 297 208 258 308

 1518b-2t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.65      21.05 
2. 1.66 21.14

3. 36 57 79 36 60 74
4. 64 170 191 80 144 190
5. 141 180 210 139 184 211

 imix-1t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.73       5.93 
2. 1.74 5.95

 imix-2t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.34      11.44 
2. 3.36 11.50

40ge2p1xl710-ethip4ipsec4tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.67       2.95 
2. 2.70 2.98

3. 32 68 89 31 45 59
4. 73 114 144 57 124 132
5. 152 198 229 116 157 215

 64b-2t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  4.59       5.07 
2. 4.63 5.12

3. 32 54 86 29 43 63
4. 64 77 83 44 58 66
5. 69 88 102 73 94 108

 1518b-1t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.73       9.33 
2. 0.74 9.37

3. 36 62 86 37 55 87
4. 64 158 244 83 122 163
5. 284 353 384 268 343 384

 1518b-2t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.42      18.03 
2. 1.43 18.25

3. 36 71 84 36 54 69
4. 56 105 136 58 84 121
5. 136 171 191 126 167 188

 imix-1t1c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.61       5.52 
2. 1.63 5.56

 imix-2t2c-ethip4ipsec4tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  3.16      10.80 
2. 3.19 10.92

40ge2p1xl710-ethip4ipsec5000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.58       1.85 
2. 1.59 1.85

3. 29 72 105 29 84 116
4. 93 196 208 67 153 196
5. 243 314 395 242 310 408

 64b-2t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  2.95       3.45 
2. 3.00 3.50

3. 52 82 95 30 68 82
4. 65 100 118 69 111 142
5. 116 140 157 160 213 255

 1518b-1t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.34       4.35 
2. 0.34 4.37

3. 69 99 116 69 98 108
4. 263 520 608 261 364 464
5. 900 1206 1349 901 1236 1403

 1518b-2t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.66       8.40 
2. 0.66 8.44

3. 68 96 115 68 101 117
4. 203 324 378 242 426 484
5. 411 509 598 406 543 649

 imix-1t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.83       2.89 
2. 0.84 2.92

 imix-2t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.63       5.67 
2. 1.66 5.79

40ge2p1xl710-ethip4ipsec5000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.27       1.65 
2. 1.28 1.66

3. 29 67 119 29 61 77
4. 110 221 280 98 270 319
5. 229 329 380 227 320 393

 64b-2t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  2.36       3.06 
2. 2.39 3.10

3. 29 62 121 29 48 73
4. 104 139 182 71 172 189
5. 123 172 202 142 190 227

 1518b-1t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.27       3.49 
2. 0.27 3.51

3. 60 99 126 60 68 87
4. 143 419 516 147 369 439
5. 610 884 976 689 864 993

 1518b-2t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.52       6.78 
2. 0.53 6.81

3. 59 81 105 57 96 115
4. 152 300 385 187 538 607
5. 453 560 606 564 738 769

 imix-1t1c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.70       2.51 
2. 0.70 2.54

 imix-2t2c-ethip4ipsec5000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.36       4.92 
2. 1.38 5.00

40ge2p1xl710-ethip4ipsec5000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.33       2.57 
2. 2.34 2.58

3. 25 63 164 25 77 108
4. 76 161 178 88 116 131
5. 116 177 189 125 170 186

 64b-2t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  4.17       4.60 
2. 4.19 4.63

3. 27 54 77 25 54 84
4. 51 81 95 51 78 98
5. 86 109 130 67 88 107

 1518b-1t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.80      10.24 
2. 0.81 10.29

3. 29 56 83 29 78 92
4. 92 130 186 103 210 235
5. 282 407 452 300 402 467

 1518b-2t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.58      20.18 
2. 1.60 20.39

3. 29 74 102 29 53 84
4. 70 152 194 107 227 269
5. 169 223 254 189 239 273

 imix-1t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.54       5.26 
2. 1.54 5.29

 imix-2t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  3.08      10.54 
2. 3.11 10.65

40ge2p1xl710-ethip4ipsec5000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.30       2.54 
2. 2.31 2.55

3. 26 60 83 26 71 95
4. 60 78 91 63 142 157
5. 117 157 187 126 177 194

 64b-2t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  4.18       4.62 
2. 4.22 4.66

3. 43 67 84 26 53 76
4. 51 77 90 53 82 96
5. 83 107 127 84 113 140

 1518b-1t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.70       8.91 
2. 0.70 8.91

3. 30 51 90 30 38 53
4. 114 343 409 135 241 333
5. 338 455 514 327 437 490

 1518b-2t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.38      17.61 
2. 1.40 17.78

3. 29 62 82 29 64 85
4. 90 189 219 96 187 218
5. 209 280 311 122 173 200

 imix-1t1c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.44       4.94 
2. 1.45 4.96

 imix-2t2c-ethip4ipsec5000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.88       9.86 
2. 2.91 9.95

40ge2p1xl710-ethip4ipsec60000tnlsw-ip4base-int-aes128cbc-hmac256sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.07       1.25 
2. 1.07 1.26

3. 36 74 106 36 71 86
4. 98 164 225 96 180 223
5. 351 454 567 344 459 528

 64b-2t2c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.95       2.28 
2. 1.98 2.31

3. 36 91 96 36 101 125
4. 80 148 200 72 168 221
5. 166 214 244 201 261 317

 1518b-1t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.31       3.94 
2. 0.31 3.97

3. 76 125 168 76 109 142
4. 211 323 386 186 308 375
5. 801 962 1097 793 999 1158

 1518b-2t2c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.60       7.69 
2. 0.61 7.76

3. 75 118 136 74 114 155
4. 215 384 416 216 545 601
5. 396 514 622 512 657 775

 imix-1t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  0.64       2.23 
2. 0.65 2.26

 imix-2t2c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac256sha-ndrpdr

 1.  1.17       4.10 
2. 1.21 4.22

40ge2p1xl710-ethip4ipsec60000tnlsw-ip4base-int-aes128cbc-hmac512sha-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.90       1.17 
2. 0.91 1.18

3. 36 78 112 36 73 95
4. 118 254 270 110 301 357
5. 306 461 525 327 450 541

 64b-2t2c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.63       2.12 
2. 1.64 2.13

3. 36 104 125 36 64 119
4. 136 254 287 105 220 244
5. 216 278 374 180 238 265

 1518b-1t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.25       3.24 
2. 0.25 3.25

3. 68 104 109 67 86 102
4. 134 269 363 137 213 236
5. 893 1186 1297 878 1235 1410

 1518b-2t2c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.49       6.28 
2. 0.49 6.38

3. 67 105 119 67 89 103
4. 222 391 425 153 347 477
5. 430 555 589 433 588 644

 imix-1t1c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  0.55       1.99 
2. 0.56 2.01

 imix-2t2c-ethip4ipsec60000tnlsw-ip4base- 
int-aes128cbc-hmac512sha-ndrpdr

 1.  1.03       3.71 
2. 1.05 3.79

40ge2p1xl710-ethip4ipsec60000tnlsw-ip4base-int-aes128gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.52       1.67 
2. 1.53 1.69

3. 33 67 75 33 51 122
4. 88 142 169 47 145 173
5. 217 283 340 222 276 349

 64b-2t2c-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  2.84       3.13 
2. 2.88 3.17

3. 32 79 120 32 71 126
4. 69 108 147 57 103 130
5. 101 121 148 97 119 146

 1518b-1t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  0.67       8.52 
2. 0.67 8.56

3. 37 82 93 37 58 90
4. 84 136 147 73 193 276
5. 312 431 515 323 442 557

 1518b-2t2c-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.28      16.34 
2. 1.29 16.47

3. 37 67 90 37 85 104
4. 62 103 117 72 126 178
5. 208 261 312 162 236 267

 imix-1t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.09       3.74 
2. 1.10 3.78

 imix-2t2c-ethip4ipsec60000tnlsw- 
ip4base-int-aes128gcm-ndrpdr

 1.  1.96       6.70 
2. 1.99 6.82

40ge2p1xl710-ethip4ipsec60000tnlsw-ip4base-int-aes256gcm-ndrpdr

RFC2544: Pkt throughput IPv4 IPsec tunnel mode.

  • [Top] Network Topologies: TG-DUT1-DUT2-TG 3-node circular topology with single links between nodes.

  • [Enc] Packet Encapsulations: Eth-IPv4 on TG-DUTn, Eth-IPv4-IPSec on DUT1-DUT2

  • [Cfg] DUT configuration: DUT1 and DUT2 are configured with multiple IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it and send to another DUT, where packets are decrypted and sent back to TG

  • [Ver] TG verification: TG finds and reports throughput NDR (Non Drop Rate) with zero packet loss tolerance and throughput PDR (Partial Drop Rate) with non-zero packet loss tolerance (LT) expressed in percentage of packets transmitted. NDR and PDR are discovered for different Ethernet L2 frame sizes using MLRsearch library. Test packets are generated by TG on links to DUTs. TG traffic profile contains two L3 flow-groups (flow-group per direction, number of flows per flow-group equals to number of IPSec tunnels) with all packets containing Ethernet header, IPv4 header with IP protocol=61 and static payload. MAC addresses are matching MAC addresses of the TG node interfaces. Incrementing of IP.dst (IPv4 destination address) field is applied to both streams.

  • [Ref] Applicable standard specifications: RFC4303 and RFC2544.

 Test Name 

 Throughput: 
1. Mpps Gbps (NDR)
2. Mpps Gbps (PDR)

One-Way Latency Percentiles in uSec at %PDR load,
one set per each direction:
3. P50 P90 P99 P50 P90 P99 (10% PDR)
4. P50 P90 P99 P50 P90 P99 (50% PDR)
5. P50 P90 P99 P50 P90 P99 (90% PDR)

 64b-1t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.49       1.65 
2. 1.50 1.66

3. 33 72 84 33 69 96
4. 92 192 291 134 248 268
5. 201 262 322 195 264 326

 64b-2t2c-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  2.83       3.12 
2. 2.87 3.16

3. 32 100 146 32 55 113
4. 79 128 159 77 149 182
5. 174 223 278 161 202 247

 1518b-1t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  0.59       7.53 
2. 0.60 7.58

3. 37 74 91 38 74 99
4. 92 185 267 90 156 254
5. 350 476 558 364 487 563

 1518b-2t2c-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.14      14.46 
2. 1.15 14.61

3. 37 69 100 37 90 99
4. 172 296 327 112 220 271
5. 250 320 352 216 275 312

 imix-1t1c-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.03       3.53 
2. 1.04 3.57

 imix-2t2c-ethip4ipsec60000tnlsw- 
ip4base-int-aes256gcm-ndrpdr

 1.  1.85       6.34 
2. 1.89 6.47