Skip to content

Commit

Permalink
ixgbe: add ipsec hw offload note to ixgbe Documentation
Browse files Browse the repository at this point in the history
Add a short note about using IPsec Hardware Offload with
the ixgbe driver.

Signed-off-by: Shannon Nelson <shannon.nelson@oracle.com>
Tested-by: Andrew Bowers <andrewx.bowers@intel.com>
Signed-off-by: Jeff Kirsher <jeffrey.t.kirsher@intel.com>
  • Loading branch information
Shannon Nelson authored and Jeff Kirsher committed Nov 21, 2018
1 parent 11c6c0c commit b3c4d7c
Showing 1 changed file with 13 additions and 0 deletions.
13 changes: 13 additions & 0 deletions Documentation/networking/ixgbe.rst
Original file line number Diff line number Diff line change
Expand Up @@ -501,6 +501,19 @@ NOTE: This feature can be disabled for a specific Virtual Function (VF)::

ip link set <pf dev> vf <vf id> spoofchk {off|on}

IPsec Offload
-------------
The ixgbe driver supports IPsec Hardware Offload. When creating Security
Associations with "ip xfrm ..." the 'offload' tag option can be used to
register the IPsec SA with the driver in order to get higher throughput in
the secure communications.

The offload is also supported for ixgbe's VFs, but the VF must be set as
'trusted' and the support must be enabled with::

ethtool --set-priv-flags eth<x> vf-ipsec on
ip link set eth<x> vf <y> trust on


Known Issues/Troubleshooting
============================
Expand Down

0 comments on commit b3c4d7c

Please sign in to comment.