New features in SNS 3.7.21 LTSB

System

IPsec VPN

Support reference 81691

On SN510, SN2000, SN2100, SN3100 and SN6100 models, the mechanism that optimizes the distribution of the IPsec service’s encryption and decryption operations has been modified to enhance its performance. This is especially useful when it is used in an encryption operation in which plaintext traffic arrives on the incoming interface and leaves the outgoing interface as encrypted traffic.

For this specific use case, CPUs that will process the IPsec service’s packets on the firewall can be distributed in a static manner. This setup can only be configured with the following CLI/serverd command:

CONFIG IPSEC CRYPTOLB UPDATE ifincoming=<interface> ifoutgoing=<interface> state=<0|1>