AES-GCM for Forticlient IPSec?
Hi everyone - posted something but was "marked as spam" perhaps due to external HTML links. Posting again without the links.
Has anyone successfully set up AES-GCM encryption for Forticlient IPSec Phase 2 connection?
Seeing some per-core limitations for IPSec throughput using AES-CBC as it's not parallelizable and hoping that AES-GCM will be better on the client side. On a 1Gbps - 1Gbps connection a client 5900X Ryzen maxes out one core and limits throughput to about 650 Mbps.
We have a 100F so AES-GCM should be offloadable to SOC4 NP6Lite.
Hoping to get more throughput effciency. it's very confusing as to whether AES-GCM can be used with RADIUS xauth for MFA as well.
Also, does anyone know what the difference is between "suite-b gcm" and AES-GCM? are these the same? They are named differently on different Fortinet versions.
Thank you all in advance. Been trying to get this going for over 2 years now.
