What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Intel QuickAssist Technology (QAT) can raise IPsec encryption throughput per CPU core when the platform and software actually offload supported cryptographic work to the accelerator. It does not guarantee a 40Gbps VPN: the result depends on the QAT generation, CPU and memory layout, network interfaces, IPsec software path, cipher, packet size, and traffic pattern. The 2017 ServeTheHome article and Intel’s later VPP benchmark describe different tests and should not be treated as a single, repeatable 40GbE result.

What the 40GbE test was designed to establish

ServeTheHome published Intel QuickAssist at 40GbE Speeds: IPsec VPN Testing on February 6, 2017. It examined VPN throughput between networks and the CPU requirements of QAT VPN nodes, using two accelerator families built on Intel’s Coleto Creek 8955 chipset: Netgate CPIC-8955 accelerators and Intel QuickAssist Adapter 8950 cards.

The article says dual 10GbE links were not sufficient to test the higher-end cards’ network capacity; at least 40GbE was needed. That is a statement about the test’s network capacity requirement, not evidence that a complete VPN system delivered 40Gbps of encrypted traffic. In the 2017 article, the CPIC-8955 was described as rated for up to 50Gbps of QAT throughput. An accelerator’s nominal rating is not an end-to-end VPN result: the NICs, host, software, and traffic conditions can each constrain delivered throughput.

The Intel 8950 cards were also noted to need suitable chassis airflow. Both the card models and performance descriptions belong to a historical test. They do not establish current availability, present-day driver support, or compatibility with current systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Intel’s later VPP benchmark measured

Intel’s separate application note, whose benchmark testing is identified as current through March 20, 2019, gives a useful comparison of QAT hardware with CPU-based cryptography. It is not a rerun of the ServeTheHome test and does not report a generic 40GbE appliance result.

VPP IPsec configuration Intel-reported throughput What the figure means
AES-NI multi-buffer software 12.75Gbps per physical core Per-core result for the documented Intel VPP test configuration.
QAT hardware 28.7Gbps per physical core Per-core result for the same documented test setup using QAT hardware.

Intel calculated the difference as a 2.25x per-core improvement in that test. Its application note says the software configuration would need eight physical cores to reach 100Gbps, compared with 3.5 cores for QAT at the measured per-core rate. These are Intel’s configuration-specific calculations, not a guarantee that a VPN appliance will reach either aggregate rate or use a fractional core in practice. Intel characterized the result as freeing compute capacity for more virtual network functions; that is the vendor’s interpretation of its benchmark.

The benchmark setup matters

Intel tested VPP IPsec through the DPDK Cryptodev API on a second-generation Intel Xeon Scalable platform. The setup used AES-128-GCM, 1420-byte packets, an Intel X710 NIC with four 10GbE ports, and two IPsec devices under test (DUTs). The appendix names a Xeon Gold 6230 at 2.10GHz and a C620-series chipset. Traffic was encrypted and decrypted between the two DUTs, ran bidirectionally, and used fixed keys rather than negotiated keys.

Those details affect comparison with another test. A live tunnel may have different key handling, packet sizes, traffic direction, and software overhead. Intel also cautions that performance varies with systems, components, software, operations, and functions. Do not use its per-core figures as a direct prediction for a different accelerator generation, cipher, NIC, or VPN implementation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why installing QAT hardware may not improve VPN throughput

QAT accelerates supported cryptographic operations; it does not automatically accelerate every stage of IPsec or the whole network path. The selected application, library, driver, and runtime must expose and use the accelerator. If the VPN software continues to process crypto on the CPU, adding a QAT card alone does not establish that offload is occurring.

Intel identifies Linux native IPsec and OpenVPN as integration examples, and its implementation guide lists FD.io VPP among projects updated for QAT. These are distinct software paths, not interchangeable setup instructions. Confirm that the exact platform and versions in use support the intended integration, then verify from application or device telemetry that cryptographic jobs are reaching the accelerator.

For OpenSSL-based integrations, Intel’s QAT repository recommends the Provider interface for OpenSSL 3.x and later. It states that the legacy Engine interface is unsupported in OpenSSL 4.0 and later. Check version-specific QAT support before choosing an integration; guidance for an older OpenSSL release should not be assumed to apply to a newer one.

How to run a meaningful QAT-versus-CPU IPsec test

A useful test changes the cryptographic path while holding the rest of the system as constant as practical. Decide first whether the question is aggregate throughput, throughput per physical core, CPU utilization, latency, or power. These metrics answer different questions: a per-core gain does not by itself establish lower latency, lower power, or higher total throughput.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Record the test platform. Note the exact accelerator model and generation, CPU model and allocated physical cores, memory configuration, NUMA topology, NIC model and port count, link capacity, firmware, drivers, and relevant software/runtime versions.
  2. Document the IPsec path. Name the implementation (for example, VPP, Linux native IPsec, or OpenVPN), the QAT integration and API, and the cipher and authentication algorithm. Verify whether the run uses QAT or CPU software crypto rather than inferring it from installed hardware.
  3. Set and report traffic conditions. Include packet sizes, offered load, flow count if relevant, and whether traffic is unidirectional or bidirectional. State whether keys are fixed or negotiated, since Intel’s VPP test used fixed keys.
  4. Establish a baseline, then change one variable. Measure the same network and software path with CPU crypto and with verified QAT offload. Keep the cipher, packet sizes, traffic generator, and core allocation consistent where possible; if a setting must change, record it.
  5. Measure more than a headline speed. Record aggregate throughput and per-core throughput separately, plus CPU utilization. Include latency and power only if measured, and describe how they were measured. Run long enough to check for stable performance rather than relying on a peak reading.
  6. Report the constraints and outcome. State offered versus achieved load, link utilization, packet loss or errors, and any bottleneck observed. A result limited by a 10GbE port, for example, cannot establish the accelerator’s maximum cryptographic capacity.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Platform tuning that can change results

Memory alignment and NUMA placement

Intel’s tuning guidance recommends 64-byte alignment for QAT engine data. On dual-processor systems, it recommends using memory local to the NUMA node connected to the accelerator for data submitted to that device. Poor alignment or remote memory access can add overhead and make a comparison less representative of the device’s cryptographic capacity.

Queue behavior on QAT Gen 4

Intel separately documents queue behavior under stress for QAT Gen 4: overly aggressive dequeue requests can prevent the device from keeping up with responses. This is a generation-specific tuning consideration. It should not be projected onto the Coleto Creek 8955 cards used in the 2017 ServeTheHome test without evidence for that hardware and software path.

What can and cannot be concluded

  • The historical ServeTheHome article establishes why a network path of at least 40GbE was needed for its higher-end card test and identifies the tested 8955-based accelerator families. The available figures here do not establish an exact VPN throughput result from that test.
  • Intel’s later VPP benchmark reports a 2.25x per-core advantage for QAT over AES-NI multi-buffer software in its specified setup. It is comparative vendor benchmark evidence, not independent validation on contemporary hardware.
  • Neither the 2017 article nor Intel’s VPP result makes QAT a universal 40GbE VPN speed multiplier. A reproducible result belongs to its exact hardware, software, cipher, packet, and traffic configuration.

The 8950/Coleto Creek 8955 hardware is legacy relative to the present day. The cited material does not establish its current price or availability. Anyone recreating the historical environment should confirm host requirements, cooling, firmware, driver support, and software compatibility before sourcing a card.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.