Network performance impact on OpenShift Container Platform 4 when configure IPsec with OVN-Kubernetes network plugin
Issue
- While evaluating
OVN-Kuberneteswe also enabledIPsecto secure traffic between nodes and found that onceIPsecis enabled, we only achieve about 1/4 of the throughput vs. whenIPsecis actually disabled. Can you please help us understand why this is (some impact is expected but not that much). - We have enabled
IPsecencryption forOVNfollowing Configuring IPsec encryption. Afterwards, network bandwidth tests withiperfshowed a heavy impact on the network performance.- Without ipsec:
~8Gbit/sec - With ipsec:
~2Gbit/sec
- Without ipsec:
Environment
- Red Hat OpenShift Container Platform (RHOCP) 4
OVN-Kubernetes
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.