Network performance impact on OpenShift Container Platform 4 when configure IPsec with OVN-Kubernetes network plugin
Issue
- While evaluating
OVN-Kubernetes
we also enabledIPsec
to secure traffic between nodes and found that onceIPsec
is enabled, we only achieve about 1/4 of the throughput vs. whenIPsec
is actually disabled. Can you please help us understand why this is (some impact is expected but not that much). - We have enabled
IPsec
encryption forOVN
following Configuring IPsec encryption. Afterwards, network bandwidth tests withiperf
showed a heavy impact on the network performance.- Without ipsec:
~8Gbit/sec
- With ipsec:
~2Gbit/sec
- Without ipsec:
Environment
- Red Hat OpenShift Container Platform (RHOCP) 4
OVN-Kubernetes
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.