Quick Question on IPsec Offload with Bond + ConnectX-6 Dx

Hi NVIDIA Team,

Do you support Linux IPsec/XFRM hardware offload when configured on a bond interface (for example bond0) and traffic goes over active slave ConnectX-6 Dx ports?

If yes, please also confirm any required driver/firmware/kernel versions and supported bonding modes.

Thanks,
Rajiv

Hi,

Thanks for your questions:

According to DOCA 3.3.0 documentation:

Section 2.2.5.2
IPsec Offload for Active-Passive Bonding – Active-passive bonding aggregates
multiple network devices into a single logical interface for higher redundancy.
While bonding already supported IPsec offload, this completes full support by
adding correct IPsec GSO offload and fixing several race conditions around
failover.

Following to my check, only IPSEC crypto offload is supported at the moment with active-backup bond (not packet offload or other bonding modes)

According to section 5.6.2.2.20 IPsec Packet Offload section, kernel this feature requires Linux kernel v6.6, or higher. (this is about IPSEC packet offload in general, bonding is not mentioned)

DOCA 3.3.0 supported firmware is listed in the below section:
2.2.6.1 Supported Platforms and NIC Firmware Versions

Best Regards,
Anatoly

Thanks for your response, and yes we are trying with v6.8 kernel but full packet offload is working ONLY for slave interfaces but not on the bond interfaces.

Hi,

As I mentioned in the answer, crypto offload is currently supported, but not the full packet offload.

Best Regards,

Anatoly