How is IPsec forwarding performance affected by the number of Security Associations (SA) and by the number of selectors (SPD entries)?
SA lookup in the fast path is based on a 16-bit hash table so that the number of SA does not significantly impact performance. With regards to the number of selectors, a threshold enables switching from linear search to a trie-based look-up algorithm, depending on the number of entries in the SPD. This enables adjusting the balance between lookup performance and memory usage. Detailed performance test results showing that the number of processed IPsec packets per second is directly proportional to number of cores are available.