Skip to main content

Scaling Secure Network Functions: High-Performance IPsec with FD.io VPP for VNFs and CNFs

H.1302 (Depage) | Day 1 | 14:05 - 14:25 | Speakers: Benoît Ganne

Scaling Secure Network Functions: High-Performance IPsec with FD.io VPP for VNFs and CNFs
A picture of a devroom at FOSDEM 2024
Open in browser
Get involved in the conversation!Join the chat

Notes

Abstract

As enterprises and service providers transition to virtualized and cloud-native infrastructures, the need for scalable, high-performance security becomes critical. FD.io's Vector Packet Processing (VPP) platform has emerged as a leading open-source framework for fast packet processing, but how well does it handle modern IPsec workloads in Virtual Network Functions (VNFs) and Cloud-Native Network Functions (CNFs)?

In this talk, we dive deep into the architecture and implementation of IPsec within FD.io VPP. We'll explore real-world performance benchmarks, discuss recent improvements, and present best practices for deploying secure, high-throughput IPsec tunnels in containerized and virtualized environments. Attendees will see how VPP's modular pipeline enables flexible integration with orchestration systems, and how it can be tuned for different network function scenarios-from high-density edge sites to large-scale data centers.

Whether you're building secure SD-WAN, 5G core, or edge networking solutions, this session will provide actionable insights on leveraging open-source VPP to deliver robust, scalable, and efficient IPsec-powered VNFs and CNFs.

Key Takeaways: - How FD.io VPP implements and accelerates IPsec for virtualized and cloud-native deployments - Tuning and scaling techniques for maximizing IPsec throughput and minimizing latency - Integration patterns for orchestration and real-world deployment considerations - Lessons learned from operational use cases and performance testing

Join us to learn how open-source innovation is redefining secure, high-performance networking for the next generation of infrastructure!

Attachments

Speakers

Benoît Ganne

Benoît Ganne is an active contributor to the open-source FD.io Vector Packet Processing (VPP) project, a leading framework for high-performance userspace networking. As a VPP committer, he plays a key role in the project's development, focusing on scalable and efficient network functions. Benoît's expertise lies in leveraging open-source solutions to address complex networking challenges in virtualized and cloud-native environments.


Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.