IPsec Scalability Limits

Scalability limits may affect the use of IPsec.

The RUCKUS ICX 7450 supports encryption and decryption on the ICX7400-SERVICE-MOD module. Encryption and decryption are hardware-based and are not performed by the software (the IKEv2 key exchanges are performed by the software).

One ICX7400-SERVICE-MOD module can be installed per device or per stack. The ICX7400-SERVICE-MOD module supports a maximum of 100 IPsec IPv4 or IPv6 tunnels. If you try to configure more than 100 tunnels, an error message displays. To configure a new IPsec tunnel when the maximum number of tunnels is already configured, you must remove an existing tunnel.

Limits also apply to the elements that are used to configure IPsec tunnels. The element thresholds are set out in the following table.

Tunnel Element Thresholds

Tunnel Element IPsec Module Threshold

 IKE session 
				

20
 IKE SA 
				
20 (IKEv2 SAs are bidirectional)
 IPsec SA 
				
This one previously said 40 IPsec SAs were needed for 20 IKE tunnels. Does that mean that 200 IPsec SAs are required now?
40 (40 IPsec SAs are needed for 100 IKE tunnels or sessions because IPSec SAs are unidirectional; one for ingress and one for egress)
 IKE proposal 
				
20 
			 
 IKE policy 
				
20 
			 
 IKE profile 
				
20
IPsec proposal 
				
20 
			 
IPsec profile 
				
20