In R80.40, if AES-NI (Intel Advanced Encryption Standard New Instructions) is supported and enabled and configured automatically, there is no longer any user configuration for AES-NI to enable or disable it.
Starting from R80.40, AES-NI related debug messages are no longer sent to
dmesg, and consequently cannot be found with
dmesg | grep 'AES-NI'
For R80.30 and below, use this command on the Security gateway:
# dmesg | grep 'AES-NI'
The expected output which indicates that AES-NI is enabled should be as follows:
[fw4_0];VPN-1: AES-NI is allowed on this machine. Testing hardware support
[fw4_0];VPN-1: AES-NI is supported on this hardware