Has anyone turned on FL-4320-HSEC-K9 for stronger IPSec performance on the 4320?
Briefly

Has anyone turned on FL-4320-HSEC-K9 for stronger IPSec performance on the 4320?
"I am looking into the FL-4320-HSEC-K9 license for an ISR 4320 that is starting to feel the pressure from growing encrypted traffic. We added more site to site tunnels and some remote access VPN load, and the router seems to hit its crypto ceiling faster than expected. From what I understand, the HSEC license removes the export controlled cap so the router can use its full encryption capability."
"If anyone has enabled this recently, did you notice a real bump in IPSec throughput or tunnel stability, or was the improvement minimal? Also curious if the activation required a specific IOS XE release to avoid errors. Any insights or firsthand experiences would help a lot."
An ISR 4320 is approaching its crypto processing limits due to additional site-to-site tunnels and increased remote-access VPN load. The FL-4320-HSEC-K9 license removes the export-controlled encryption cap, permitting the router to utilize its full hardware crypto capability. Expected benefits include higher IPSec throughput and improved tunnel stability, though real-world gains depend on traffic mix, packet sizes, and CPU offload. Activation may require a specific IOS XE release or activation procedure to avoid errors during licensing. Empirical reports on throughput improvements and any version-specific activation issues are needed to validate performance expectations.
[
|
]