ASA - crypto hardware processing

When implementing DH groups for Phase 1 key exchange of a VPN connection on a Cisco ASA device, it is best practice (if possible) to enable hardware processing instead of software processing. This reduces the CPU load.

This can be achieved using the following command:

crypto engine large-mod-accel

The command was introduced in ASA version 8.3(2) and is available on the ASA 5510, 5520, 5540, and 5550 platforms.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/crypto-a-to-crypto-ir-commands.html#wp2386520637

https://sec.cloudapps.cisco.com/security/center/resources/next_generation_cryptography#14