ASA - crypto hardware processing
When implementing DH groups for Phase 1 key exchange of a VPN connection on a Cisco ASA device, it is best practice (if possible) to enable hardware processing instead of software processing. This reduces the CPU load.
This can be achieved using the following command:
crypto engine large-mod-accel
The command was introduced in ASA version 8.3(2) and is available on the ASA 5510, 5520, 5540, and 5550 platforms.
Links
https://sec.cloudapps.cisco.com/security/center/resources/next_generation_cryptography#14