Updating BIOS and the Intel Management Engine firmware

This section sets out the steps to follow in order to update BIOS on SN-L-Series (SN-L-Series-2200SN2200 and SN-L-Series-3200SN3200) model firewalls to version R1.07 in console mode from a USB drive.

Connecting devices to SNS firewalls

  • Connect the computer to the SNS firewall using a USB-A to USB-C cable (SNS firewall side) or an RJ45 to DB9 serial cable (RS232).

    - or -

  • Connect a USB keyboard and a monitor to the SNS firewall using an HDMI cable.
Front panel   Rear panel

 

1: USB-C serial port in console mode

2: RJ45 serial port in console mode

3: USB 3.0 port

 

1: On/off button

2: USB port 3.0

3: HDMI port: for plugging in the monitor

4: Mains sockets for redundant power supplies

Checking the current BIOS version

  1. Log in to the SNS firewall system in console or SSH mode.
  2. Authenticate by using the admin account on the SNS firewall system.
  3. Enter the command:

    dmidecode -s bios-version

    The SNS firewall should show version R1.02, R1.05 or R1.06.

Disabling Secure Boot

The update procedure requires Secure Boot to be disabled so that the SNS firewall can start up on the USB drive that was prepared earlier.

To disable Secure Boot, refer to the section Disabling the Secure Boot feature in the technical note Managing Secure Boot in SNS firewalls' UEFI.

Updating BIOS and the Intel Management Engine firmware

IMPORTANT
The update process is automatic and lasts around five minutes. Once the process is run, it must never be interrupted, and the SNS firewall must not be disconnected from the power supply. If this occurs, the SNS firewall will be completely unable to run.

  1. As SN-L-Series firewalls have two internal power supply units to provide a redundant power supply, ensure that you have plugged in both power cords to the electrical mains.
  2. Insert the USB drive that was prepared earlier into a USB port.
  3. Restart the SNS firewall by using the command:

    reboot

  4. Please wait while updating. When the update is complete, the following message is displayed:

    Confirmation of SN-L-Series BIOS update

  5. Remove the USB drive.

  6. Restart the firewall by using the command:

    reset

Checking the BIOS and Intel Management Engine firmware versions after the update

  1. Once the SNS firewall starts up, press [Del] several times to stop its startup sequence, and access BIOS.
  2. Go to the Main tab and check the following versions:
    1. BIOS Version field: the version that appears should be R1.07.
    2. ME Firmware Version field: the version that appears should be 16.1.38.2676.
  3. Quit BIOS.

Required operations following an update

Once you have updated BIOS, launch the following operations, in this order.

NOTE
The Secure Boot feature does not need to be activated again. Updating the BIOS to version R1.07 restores the default activation of Secure Boot on the SN-L-Series firewall.

Configuring the password to access the UEFI control panel

If you have defined one, it is deleted in the case of a BIOS update from version R1.02. You will need to set it again. To set a new password, refer to the technical note Protecting access to the configuration panel of the UEFI on SNS firewalls.

If BIOS is being updated from version R1.05 or R1.06, you do not need to perform any operation as the password will be retained.

Resealing the TPM

If you had initialized the TPM, the features that use certificates with TPM-protected private keys (VPN, SNS firewall managed by an SMC server, etc.) will no longer function. To restore the features in question, follow one of the procedures below to reseal the TPM.

From the web administration interface

This use case is exclusive to SNS 4.8.7 and higher versions. For earlier SNS versions, you must perform this operation from the CLI console.

  1. Log in to the SNS firewall web administration interface. A window prompts you to seal the TPM module of the SNS firewall.

    Password window to seal the TPM

  2. Enter the TPM module administration password in the relevant field.
  3. Click on OK.
  4. If the SNS firewall is part of a high availability cluster, a second window prompts you to seal the TPM module of the passive firewall. Enter the TPM module administration password and click on OK.

From the CLI console

  1. Seal the TPM on the SNS firewall with the command:

    SYSTEM TPM PCRSEAL tpmpassword=<password>

    Replace <password> with the TPM module administration password.

  2. If the SNS firewall is part of a high availability cluster, seal the TPM on the passive firewall with the command:

    SYSTEM TPM PCRSEAL tpmpassword=<password> serial=passive