Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

BIOS Installation Guide for Skyhigh Web Gateway Appliances

Mapping from EWS/MEG to WBG

Table helps to maps Email and Web Security models to Skyhigh Web Gateway models and to BIOS packages:

Hardware Model EWS Model SWG Model
Dell CR100 3000 or 3100 WW 500
Dell R200 3200 WW 1100
Dell R610 3300 or 3400 WG 5000
     
Intel SR1530 3000 or 3100 WBG-4000-B
Intel SR1625 3300 WBG-5000-B
Intel SR1630 3200 WBG-4500-B
Intel SR2625 3400 WBG-5500-B

Installing a New BIOS

Dell Hardware

To install a BIOS package on a Dell appliance, perform the following steps:

  1. Download the correct BIOS package for your model from the Skyhigh Content & Cloud Security Portal.
  2. Extract the ZIP file (if applicable, some versions are available as ISO image already).
  3. Burn the included ISO image to CD.
  4. Boot the appliance from the CD and follow the steps on the screen to install the BIOS.

Intel Hardware Model B

Consider the version that will be installed and the appliance model the BIOS is being installed on and refer to the appropriate section below.

WBG-4000-B

For a WBG-4000 appliance, execute the following commands first and write down result. This will be needed during BIOS installation.

  • dmidecode -s system-serial-number
  • dmidecode -s chassis-serial-number

To install a BIOS package on a Intel appliance, perform the following steps:

  1. Download the correct BIOS package for your model from the Skyhigh Content & Cloud Security Portal.
  2. Extract the ZIP into the root directory of a USB drive that is formatted in Microsoft DOS mode.
  3. Attach the USB drive to your appliance.
  4. Restart your appliance.
  5. When prompted, press F2 to enter the setup menu.
  6. Navigate to Boot Manager and select EFI Shell. The appliance is restarted in EFI shell mode. The EFI shell mode runs the startup.nsh procedure from the USB drive which will install the BIOS package.

 The process takes up to 30 minutes to complete. The BIOS installation process of a WBG-4000 appliance will prompt for the serial numbers you wrote down earlier.

WBG-4500-B, WBG-5000-B and WBG-5500-B

To install a BIOS package on a Intel appliance, perform the following steps:

  1. Download the correct BIOS package for your model from the Skyhigh Content & Cloud Security Portal.
  2. Extract the ZIP into the root directory of a USB drive that is formatted in Microsoft DOS mode.
  3. Attach the USB drive to your appliance.
  4. Restart your appliance.
  5. When prompted, press F6 to enter the boot menu.
  6. Select EFI Shell.
    The appliance is restarted in EFI shell mode. The EFI shell mode runs the startup.nsh procedure from the USB drive which will install the BIOS package.

 The process takes up to 30 minutes to complete.

WBG-5000-B and WBG-5500-B with BIOS Package 024, 034

If you enable RMM3 (Intel Remote Management Module 3/ Remote Access Card), do not log on to the Web User Interface of the RMM3 during the package installation as this may interrupt applying the firmware.

 To upgrade the BIOS, perform the following steps:

  1. Download the correct BIOS package for your model from the Skyhigh Content & Cloud Security Portal. (see above table).
  2. Extract the ZIP into the root directory of a USB drive that is formatted in Microsoft DOS mode. NOTE: FAT 12, 16, and 32 formats are supported.
  3. Attach the USB drive to your appliance.
  4. Restart your appliance.
  5. When prompted, press F6 to enter the boot menu.
  6. Select EFI Shell. The appliance is restarted in EFI shell mode. The EFI shell mode runs the startup.nsh procedure from the USB drive which will install the BIOS package.
  7. If the hardware validation fails, follow the instructions displayed in the screen. The validation can be retried twice. If it fails three times, then remove power for several minutes (see later)

The process takes up to 30 minutes to complete. When the EFI Shell prompt appears, the update process is finished.

There is a small chance, the SDR firmware update will stop responding. If you come across the issue, follow these steps to recover:

  1. Wait for about 30 minutes to confirm if the update has stopped responding.
  2. Press CTRL+ALT+DELETE and reboot the appliance.
  3. Return to step 5 and resume the package installation. 

 To confirm the BIOS version is correctly applied:

  1. At the boot screen, press F2 to enter Setup and go to the Main menu.
  2. See the Version and confirm if the BIOS firmware is S5500.86B.01.00.0063. The last 4 digits indicate that the BIOS firmware version installed is 0063.
  3. Go to Server Management, System information.
  4. Locate HSC Firmware Revision and confirm that the HSC firmware version is 2.17.

 clipboard_ee6f82c28cd5e11d09a8e0ad33e0066df.png

clipboard_e5a16619758197278a6c6b5003b5eb2ac.png

Troubleshoot when the validation failure occurs afterthree times:

  1. Power down the appliance.
  2. Disconnect the power lead from the appliance and wait several minutes.
  3. Connect the power lead and power on the appliance.
  4. At the BIOS boot screen, enter boot menu by pressing F6. Select Internal EFI Shell and retry the BIOS package update again.
 WBG-5000-B and WBG-5500-B with BIOS 035

This BIOS package is special as it contains only the BIOS cap to address INTEL-SA-00045. Before applying this packages, it is recommended to upgrade to version 034
first.

Perform the following steps to upgrade to version 034:

  • Stage 1
    • Reboot the appliance
    • When prompted, press F6 to enter the boot menu.
    • Select EFI Shell.
    • The appliance is restarted in EFI shell mode. The EFI shell mode runs the startup.nsh procedure from the USB drive which will install the first stage BIOS after pressing a key.
    • The system will reboot automatically.
  • Stage 2
    • When prompted, press F6 to enter the boot menu.
    • Select EFI Shell.
      The appliance is restarted in EFI shell mode. The EFI shell mode runs the startup.nsh procedure from the USB drive which will install the second
      stage BIOS automatically.
    • The system will reboot automatically.
  • Stage 3
    • When prompted, press F6 to enter the boot menu.
    • Select EFI Shell.
      The appliance is restarted in EFI shell mode. The EFI shell mode runs the startup.nsh procedure from the USB drive which will install the third stage BIOS automatically.
    • When finished a prompt will appear. Remove USB key and restart.

 The BIOS package did not allow to implement Skyhigh specific BIOS defaults. This means after loading optimized BIOS defaults in BIOS setup utility, the customizations have to be re-implemented manually:

  • Boot Options -> USB boot priority = ”Disabled”
  • Advanced -> USB Configuration -> Device Reset Timeout = 10s
  • Server Management -> Resume on AC Power Loss = ”Reset”
  • Server Management -> Console Redirection -> Baud Rate = ”19.2K”
  • Server Management -> Console Redirection -> Console Redirection = ”Serial Port A”

Intel Hardware Model C

To install a BIOS package on a Intel appliance, perform the following steps:

  1. Download the correct BIOS package for your model from the Skyhigh Content & Cloud Security Portal (see above table).
  2. Extract the ZIP into the root directory of a USB drive that is formatted in Microsoft DOS mode.
  3. Attach the USB drive to your appliance.
  4. Restart your appliance.
  5. The appliance will automatically enter EFI Shell.
    The EFI shell mode runs the startup.nsh procedure from the USB drive which will install the BIOS package.
  6. In case the appliance will not automatically enter the EFI Shell, press F6 during boot to enter the boot menu and select Internal EFI Shell.

The process takes up to 30 minutes to complete.

WBG-5000-C and WBG-5500-C with BIOS 035

This BIOS version requires an Intel Active System Console (ASC) software version that is not supported with SWG. If you install this BIOS version you won’t be able to use ASC. The remote management module RMM4 will provide this functionality.

WBG-5000-C and WBG-5500-C with BIOS 039 

This BIOS version requires a new SWG software version being installed prior to the BIOS upgrade

The following software versions are supported:
• Skyhigh Web Gateway >_ 7.7.2.7-24770
• Skyhigh  Web Gateway >_ 7.8.0.2-24769

 

It is not supported to install this BIOS version with an SWG software version below the versions listed above.

Once a supported software version is installed you can continue with the normal BIOS upgrade process as described above . After successful completion of the BIOS upgrade remove the USB stick and reboot the system using CTRL-ALT-DEL or the front panel button. During OS boot an automatic reboot will occur to enable the SWG specific BIOS settings.

During the upgrade you might see some events logged in the System Event Log (SEL).These events can be savely ignored.
728  = 11/24/2017 12:21:43 BMC FW Health Management Subsystem Health > '' sensor has failed and may not be providing a valid reading - > Asserted
727 = c11/24/2017 12:21:42 BMC FW Health Management Subsystem Health > 'P2 Therm Margin' sensor has failed and may not be providing a > valid reading - Asserted
726 =  11/24/2017 12:21:42 BMC FW Health Management Subsystem Health > 'P1 Therm Margin' sensor has failed and may not be providing a > valid reading - Asserted

 

Intel Hardware Model D

To install a BIOS package on a Intel appliance, perform the following steps:

  1. Download the correct BIOS package for your model from the Skyhigh Content & Cloud Security Portal.
  2. Extract the ZIP into the root directory of a USB drive that is formatted in Microsoft DOS mode.
  3. Attach the USB drive to your appliance.
  4. Restart your appliance.
  5. During boot press F6 to enter the boot selection menu.
    Select EFI Shell.
  6. The EFI shell mode runs the startup.nsh procedure from the USB drive which will install the BIOS package.
  7. When the installation has finished you will be asked to remove the USB stick and reboot the Appliance.

Do not remove the power cables.

  1. The backup BIOS will be updated after the reboot. The screen will be blank for several minutes.
 WBG-4500-D, WBG-5000-D and WBG-5500-D with >_ BIOS 037

For SWG appliances with MFE BIOS version >_ 037 we recommend to use the following SWG software versions:

 

 

Appliance Model MFE version Intel version SWG (>_)

WBG-4500-D

037 02.01.0049 7.5.2.12-22959
7.6.2.7-22954
7.7.1.1-23105
WBG-5000-D 037 01.01.0020 7.6.2.9.0-23104
7.7.1.1-23105
WBG-5500-D 037 01.01.0020 7.6.2.9.0-23104
7.7.1.1-23105

Previously for this appliance models released SWG versions will continue to work, but we recommend to use the versions listed above. If you plan to upgrade the appliance BIOS, we recommend to upgrade the SWG software version prior to the BIOS upgrade.

If you re-image an Appliance (with BIOS version greater than or equal to 037) with a SWG version that is lower than the recommended software version, you will get  notification that the installation has failed at the end of the installation procedure.

clipboard_e4f345bfbea91f1e4f68835c4f2d110bd.png

Despite of the error message you can see above, the installation procedure finished successfully and only restoring the BIOS settings has failed. You can remove the installation media and boot the Appliance. You can continue with the Appliance configuration wizard, as usual.

WBG-4500-D with BIOS 040

Execute the upgrade as described above mentioned steps. After step 8, the appliance will automatically boot to the EFI shell again. In the EFI shell, press CTRL-ALT-DEL to reboot the system, it will automatically boot to the OS.

WBG-5000-D and WBG-5500-D with BIOS 041

This BIOS version requires at least Intel version 01.01.0019 to be installed on the system. To check the currently installed Intel BIOS version, log on to the command-line of the system and execute the following command:

# dmidecode -s bios-version | cut -d. -f3-5
The output will look similar to this: 01.01.0019
In case the version is C 01.01.0019 you can safely upgrade to MFE BIOS package
041. If not, you’ll need to upgrade to MFE BIOS package 037 or 038 prior to the
actual upgrade.
Flash update procedure for model D
  1. Download the flash update tool here: https://www.intel.com/content/www/us/en/download/19032/intel-one-boot-flash-update-intel-ofu-utility-for-intel-server-boards-and-intel-server-systems-based-on-intel-62x-chipset.html
  2. Inside the ZIP file, you will find an RPM in Linux_x64 -> RHEL. Install that RPM on the target system's OS. rpm -i <package name>
  3. Contact support to get the customized BIOS ZIP file.
  4. Extract its contents.
  5. Run flashupdt -u flashupdt.cfg in the directory where BIOS package is extracted. 

Intel Hardware Model E

To install a BIOS package on a Intel appliance, perform the following steps:

  1. Download the correct BIOS package for your model from the Skyhigh Content & Cloud Security Portal.
  2.  Extract the ZIP into the root directory of a USB drive that is formatted in Microsoft DOS mode.
  3. Attach the USB drive to your appliance.
  4. Restart your appliance.
  5. During boot press F6 to enter the boot selection menu.
    Select EFI Shell.
  6. The EFI shell mode runs the startup.nsh procedure from the USB drive which will install the BIOS package.
  7. When the installation has finished you will be asked to remove the USB stick and reboot the Appliance.

Do not remove the power cables

  1. The backup BIOS will be updated after the reboot. The screen will be blank for several minutes.
Flash update procedure for model E
  1. Download the flash update tool here: https://www.intel.com/content/www/us/en/download/19032/intel-one-boot-flash-update-intel-ofu-utility-for-intel-server-boards-and-intel-server-systems-based-on-intel-62x-chipset.html
  2. Inside the ZIP file, you will find an RPM in Linux_x64 -> RHEL. Install that RPM on the target system's OS. rpm -i <package name>
  3. Contact support to get the customized BIOS ZIP file.
  4. Extract its contents.
  5. Run flashupdt -u flashupdt.cfg in the directory where BIOS package is extracted. 

 

Steps for BIOS/FW upgrade for WBG-4500-E appliance

Steps to upgrade the BIOS package

  1. Download and unzip the BIOS FW package file on to the appliance ( 7220_Production.ROM   is the BIOS package file to be installed)
  2. Download the Intel BIOS Tool [IntelAfuLnx64|https://www.intel.com/content/www/us/en/download/19550/afu-ami-firmware-update-utility-for-m10jnp2sb.html
  3. Execute the below command  from the location where the IntelAFuLnx64 is installed 
    •   ./IntelAfuLnx64 <Full path of  7220_Production.ROM   >  /B /P /N /K /L /R /ME 
    • Below errors can be ignored
      • Error: Cannot locate kernel source.
        Error: gcc complier did not exist.
  4.  Once the process is completed, reboot the appliance for the new BIOS to be loaded.

Steps to upgrade the BMC FW:

  1. Log in to RMM UI
  2. Navigate to Maintenance  > Firmware update 

upload the .ima file and click start to update the firmware.  This should upgrade the BMC 

  • Was this article helpful?