Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Watchguard Firebox M400/M500

    Scheduled Pinned Locked Moved Hardware
    596 Posts 59 Posters 783.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      korenchkin
      last edited by

      so for those noctua 'fans' out there,since the fan is moving such a low volume,you should probably seal everything you can on the path between fans and cpu cooler(careful around power stage to keep air flowing there a bit maybe),and that means mainly:space under board,space under cooler,space around those 2 aluminium rails(mainly below,big holes),i have 4590t(also does not reboot well,with v6 bios,thanks for the mod btw!)

      i have similar/same machine(lanner was busy:) )

      i think(early testing) it is making massive difference on silent mode,since it is not pulling air through the gaps

      i also tried updating microcode in bios,but i did it wrong,or it did not work (you don't actually need bios update for microcode update),but still locked on reboot..no clue why it freezes

      1 Reply Last reply Reply Quote 1
      • K
        korenchkin
        last edited by

        okay,this is another BIG one! (at least for me) :) @zanthos @stephenw10
        i managed to make i5-4590t supported and reboots okay
        main problem was intel me firmware(that is part of bios),but that bastard is not easy to mod and to flash too (need to be carefull when replacing,there are registers and shi* that needs to stay the same,so skip configuration,intel fit,replace and rebuild)
        you need 9.1 version for haswell refresh,that's it

        i have different machine,but same board,i used m400 v6 bios up here somewhere(thanks for that!)

        long story short:

        1. the jumper just beside cmos clear is me disable(those jumpers are zig-zag,outer is cmos clear,inner is me disable),you need to flip it so bios can operate on this region(and after that flip it back)
        2. i also set me fw image reflash to enable in bios,to be sure (version is not displayed for you(yet :) )
        3. boot from flash(i'll attach right away,fat32,partition 100mb is enough if you are not sure) into efi shell (or use your tools)
          --efi shell use tab same as linux to quickly finish commands and file names-use it :)
        4. command: afuefix64.efi m400-91.rom /me
          ---this will flash me image,if it seems stalled,it might be reading file from flash(for minute or two,use flash with led if you are not sure)
        5. power off,jumper back,close,power on,it will reset about 3 times and then the usual beeps
        6. go to bios,me fw version 9.1.40.1000
        7. profit

        i wonder what cpus it might support....

        as usual,no warranties,but compare for yourself,use uefitool and meanalyzer
        i would prefer that some pro here check it and confirm independently before you all start flashing,even though i use bios found here,my machine has different colours :)

        file is here

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Ooo fun. So that's the full rom file but you are just flashing the me section from it?

          K 1 Reply Last reply Reply Quote 0
          • K
            korenchkin @stephenw10
            last edited by

            @stephenw10 yep,just to be sure,i'm on it for...well about 8 hours..need some sleep now :)

            i didn't want to touch it standalone,look at intel csme tools "fit" (some winraid level1techs forum if i remember correctly),this is hardcore stuff,but fit is pretty simple(for you i guess),if you open the whole section of me,there are hardware addresses that i guess needs to stay the same,so definitely look but don't touch

            fit can also not display several items,they stay in xml only,so best way to update is disassemble with fit,save to xml,close fit,replace me part,open fit,load xml and rebuild..if you do it officially and replace me part with fit gui,defaults will jump in,not sure about:
            why bias0 has different register? why lcpll3 is 0x0 if default is not(also,what is it?),what is sscctl_dclk135 and why it is 0x0? and this kind of danger 😆

            so basically i did it and discovered that i can just flash(with another tool) only me,but that means modifying me for this machine,so...nope,this works for my machine,and i have another one(if this one fails),but i'll probably won't use them,since they are still too noisy for me...but it was fun finding out...

            stephenw10S 1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator @korenchkin
              last edited by

              @korenchkin said in Watchguard Firebox M400/M500:

              i'll probably won't use them,since they are still too noisy for me

              With the fan speed set lower? I haven't tried using Noctua fans but I guess they must also be a lot quieter.

              K 1 Reply Last reply Reply Quote 0
              • K
                korenchkin @stephenw10
                last edited by korenchkin

                @stephenw10 i'm already at uncomfortable temperature levels(for me),i swapped all 3 fans for noctuas,buty they are annoyingly noisy(motor hum,not blade/air noise)..they have those fancy names and advanced technologies on box it feels like false advertising...

                i'm contemplating how to solve this,either cut a hole and mount at least 80mm fan on top,or maybe ditch the case completely,nothing feels right...i have mikrotik,so no pressure(probably better than this,but it is so annoyingly reliable and boring :) )

                edit:about those temperatures,bios is about 25-30 degrees C wrong(higher reported),so i made the fan curve start at 85 degrees

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Hmm, that must be CPU specific. They've always been pretty accurate here.

                  You might try just turning down the standard fans at run time with WGXepc. I guess it depends how/where you use it but the test boxes are next to my desk and are acceptably quiet like that.

                  K 1 Reply Last reply Reply Quote 0
                  • K
                    korenchkin @stephenw10
                    last edited by korenchkin

                    @stephenw10 yeah,it is definitely cpu related,but strange thing is coretemp readings in opnsense seems correct and if i disable coretemp,readings are correct too,only bios(which sets fan speeds)...so i set my preference and added about 25C,so they are sitting idle at ~51C and still way noisier than my more or less idle proxmox i5-7600k.. (i sleep here)

                    now how about this nice strange form-factor 4-port ethernet card that is in,maybe use it in different board?maybe a little cut in case so it fits? :)

                    edit (about temperature/consumption): measuring ~26W idle at wall,when crowdsec went wonky and used full cpu,i measured about 38W

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      You could. It's just PCIe, you can make it work with the right adapter. But I'd only do that for fun at this point. 😉

                      The Mx70 models are pretty cheap and have a module slot. (for values of x between 4 and 6!)

                      K 1 Reply Last reply Reply Quote 0
                      • K
                        korenchkin @stephenw10
                        last edited by

                        @stephenw10 i have strange fetish for this kind of devices,i'd like to get my hands on them,but still,i'll have to use some bigger pc-like or passive and keep those for tinker purposes...
                        i didn't even installed windows 10/11 there yet..just for fun

                        addon card eats about 2.5W idle unconnected.i'm now down to ~23.8W

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.