Intel / Cisco X710 NIC Runbook¶
Triage, firmware crossflash, and SFP+ unlock for Intel 700-series (X710/XL710) NICs — including Cisco- and Dell-OEM variants. Written against a Linux live environment (grml / Debian live) booted over iDRAC virtual media.
Safety first. Firmware writes can brick a card. Always: take the backup when prompted, cold power-cycle (full off/on, not a warm reboot) between steps, select the correct adapter by PCI bus, and never interrupt a write.
Reference: reading the identifiers¶
ethtool -i firmware string has three parts:
- NVM — the human version (e.g. 5.05, 8.50).
- ETrackID — the value the NVM tool matches on. Used in the
REPLACES:line. Uppercase, drop the0x(0x80002a3c→80002A3C). - Both ports of one physical card share one flash, so a healthy card reports identical firmware on both functions.
PCI / subsystem vendor IDs (lspci -nnvvv):
| ID | Meaning |
|---|---|
8086:1572 |
Intel X710 for 10GbE SFP+ (device) |
8086:xxxx |
Intel retail (subsystem) |
1137:xxxx |
Cisco OEM (subsystem) |
1028:xxxx |
Dell OEM (subsystem) |
The Intel NVM Update Tool is not designed for OEM cards — for Cisco/Dell/HPE
cards you either use the vendor's package, or override the lock with a REPLACES:
edit (the crossflash method in section 2). A wrong image on an OEM card can brick
it, so keep firmware .bin and its matching .cfg from the same package.
1. Triage — inventory NICs, firmware, and optics¶
Dumps every physical NIC with make/model/revision, PCI + subsystem IDs, driver, NVM/ETrackID/build, and installed optic details.
#!/usr/bin/env bash
# nic-triage.sh — inventory all physical NICs
for path in /sys/class/net/*; do
dev=$(basename "$path")
[ -e "$path/device" ] || continue # skip lo / virtual
bus=$(basename "$(readlink -f "$path/device")") # e.g. 0000:19:00.0
echo "==================================================================="
echo "Interface : $dev"
echo "PCI bus : $bus"
# make / model / revision + device & subsystem IDs
lspci -nnvvv -s "$bus" 2>/dev/null \
| grep -iE 'Ethernet controller|Subsystem' | sed 's/^/ /'
# driver / firmware-version (NVM ETrackID build) / bus-info
ethtool -i "$dev" 2>/dev/null \
| grep -E 'driver|firmware-version|bus-info' | sed 's/^/ /'
# installed optic (SFP+/DAC) — vendor, part, type, DOM
echo " -- optic (ethtool -m) --"
ethtool -m "$dev" 2>/dev/null \
| grep -iE 'Identifier|Vendor name|Vendor PN|type|wavelength|temperature|power' \
| sed 's/^/ /' || echo " (no module / not readable)"
done
Run as root:
Quick one-liners if you just want the essentials:
# per-interface driver/fw/bus
for n in $(ls /sys/class/net); do [ -e /sys/class/net/$n/device ] || continue; \
echo "== $n =="; ethtool -i "$n" | grep -E 'driver|firmware-version|bus-info'; done
# all ethernet controllers with device + subsystem IDs
lspci -nn | grep -i ethernet
lspci -nnvvv -s <bus> | grep -i subsystem # provenance for one card
# optic in a single port
ethtool -m <iface>
What to look for
- Two
i40eports on the same bus prefix (...:00.0/...:00.1) with identical firmware = one healthy dual-port card. - Firmware mismatch across a card's two ports, or a blank NVM string = suspect (bad flash / counterfeit).
- Subsystem
1137/1028= OEM card — read section 2 before flashing. ethtool -merrors or blank on one port but not another = bad/foreign optic or a locked card rejecting the module (see section 3).
2. Cisco X710 crossflash (via Intel NVM tool + REPLACES:)¶
Used to move an OEM (Cisco 1137:020a) X710-DA2 off old firmware. Cisco cards
often ship stuck on NVM 5.05 (2017); this brings them to 8.50. The Intel tool
normally refuses OEM cards, so each firmware folder's .cfg gets a REPLACES:
line set to the card's current ETrackID to authorise the update.
2a. Build a FAT32 USB image (on any Linux box / the live session)¶
# 512 MB raw image, whole-disk FAT32 (no partition table needed for iDRAC)
dd if=/dev/zero of=usb.img bs=1M count=512
mkfs.vfat -n TOOLS usb.img
# populate it
mkdir -p /mnt/img && sudo mount -o loop usb.img /mnt/img
sudo cp -r cisco /mnt/img/ # the flasher pack
sudo cp 700Series_NVMUpdatePackage_*_Linux.tar.gz /mnt/img/ # Intel tool, as tarball
sync && sudo umount /mnt/img
Keep the Intel package as a .tar.gz and extract it on the target. FAT can't store the
+xbit, so extracting on-target preserves the executable permission onnvmupdate64e.
2b. Mount it in the running live OS (via iDRAC)¶
In iDRAC: Configuration → Virtual Media → map usb.img as Removable Disk / USB.
Then inside the live session:
lsblk -f # find the ~512M vfat device, label TOOLS
mkdir -p /mnt/usb
mount /dev/sdX /mnt/usb # whole-disk FAT; use /dev/sdX1 if partitioned
ls /mnt/usb # should show cisco/ and the Intel tarball
If iDRAC hot-swapped media and the mount shows stale contents:
umount /mnt/usb; eject /dev/srX (for CDs) then re-mount.
2c. Stage tools in writable space (preserves exec bits)¶
cp -r /mnt/usb/cisco /tmp/cisco
cd /tmp && tar xzf /mnt/usb/700Series_NVMUpdatePackage_*_Linux.tar.gz
# tool now at /tmp/700Series/Linux_x64/nvmupdate64e
2d. Flash one rung¶
# confirm the target card's CURRENT ETrackID and bus
ethtool -i <iface> | grep -E 'firmware-version|bus-info'
# middle hex of firmware-version = current ETrackID
cd "/tmp/cisco/6.01 Version 800036BD" # quote folders (they contain spaces)
cp /tmp/700Series/Linux_x64/nvmupdate64e . # tmpfs keeps +x
# set REPLACES to the card's CURRENT ETrackID (uppercase, no 0x)
grep -i replaces Fortville.cfg
nano Fortville.cfg # e.g. REPLACES: 80002A3C
./nvmupdate64e -c Fortville.cfg
At the index prompt: pick the entry whose bus matches your target
(e.g. 0000:86:00), answer Yes to the backup, and let it finish.
2e. The incremental ladder¶
REPLACES: for each step = the ETrackID the card reports right now. Each
folder is named <version> Version <ETrackID-it-writes>, so each step's result
becomes the next step's REPLACES:. Note 8.15 is older than 8.50 — order by
the ETrackID chain, not the number.
Card starting at 5.05 (80002A3C):
| Step | Folder | REPLACES: |
Ends at |
|---|---|---|---|
| 1 | 6.01 Version 800036BD |
80002A3C |
6.01 / 800036BD |
| 2 | 8.15 Version 80009E61 |
800036BD |
8.15 / 80009E61 |
| 3 | 8.5 Version 8000B8FD |
80009E61 |
8.50 / 8000B8FD |
| 4 | 8.5 Version 8000CC12 |
8000B8FD |
8.50 / 8000CC12 |
Card starting at 7.00 (80005026): past 6.01, so skip step 1 — start at the
8.15 folder with REPLACES: 80005026, then continue steps 3–4.
2f. Between every rung¶
- Cold power-cycle (iDRAC → Power → Power Off, then On). NVM banks only swap on a full power cycle; a warm reboot won't activate the new image.
- Verify before the next step:
- If the tool says "no candidate / update not available", your
REPLACES:doesn't match the live ETrackID — stop and recheck, don't force it.
2g. Gotchas¶
- Both ports flash together (one shared NVM) — expect both to change.
- Two similar OEM cards in one box look near-identical in the list — always disambiguate by bus before selecting an index.
- Do cards one at a time, start to finish, to avoid wrong-index picks.
- Never
nvmupdate64e -rdon a card you've unlocked (see section 3).
3. Unlock X710 to accept any SFP+ / DAC¶
By default the X710 firmware authenticates modules and disables Rx/Tx on non-Intel optics:
The xl710-unlocker tool clears the module-authentication bit in NVM so the card accepts any SFP+/DAC. Works on the onboard Intel X710 and OEM (Cisco) cards alike. The change is in NVM, so it persists across reboots.
3a. Build and run¶
sudo apt-get update && sudo apt-get install -y build-essential git ethtool
git clone https://github.com/bibigon812/xl710-unlocker
cd xl710-unlocker
make # produces the xl710_unlock executable
Follow the repo's README for the exact invocation — it reads the card's EEPROM, locates the module-authentication register, and clears it for the interface you name. Register offsets can differ between cards, which is why the tool inspects before writing. Run it per card (and per port where applicable).
3b. Activate + test¶
# 1. COLD power-cycle first (iDRAC power off/on) — the NVM change only goes live then.
# 2. Insert the previously-rejected third-party module, then:
ip link set <iface> up
ethtool <iface> | grep -iE 'link detected|speed' # want: yes / 10000Mb/s
# 3. Definitive check — the rejection message should be GONE:
dmesg | grep -i i40e | grep -iE 'sfp|unsupported|disabled' # expect no output
# 4. Module now readable:
ethtool -m <iface> | head # vendor / PN / DOM, no errors
# 5. Real traffic (link != working):
# peer: iperf3 -s
# here: iperf3 -c <peer-ip> -t 60
A further confirmation: at Dell POST/boot the "unsupported SFP" message disappears once the bit is cleared — proof it's cleared at firmware level, not just masked by a driver flag. (A harmless "boot device" error can appear if the server tries to PXE off the now-live port; lower those ports in the boot order or disable their network-boot OPROM to silence it.)
3c. Cautions¶
- Never run
nvmupdate64e -rdon an unlocked card — restore-defaults rewrites the lock bit and re-locks it. Plain NVM updates preserve the unlock. - If you both flash and unlock a card, flash firmware first, unlock last, so a later NVM write can't clobber the bit. If you unlocked before finishing the ladder, re-verify the unlock survived each subsequent flash (repeat 3b step 3).
- The bit is per card — unlocking one says nothing about the others.
Appendix: firmware notes for X710 (context)¶
- Pre-5.05 NVM carries a documented security vulnerability; 5.05 is the minimum fix. Move off it regardless.
- NVM 4.53 / 5.x: disabling LLDP can misconfigure the receive packet buffer; fixed in 6.01. Intel recommends NVM ≥ 6.01 with driver release ≥ 22.6. This is why the ladder forces 6.01 as a stepping stone.
- Firmware LLDP agent is on by default on all these versions — the card eats inbound LLDP frames, which breaks LLDP neighbour discovery and can hang PXE. It's not a version bug; disable it in software when needed:
- Keep the i40e driver roughly in step with NVM; a very old in-box driver against new firmware causes odd failures (this was the original Windows "device cannot start (Code 10)" on one port).
- The MAC/VLAN-filter-removal erratum on NVM 8.40+ applies to the
X710-TM4/AT2 10GBASE-T silicon, not the SFP+ DA2 (
1572).