Skip to content

Intel / Cisco X710 NIC Runbook

Triage, firmware crossflash, and SFP+ unlock for Intel 700-series (X710/XL710) NICs — including Cisco- and Dell-OEM variants. Written against a Linux live environment (grml / Debian live) booted over iDRAC virtual media.

Safety first. Firmware writes can brick a card. Always: take the backup when prompted, cold power-cycle (full off/on, not a warm reboot) between steps, select the correct adapter by PCI bus, and never interrupt a write.


Reference: reading the identifiers

ethtool -i firmware string has three parts:

firmware-version: 9.20 0x8000d969 22.0.9
                  ^^^^ ^^^^^^^^^^ ^^^^^^
                  NVM  ETrackID   FW/API build
  • NVM — the human version (e.g. 5.05, 8.50).
  • ETrackID — the value the NVM tool matches on. Used in the REPLACES: line. Uppercase, drop the 0x (0x80002a3c → 80002A3C).
  • Both ports of one physical card share one flash, so a healthy card reports identical firmware on both functions.

PCI / subsystem vendor IDs (lspci -nnvvv):

ID Meaning
8086:1572 Intel X710 for 10GbE SFP+ (device)
8086:xxxx Intel retail (subsystem)
1137:xxxx Cisco OEM (subsystem)
1028:xxxx Dell OEM (subsystem)

The Intel NVM Update Tool is not designed for OEM cards — for Cisco/Dell/HPE cards you either use the vendor's package, or override the lock with a REPLACES: edit (the crossflash method in section 2). A wrong image on an OEM card can brick it, so keep firmware .bin and its matching .cfg from the same package.


1. Triage — inventory NICs, firmware, and optics

Dumps every physical NIC with make/model/revision, PCI + subsystem IDs, driver, NVM/ETrackID/build, and installed optic details.

#!/usr/bin/env bash
# nic-triage.sh — inventory all physical NICs
for path in /sys/class/net/*; do
  dev=$(basename "$path")
  [ -e "$path/device" ] || continue                 # skip lo / virtual
  bus=$(basename "$(readlink -f "$path/device")")    # e.g. 0000:19:00.0
  echo "==================================================================="
  echo "Interface : $dev"
  echo "PCI bus   : $bus"
  # make / model / revision + device & subsystem IDs
  lspci -nnvvv -s "$bus" 2>/dev/null \
    | grep -iE 'Ethernet controller|Subsystem' | sed 's/^/  /'
  # driver / firmware-version (NVM ETrackID build) / bus-info
  ethtool -i "$dev" 2>/dev/null \
    | grep -E 'driver|firmware-version|bus-info' | sed 's/^/  /'
  # installed optic (SFP+/DAC) — vendor, part, type, DOM
  echo "  -- optic (ethtool -m) --"
  ethtool -m "$dev" 2>/dev/null \
    | grep -iE 'Identifier|Vendor name|Vendor PN|type|wavelength|temperature|power' \
    | sed 's/^/  /' || echo "    (no module / not readable)"
done

Run as root:

chmod +x nic-triage.sh && sudo ./nic-triage.sh

Quick one-liners if you just want the essentials:

# per-interface driver/fw/bus
for n in $(ls /sys/class/net); do [ -e /sys/class/net/$n/device ] || continue; \
  echo "== $n =="; ethtool -i "$n" | grep -E 'driver|firmware-version|bus-info'; done

# all ethernet controllers with device + subsystem IDs
lspci -nn | grep -i ethernet
lspci -nnvvv -s <bus> | grep -i subsystem     # provenance for one card

# optic in a single port
ethtool -m <iface>

What to look for

  • Two i40e ports on the same bus prefix (...:00.0 / ...:00.1) with identical firmware = one healthy dual-port card.
  • Firmware mismatch across a card's two ports, or a blank NVM string = suspect (bad flash / counterfeit).
  • Subsystem 1137 / 1028 = OEM card — read section 2 before flashing.
  • ethtool -m errors or blank on one port but not another = bad/foreign optic or a locked card rejecting the module (see section 3).

2. Cisco X710 crossflash (via Intel NVM tool + REPLACES:)

Used to move an OEM (Cisco 1137:020a) X710-DA2 off old firmware. Cisco cards often ship stuck on NVM 5.05 (2017); this brings them to 8.50. The Intel tool normally refuses OEM cards, so each firmware folder's .cfg gets a REPLACES: line set to the card's current ETrackID to authorise the update.

2a. Build a FAT32 USB image (on any Linux box / the live session)

# 512 MB raw image, whole-disk FAT32 (no partition table needed for iDRAC)
dd if=/dev/zero of=usb.img bs=1M count=512
mkfs.vfat -n TOOLS usb.img

# populate it
mkdir -p /mnt/img && sudo mount -o loop usb.img /mnt/img
sudo cp -r cisco /mnt/img/                                   # the flasher pack
sudo cp 700Series_NVMUpdatePackage_*_Linux.tar.gz /mnt/img/  # Intel tool, as tarball
sync && sudo umount /mnt/img

Keep the Intel package as a .tar.gz and extract it on the target. FAT can't store the +x bit, so extracting on-target preserves the executable permission on nvmupdate64e.

2b. Mount it in the running live OS (via iDRAC)

In iDRAC: Configuration → Virtual Media → map usb.img as Removable Disk / USB. Then inside the live session:

lsblk -f                                  # find the ~512M vfat device, label TOOLS
mkdir -p /mnt/usb
mount /dev/sdX /mnt/usb                    # whole-disk FAT; use /dev/sdX1 if partitioned
ls /mnt/usb                               # should show cisco/ and the Intel tarball

If iDRAC hot-swapped media and the mount shows stale contents: umount /mnt/usb; eject /dev/srX (for CDs) then re-mount.

2c. Stage tools in writable space (preserves exec bits)

cp -r /mnt/usb/cisco /tmp/cisco
cd /tmp && tar xzf /mnt/usb/700Series_NVMUpdatePackage_*_Linux.tar.gz
# tool now at /tmp/700Series/Linux_x64/nvmupdate64e

2d. Flash one rung

# confirm the target card's CURRENT ETrackID and bus
ethtool -i <iface> | grep -E 'firmware-version|bus-info'
#   middle hex of firmware-version = current ETrackID

cd "/tmp/cisco/6.01 Version 800036BD"          # quote folders (they contain spaces)
cp /tmp/700Series/Linux_x64/nvmupdate64e .      # tmpfs keeps +x

# set REPLACES to the card's CURRENT ETrackID (uppercase, no 0x)
grep -i replaces Fortville.cfg
nano Fortville.cfg                              # e.g. REPLACES: 80002A3C

./nvmupdate64e -c Fortville.cfg

At the index prompt: pick the entry whose bus matches your target (e.g. 0000:86:00), answer Yes to the backup, and let it finish.

2e. The incremental ladder

REPLACES: for each step = the ETrackID the card reports right now. Each folder is named <version> Version <ETrackID-it-writes>, so each step's result becomes the next step's REPLACES:. Note 8.15 is older than 8.50 — order by the ETrackID chain, not the number.

Card starting at 5.05 (80002A3C):

Step Folder REPLACES: Ends at
1 6.01 Version 800036BD 80002A3C 6.01 / 800036BD
2 8.15 Version 80009E61 800036BD 8.15 / 80009E61
3 8.5 Version 8000B8FD 80009E61 8.50 / 8000B8FD
4 8.5 Version 8000CC12 8000B8FD 8.50 / 8000CC12

Card starting at 7.00 (80005026): past 6.01, so skip step 1 — start at the 8.15 folder with REPLACES: 80005026, then continue steps 3–4.

2f. Between every rung

  1. Cold power-cycle (iDRAC → Power → Power Off, then On). NVM banks only swap on a full power cycle; a warm reboot won't activate the new image.
  2. Verify before the next step:
    ethtool -i <iface> | grep -i firmware      # middle hex must match the folder
    
  3. If the tool says "no candidate / update not available", your REPLACES: doesn't match the live ETrackID — stop and recheck, don't force it.

2g. Gotchas

  • Both ports flash together (one shared NVM) — expect both to change.
  • Two similar OEM cards in one box look near-identical in the list — always disambiguate by bus before selecting an index.
  • Do cards one at a time, start to finish, to avoid wrong-index picks.
  • Never nvmupdate64e -rd on a card you've unlocked (see section 3).

3. Unlock X710 to accept any SFP+ / DAC

By default the X710 firmware authenticates modules and disables Rx/Tx on non-Intel optics:

i40e ...: Rx/Tx is disabled on this device because an unsupported SFP module
          type was detected.

The xl710-unlocker tool clears the module-authentication bit in NVM so the card accepts any SFP+/DAC. Works on the onboard Intel X710 and OEM (Cisco) cards alike. The change is in NVM, so it persists across reboots.

3a. Build and run

sudo apt-get update && sudo apt-get install -y build-essential git ethtool
git clone https://github.com/bibigon812/xl710-unlocker
cd xl710-unlocker
make                       # produces the xl710_unlock executable

Follow the repo's README for the exact invocation — it reads the card's EEPROM, locates the module-authentication register, and clears it for the interface you name. Register offsets can differ between cards, which is why the tool inspects before writing. Run it per card (and per port where applicable).

3b. Activate + test

# 1. COLD power-cycle first (iDRAC power off/on) — the NVM change only goes live then.

# 2. Insert the previously-rejected third-party module, then:
ip link set <iface> up
ethtool <iface> | grep -iE 'link detected|speed'      # want: yes / 10000Mb/s

# 3. Definitive check — the rejection message should be GONE:
dmesg | grep -i i40e | grep -iE 'sfp|unsupported|disabled'   # expect no output

# 4. Module now readable:
ethtool -m <iface> | head                              # vendor / PN / DOM, no errors

# 5. Real traffic (link != working):
#    peer:  iperf3 -s
#    here:  iperf3 -c <peer-ip> -t 60

A further confirmation: at Dell POST/boot the "unsupported SFP" message disappears once the bit is cleared — proof it's cleared at firmware level, not just masked by a driver flag. (A harmless "boot device" error can appear if the server tries to PXE off the now-live port; lower those ports in the boot order or disable their network-boot OPROM to silence it.)

3c. Cautions

  • Never run nvmupdate64e -rd on an unlocked card — restore-defaults rewrites the lock bit and re-locks it. Plain NVM updates preserve the unlock.
  • If you both flash and unlock a card, flash firmware first, unlock last, so a later NVM write can't clobber the bit. If you unlocked before finishing the ladder, re-verify the unlock survived each subsequent flash (repeat 3b step 3).
  • The bit is per card — unlocking one says nothing about the others.

Appendix: firmware notes for X710 (context)

  • Pre-5.05 NVM carries a documented security vulnerability; 5.05 is the minimum fix. Move off it regardless.
  • NVM 4.53 / 5.x: disabling LLDP can misconfigure the receive packet buffer; fixed in 6.01. Intel recommends NVM ≥ 6.01 with driver release ≥ 22.6. This is why the ladder forces 6.01 as a stepping stone.
  • Firmware LLDP agent is on by default on all these versions — the card eats inbound LLDP frames, which breaks LLDP neighbour discovery and can hang PXE. It's not a version bug; disable it in software when needed:
    ethtool --set-priv-flags <iface> disable-fw-lldp on    # Linux
    # ESXi:  esxcli system module parameters set -m i40en -p LLDP=0,0
    # Dell:  F2 → Device Settings → X710 NIC → disable LLDP
    
  • Keep the i40e driver roughly in step with NVM; a very old in-box driver against new firmware causes odd failures (this was the original Windows "device cannot start (Code 10)" on one port).
  • The MAC/VLAN-filter-removal erratum on NVM 8.40+ applies to the X710-TM4/AT2 10GBASE-T silicon, not the SFP+ DA2 (1572).