Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Watchguard Firebox M400/M500

    Scheduled Pinned Locked Moved Hardware
    596 Posts 59 Posters 698.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      The K CPUs were usually the unlocked version preferred by overclockers. So capable of the maximum possible performance. And cost! Of course that also means many have had a hard life. 😉

      M 1 Reply Last reply Reply Quote 0
      • M
        Mookatroid @stephenw10
        last edited by

        @stephenw10
        Avoid the i7-6700
        Worked great until it died
        At which point I realized the heatsink could not dea

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          That definitely wouldn't work in the M400/M500. I assume you tried that in an Mx70?

          M 1 Reply Last reply Reply Quote 0
          • M
            Mookatroid @stephenw10
            last edited by

            @stephenw10
            Sorry, yes.
            Mx70
            The i7-6700 runs too hot for the Mx70 heatsink and eventually just cooks itself.

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Urgh, best avoid that then! 😬

              1 Reply Last reply Reply Quote 0
              • X
                xxup
                last edited by xxup

                @xxup said in Watchguard Firebox M400/M500:

                i5-4670K

                I have installed the i5-4670K into the M500 and I can confirm that it reboots from both the console and the GUI. The i5-4670 should be here next week, but I am confident that it will boot okay as it is older than the K version.

                ***** Edit ***** The K runs about 3-4C hotter than the old i3-4130. I will keep this one in the test lab box and the i5-4670 in the home (production) box.

                1 Reply Last reply Reply Quote 1
                • X
                  xxup
                  last edited by

                  The i5-4670 has just been installed into the home network's M400 and the reboot test was successful. Certainly runs cooler than the i5-4670K.

                  1 Reply Last reply Reply Quote 1
                  • K
                    korenchkin
                    last edited by

                    thanks all for the great reading and !BIOS! file,now running on Peplink balance 710 (i3-4330+2g ram +4gb cf),now 8gb ram+sata ssd

                    it was usable with default bios,but i have 2,so i said myself why not...(i have bios backup and some spi tools too,so i was not scared)...also fans are a bit less noisier(still loud for router...)..and the options in bios..wow i like it..

                    1 Reply Last reply Reply Quote 1
                    • A
                      ajnsan
                      last edited by

                      To add to the topic, I also acquired a (free) firebox m400 - came with 8Gb ram - stock cpu. Stock CF card and one extra empty one (both are generic transcend cards).
                      Serial cable also included, used a USB-serial adapter to view the terminal.

                      Flashed Grub on the second card to chainload Arch installed on SSD.
                      Works great!

                      The firebox didnt want to boot from SSD directly with stock bios,
                      but happily boots grub from a CF card which then enables booting from the SSD anyway.

                      With the CF card handling boot, the sata port didnt matter for the SSD (using UUIDs in grub) so switching the SSD between sata ports didnt matter.

                      All nics detected and operational.

                      Now waiting for a i5-4590T,
                      will probably upgrade the fans, possibly PSU, add some acoustics insulation - to quiet it down for home use.

                      stephenw10S 1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator @ajnsan
                        last edited by

                        @ajnsan said in Watchguard Firebox M400/M500:

                        Now waiting for a i5-4590T,

                        Be aware it may not reboot with that CPU.

                        1 Reply Last reply Reply Quote 0
                        • K
                          korenchkin
                          last edited by

                          so for those noctua 'fans' out there,since the fan is moving such a low volume,you should probably seal everything you can on the path between fans and cpu cooler(careful around power stage to keep air flowing there a bit maybe),and that means mainly:space under board,space under cooler,space around those 2 aluminium rails(mainly below,big holes),i have 4590t(also does not reboot well,with v6 bios,thanks for the mod btw!)

                          i have similar/same machine(lanner was busy:) )

                          i think(early testing) it is making massive difference on silent mode,since it is not pulling air through the gaps

                          i also tried updating microcode in bios,but i did it wrong,or it did not work (you don't actually need bios update for microcode update),but still locked on reboot..no clue why it freezes

                          1 Reply Last reply Reply Quote 1
                          • K
                            korenchkin
                            last edited by

                            okay,this is another BIG one! (at least for me) :) @zanthos @stephenw10
                            i managed to make i5-4590t supported and reboots okay
                            main problem was intel me firmware(that is part of bios),but that bastard is not easy to mod and to flash too (need to be carefull when replacing,there are registers and shi* that needs to stay the same,so skip configuration,intel fit,replace and rebuild)
                            you need 9.1 version for haswell refresh,that's it

                            i have different machine,but same board,i used m400 v6 bios up here somewhere(thanks for that!)

                            long story short:

                            1. the jumper just beside cmos clear is me disable(those jumpers are zig-zag,outer is cmos clear,inner is me disable),you need to flip it so bios can operate on this region(and after that flip it back)
                            2. i also set me fw image reflash to enable in bios,to be sure (version is not displayed for you(yet :) )
                            3. boot from flash(i'll attach right away,fat32,partition 100mb is enough if you are not sure) into efi shell (or use your tools)
                              --efi shell use tab same as linux to quickly finish commands and file names-use it :)
                            4. command: afuefix64.efi m400-91.rom /me
                              ---this will flash me image,if it seems stalled,it might be reading file from flash(for minute or two,use flash with led if you are not sure)
                            5. power off,jumper back,close,power on,it will reset about 3 times and then the usual beeps
                            6. go to bios,me fw version 9.1.40.1000
                            7. profit

                            i wonder what cpus it might support....

                            as usual,no warranties,but compare for yourself,use uefitool and meanalyzer
                            i would prefer that some pro here check it and confirm independently before you all start flashing,even though i use bios found here,my machine has different colours :)

                            file is here

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Ooo fun. So that's the full rom file but you are just flashing the me section from it?

                              K 1 Reply Last reply Reply Quote 0
                              • K
                                korenchkin @stephenw10
                                last edited by

                                @stephenw10 yep,just to be sure,i'm on it for...well about 8 hours..need some sleep now :)

                                i didn't want to touch it standalone,look at intel csme tools "fit" (some winraid level1techs forum if i remember correctly),this is hardcore stuff,but fit is pretty simple(for you i guess),if you open the whole section of me,there are hardware addresses that i guess needs to stay the same,so definitely look but don't touch

                                fit can also not display several items,they stay in xml only,so best way to update is disassemble with fit,save to xml,close fit,replace me part,open fit,load xml and rebuild..if you do it officially and replace me part with fit gui,defaults will jump in,not sure about:
                                why bias0 has different register? why lcpll3 is 0x0 if default is not(also,what is it?),what is sscctl_dclk135 and why it is 0x0? and this kind of danger 😆

                                so basically i did it and discovered that i can just flash(with another tool) only me,but that means modifying me for this machine,so...nope,this works for my machine,and i have another one(if this one fails),but i'll probably won't use them,since they are still too noisy for me...but it was fun finding out...

                                stephenw10S 1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator @korenchkin
                                  last edited by

                                  @korenchkin said in Watchguard Firebox M400/M500:

                                  i'll probably won't use them,since they are still too noisy for me

                                  With the fan speed set lower? I haven't tried using Noctua fans but I guess they must also be a lot quieter.

                                  K 1 Reply Last reply Reply Quote 0
                                  • K
                                    korenchkin @stephenw10
                                    last edited by korenchkin

                                    @stephenw10 i'm already at uncomfortable temperature levels(for me),i swapped all 3 fans for noctuas,buty they are annoyingly noisy(motor hum,not blade/air noise)..they have those fancy names and advanced technologies on box it feels like false advertising...

                                    i'm contemplating how to solve this,either cut a hole and mount at least 80mm fan on top,or maybe ditch the case completely,nothing feels right...i have mikrotik,so no pressure(probably better than this,but it is so annoyingly reliable and boring :) )

                                    edit:about those temperatures,bios is about 25-30 degrees C wrong(higher reported),so i made the fan curve start at 85 degrees

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Hmm, that must be CPU specific. They've always been pretty accurate here.

                                      You might try just turning down the standard fans at run time with WGXepc. I guess it depends how/where you use it but the test boxes are next to my desk and are acceptably quiet like that.

                                      K 1 Reply Last reply Reply Quote 0
                                      • K
                                        korenchkin @stephenw10
                                        last edited by korenchkin

                                        @stephenw10 yeah,it is definitely cpu related,but strange thing is coretemp readings in opnsense seems correct and if i disable coretemp,readings are correct too,only bios(which sets fan speeds)...so i set my preference and added about 25C,so they are sitting idle at ~51C and still way noisier than my more or less idle proxmox i5-7600k.. (i sleep here)

                                        now how about this nice strange form-factor 4-port ethernet card that is in,maybe use it in different board?maybe a little cut in case so it fits? :)

                                        edit (about temperature/consumption): measuring ~26W idle at wall,when crowdsec went wonky and used full cpu,i measured about 38W

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          You could. It's just PCIe, you can make it work with the right adapter. But I'd only do that for fun at this point. 😉

                                          The Mx70 models are pretty cheap and have a module slot. (for values of x between 4 and 6!)

                                          K 1 Reply Last reply Reply Quote 0
                                          • K
                                            korenchkin @stephenw10
                                            last edited by

                                            @stephenw10 i have strange fetish for this kind of devices,i'd like to get my hands on them,but still,i'll have to use some bigger pc-like or passive and keep those for tinker purposes...
                                            i didn't even installed windows 10/11 there yet..just for fun

                                            addon card eats about 2.5W idle unconnected.i'm now down to ~23.8W

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.