Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Safeguard 5.60 client POA Boot from External Medium USB WINPE

Hi there,

We have a small form factor pc with no cdrom drive: Optiplex 780 Bios A06, and it has the BCD Boot error.

We have downloaded the latest WINPE iso from here http://www.sophos.com/support/knowledgebase/article/108805.html

"WINPE SGN 5.60.0.192 (based on WinPE 3.0) works for the SGN client 5.60.0.192 and 5.60.1.7. "

and we have the iso burnt to a CD. When our machines with cd roms have boot issues, we insert the cd. Authenticate POA and change the boot device to "External Media". It then authenticates and prompts us to press any key to boot from cd, and away we go. 

As this machine has no cdrom we have created a usb boot disk using the guide:

Building a Standard Image of Windows 7: Building a Standard Image of Windows 7: Step-by-Step Guide

Section: Build Windows 7 Media 

http://technet.microsoft.com/en-us/library/ee523217(WS.10).aspx however we used the iso's boot files not the ones mentioned in the guide .

The usb image works fine when booting from BIOS, we get the A43 Explorer GUI as expected.  When booting from POA external media however nothing happens it skips through too booting the hdd which gives us the windows boot error. I have changed the bios boot order, chose boot from floppy, toggled Shift F3 = switch USB Legacy support (Off/On)* .

Any ideas how to boot from External Medium at the POA and it not be a CD? From my reading this should be possible.

:16941


This thread was automatically locked due to age.
Parents
  • Hi MattR,

    thank you very much for posting.

    To cut a long story short the only secure option to boot a device is booting it prior to the POA and using the Recoverkeys.exe functionality then.

    The reason for this is that the boot after the POA is dependent on the BIOS vendor meaning we can only boot from an external device if the BIOS has loaded the relevant calls. Unfortunately some BIOS vendors terminate these external codes once the boot of the HDD has started. In this case there is no option / workaround etc. to boot from an external device after the POA.

    In this case the vendor would have to change his BIOS else there is no option available.

    I would suggest to connect a USB DVD drive to the machine and check if you can then boot prior to the POA (I have a private machine which is able to do that as well)

    Regards

    Dan

    :17767
Reply
  • Hi MattR,

    thank you very much for posting.

    To cut a long story short the only secure option to boot a device is booting it prior to the POA and using the Recoverkeys.exe functionality then.

    The reason for this is that the boot after the POA is dependent on the BIOS vendor meaning we can only boot from an external device if the BIOS has loaded the relevant calls. Unfortunately some BIOS vendors terminate these external codes once the boot of the HDD has started. In this case there is no option / workaround etc. to boot from an external device after the POA.

    In this case the vendor would have to change his BIOS else there is no option available.

    I would suggest to connect a USB DVD drive to the machine and check if you can then boot prior to the POA (I have a private machine which is able to do that as well)

    Regards

    Dan

    :17767
Children
No Data