Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Trouble booting from USB to install the latest XG Home Edition SW-19.0.1_MR-1-365

Hi all,

I just purchased a new piece of hardware to replace my dying XG Home box.

I downloaded the latest SW-19.0.1_MR-1-365 and burned to USB with RUFUS.  I can't seem to boot from it, it just hangs.

The device in question is here:

https://www.aliexpress.com/item/765856572.html

Specs:

Basic Information:

CPU

Onboard Intel Celeron J6412

TDP

10W

Motherboard

120 x 120mm customized size

BIOS

American Megatrends Inc

Chipset

Elkhart Lake

Memory

1* SO-DIMM DDR4 Slot,Support 4GB/8GB

DDR4-2133, LPDDR3-1866, DDR3L-1600

OS

Windows 10/Linux/WES10

PXE

YES

Audio

Intel High Definition Audio Controller

Network

2 x Realtek 811H Gigabit Ethernet Controller

10/100Mbps/1000Mbps BaseT LAN

Video

Intel® UHD Graphics

Input/output port:

Switch

1 x Power On/Off Switch

Power

1 x 12V DC In

USB

2 x USB2.0, 2 x USB3.0

Display

2 x HDMI 1.4, 1 x DP 1.2

LAN

2 x RJ45 Giga LAN

Audio

1 x MIC, 1 x SPK

COM

2 x DB9 RS232 COM

Storage:

MSATA

1 x M-SATA3.0 slot for MSATA SSD, support 6Gb/s

M.2

1 x M.2 slot for NVME 2280 SSD

SATA

1 x SATA3.0 slot for SATA HDD or SSD, , support 6Gb/s

Wi-Fi:

Module

1 x M.2 2230 slot for Wi-Fi & Bluetooth module

Antenna

2 x inner RF cables and 2 x external antennas

Could it be that the chipset is incompatible?  Or perhaps a setting in the AMI BIOS?

I have :

Disabled secure Boot

I tried MBR burn and GPT Burn

Disabling TPM

Nothing seems to allow me to boot

My next test will be to find n external USB drive that I can burn the ISO to.  I am thinking the UEFI boot may be the issue...  However, i can boot a Windows installer no problem on the device.

Any insights or suggestions would be greatly appreciated!

Cheers,

Ken



This thread was automatically locked due to age.
Parents
  • OK so..   It seems that Intel has removed Legacy BIOS support from all chipsets starting Dec 2020.  This is a latest model Celeron J6412, so therefore incompatible with Sophos.

    Quite odd that in 2022, when hardware vendors are phasing out, or indeed have removed Legacy support, that Sophos doe snot support UEFI.

    Is there a thread of feature request somewhere that UEFI users can request or follow any progress on when this will be implemented?

    Over to pfsense I guess.  Sad as I love Sophos and use their hardware appliances on all my customers.  Just can't justify the cost for my home network.

    Ken

  • Check out the server motherboards, they still support legacy boot, or at least my last purchase does. Asus,  Xeon based with intel nics.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Not, the i219.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi,

    please check these devices, some have intel i211 NICs,

    https://www.amazon.com/pfSense-Firewall/s?k=pfSense+Firewall

    If it is just you travelling, then you do not need a high speed chip, the older j1900 might suit. They are slow to configure..

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • h, OK , so avoid the i219 chipset.  Thanks

  • Well, my family and I travel around the globe and we setup our network which has quite a bit of traffic. I'll need a newer chipset, I think the J4125 will be right. 

    So on this device, with an i210/211 chipset, I should be able to install Sophos on?

    https://www.aliexpress.com/item/1005004740762730.html

    Cheers,

    Ken

  • I recommend you to not spend money on those low-end appliances.

    It will be much better to buy a N5105 or J6413 with the I226-V NIC and use Proxmox to virtualize Sophos Firewall since the overhead with KVM is minimum to non-existent, and It will allow you to use the 2.5G port to It's fullest.

    If you do this, in the future when Sophos starts shipping a installer with UEFI support you will be able to overwrite Proxmox and use the appliance as bare-metal.


    If a post solves your question use the 'Verify Answer' button.

    XG 115w Rev.3 8GB RAM v19.5 MR1 @ Home.

  • Not, the i219.

    Does the XG not support this chipset?

  • f you do this, in the future when Sophos starts shipping a installer with UEFI support you will be able to overwrite Proxmox and use the appliance as bare-metal.

    It's more than just UEFI requirement. The kernel of the firmware has to be updated to a newer version to support the newer NICs without needing to virtualize.  The current kernel included in the Sophos Firewall was released in 2016. That's a really old kernel. 

  • The current kernel included in the Sophos Firewall was released in 2016. That's a really old kernel. 

    Sophos Firewall v19.5 is currently running: Linux localhost 4.14.277

    The 4.14 is a LTS branch, the version the Firewall is running is from April 2022.

    If you virtualize with KVM and use VirtiO you won't need to worry about firmware or UEFI support with the Firewall. From this scenario It doesn't make sense to get an older appliance just because the Firewall doesn't have a newer Kernel.


    If a post solves your question use the 'Verify Answer' button.

    XG 115w Rev.3 8GB RAM v19.5 MR1 @ Home.

  • Sophos could without much effort change the SFOS to support EUFI boot because the hardware version of XG I believe already supports UEFI boot.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • I would like to remind you we're home users, we don't have a support contract.

    Because of this home users have to work with what they got, since using KVM to virtualize the Firewall won't cause a considerable performance drop, It doesn't make sense to get an older appliance when you can just... virtualize It.

    Sophos could without much effort change the SFOS to support EUFI boot because the hardware version of XG I believe already supports UEFI boot.

    I've been hearing this for years, since they still don't support UEFI over Software installations It's better to buy something new and virtualize the Firewall instead of waiting for a miracle. (Or maybe they bring support with v20, who knows.)


    If a post solves your question use the 'Verify Answer' button.

    XG 115w Rev.3 8GB RAM v19.5 MR1 @ Home.

Reply
  • I would like to remind you we're home users, we don't have a support contract.

    Because of this home users have to work with what they got, since using KVM to virtualize the Firewall won't cause a considerable performance drop, It doesn't make sense to get an older appliance when you can just... virtualize It.

    Sophos could without much effort change the SFOS to support EUFI boot because the hardware version of XG I believe already supports UEFI boot.

    I've been hearing this for years, since they still don't support UEFI over Software installations It's better to buy something new and virtualize the Firewall instead of waiting for a miracle. (Or maybe they bring support with v20, who knows.)


    If a post solves your question use the 'Verify Answer' button.

    XG 115w Rev.3 8GB RAM v19.5 MR1 @ Home.

Children
  • Thanks to you all for your great advice.  Since I would ideally not want to spend any more money on a device at the moment, I'm going to try Proxmox first.  My current device is more than powerful enough and has 8Gb RAM.

    I'll report back once I have tested.

    Thanks again!!!