Beware of EMC switches sold as Mellanox SX6XXX on eBay

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

Freebsd1976

Active Member
Feb 23, 2018
431
79
28
It's a 6018. I've done a few with no issues. Was just bad luck this time I guess. It was really cheap so not the end of the world. I'll probably put it to one side to fix at some point. Thank you all for the input. Has been educational :)
desolid nor flash, use a programmer write uboot to nor flash, then resolid, the switch will have uboot and kernel and ftd in the nor flash, and run remanufacture again. this is not so difficult , especially someone already post image of nor flash in this thread.
 
  • Like
Reactions: Marc_

Marc_

Chief breaker of switches
Jul 22, 2022
115
21
18
desolid nor flash, use a programmer write uboot to nor flash, then resolid, the switch will have uboot and kernel and ftd in the nor flash, and run remanufacture again. this is not so difficult , especially someone already post image of nor flash in this thread.
It's time for me at the moment is this issue. I'll get to it soon and give it a go. I like learning so I'm looking forward to it.
 

miloman

New Member
Apr 10, 2021
6
0
1
I can buy a SX6012 and it;s mentioned 'NO OS'. Would it still be possible to flash it with mellanox firmware using (part of) the guide which is mentioned here>
 

Stephan

Well-Known Member
Apr 21, 2017
1,127
895
113
Germany
I can buy a SX6012 and it;s mentioned 'NO OS'. Would it still be possible to flash it with mellanox firmware using (part of) the guide which is mentioned here>
Can fix it up completely unless boot loader is wiped. If there is absolutely no output on serial on all baud rates, and you tried two cables, only way to rescue is JTAG (BDI 2000) and a bunch of files.
 
  • Like
Reactions: miloman

miloman

New Member
Apr 10, 2021
6
0
1
Ok, thanks. Took the gamble, my offer was accepted very quick, so expecting the worst

Can fix it up completely unless boot loader is wiped. If there is absolutely no output on serial on all baud rates, and you tried two cables, only way to rescue is JTAG (BDI 2000) and a bunch of files.
 

86turbodsl

Active Member
Feb 24, 2020
120
36
28
I've got a freshly updated SX6036. Updated to 3.6.8012. Can some kind soul help me understand how to get licensing figured out? I haven't a clue how to sort that.
 

bekax

New Member
Feb 14, 2017
22
0
1
37
Anyone knows if after activating an IPL cluster between two SX6012 for ethernet MLAG, do I loose the chance to manage IB SM ?

It shows my IB HA VIP as 0.0.0.0, and I am unsure how to change this one since the option is greyed out and states:
"Please change SM configuration from Virtual management IP (VIP)."
 

Marc_

Chief breaker of switches
Jul 22, 2022
115
21
18
Morning all, got a strange one. Picked up a cheap EMC sx6012 and sx6018. Converted as I have in the past with no issues following the guide. Did the first update to update from the manufacture image. When both rebooted they failed in exactly the same way - would not configure the modules. Attempted to re-load again from the beginning, which was fine. Checked everything over and I am stumped. They both boot, and I can log in but eventually I get to the CLI but the switch prompt on both is unknown. PSID of each is correct and displaying correctly. I just can't make them function. Any help here is much appreciated.
 
  • Like
Reactions: abq

Marc_

Chief breaker of switches
Jul 22, 2022
115
21
18
Think I've found the problem but not sure why I can't read the info :(

switch-5d084c [standalone: *unknown*] # show inv
=================================================================================================
Module Type Part number Serial Number Asic revision HW Revision
=================================================================================================
CHASSIS N/A N/A (null) N/A (null)
No managed modules found.

I've double checked everything from the guide (I've done a few with no issue) but this actually has me stumped. Everything looks correct.
 

Marc_

Chief breaker of switches
Jul 22, 2022
115
21
18
Had a bit more time to look at this finally. The systems both pause for quite a long period here (booting the earliest image to rule things out)

U-Boot 2009.01 SX_PPC_M460EX SX_3.2.0330-82 ppc (Dec 20 2012 - 17:53:54)

CPU: AMCC PowerPC 460EX Rev. B at 1000 MHz (PLB=166, OPB=83, EBC=83 MHz)
Security/Kasumi support
Bootstrap Option H - Boot ROM Location I2C (Addr 0x52)
Internal PCI arbiter disabled
32 kB I-Cache 32 kB D-Cache
Board: Mellanox PPC460EX Board
FDEF: No
I2C: ready
DRAM: 2 GB (ECC enabled, 333 MHz, CL3)
FLASH: 16 MB
NAND: 1024 MiB
PCI: Bus Dev VenId DevId Class Int
PCIE0: link is not up.
PCIE1: successfully set as root-complex
01 00 15b3 c738 0c06 00
Net: ppc_4xx_eth0, ppc_4xx_eth1
Reading image settings from EEPROM

Mellanox MLNX-OS

Default image: 'PPC_M460EX 3.6.8010 2018-08-20 18:04:16 ppc'
Press Enter to boot this image, or 'Ctrl B' for boot menu

Booting default image in: 0


Mellanox MLNX-OS Boot Menu:

1: SX_PPC_M460EX SX_3.4.0012 2014-12-15 23:27:42 ppc
* 2: PPC_M460EX 3.6.8010 2018-08-20 18:04:16 ppc
u: USB menu (if USB device connected)
c: Command prompt

Choice:


Booting location 1: 'SX_PPC_M460EX SX_3.4.0012 2014-12-15 23:27:42 ppc'

INIT: version 2.86 booting

Starting: SX_PPC_M460EX SX_3.4.0012 2014-12-15 23:27:42 ppc
Starting udev: [ OK ]
Setting clock (utc): Wed Apr 8 10:49:52 UTC 2026 [ OK ]
Setting hostname localhost: [ OK ]
Checking filesystems
Checking all file systems.
[ OK ]
Remounting root filesystem in read-write mode: [ OK ]
Mounting local filesystems: [ OK ]
Running vpart script: [ OK ]
Applying file system skeletons: base_var base_config .
Enabling /etc/fstab swaps: [ OK ]
INIT: Entering runlevel: 3
Starting system services
Starting sx_low_level_if: Starting sx_low_level_if:
Loading i2c_mux_pca954x driver - Success
Loading glue logic low level - Success
Loading watchdog - Success
Loading cpld handler - Success
Loading mellaggra module - Success
Loading sx i2c module - Success
[ OK ]
Starting openibd: IPoIB configuration for embedded system
Loading SX driver:[ OK ]
Loading HCA driver and Access Layer:[ OK ]
Setting up InfiniBand network interfaces:
Setting up service network . . .[ done ]
Reloading udev:
[ OK ]
Starting system logger: <--------------- Pauses here for around 3 minutes and continues as normal:

Starting system logger: [ OK ]
Starting kernel logger: [ OK ]
Running renaming interfaces
Renaming: MAC: E4:1D:2D:5D:08:4C ifindex: 2 name: mgmt0
Renaming: MAC: E4:1D:2D:5D:08:4D ifindex: 3 name: mgmt1
Checking for unexpected shutdown

Probing for HRNG module
Starting rngd: [ OK ]
Running system image: SX_PPC_M460EX SX_3.4.0012 2014-12-15 23:27:42 ppc
Applying initial configuration: Apr 08 10:53:14 INFO LOG: Initializing SX log with STDOUT as output file.
Starting internal_startup: [ OK ]
Starting tc_ingress_policy: tc_ingress_policy system name is not obtained - use default IS5600MDC
mDNS policing rate=4000kbit burst=400k
Ingress policing enable on interface mgmt0 rate=9000kbit burst=900k
[ OK ]
Starting clean_issnvram: Deleting issnvram.txt
[ OK ]
Starting intr_hndl: Starting :
Loading int handler module - Success
[ OK ]
Starting iss-nvram-mac: [ OK ]
Starting copy_rh_files_to_vtmp: [ OK ]
Starting sx_pra: Starting proxy arp management:
Loading proxy arp management module - Success
[ OK ]
Starting udevd: Reloading udev...
[ OK ]
Starting pm: [ OK ]
Starting oops_dump_reg: Starting kernel reg dump:
Loading kernel reg dump module - Success
[ OK ]
Starting lnpuppetvar.sh: [ OK ]
Starting mst: Starting MST (Mellanox Software Tools) driver set
Loading MST PCI module - Success
Loading MST PCI configuration module - Success
Create devices
[ OK ]
Mellanox MLNX-OS Switch Management

switch-5d084c login: admin
Password:
Last login: Wed Apr 8 10:32:21 on ttyS0

Mellanox Switch

System is initializing!
This may take a few minutes


Modules are being configured <------- this seems to be where the issue is occurring

After this, the system will eventually progress to the login. I log in and this is where my issue definitely lies. The switch doesn't seem to know what it is. Everything else seems to have loaded fine, I even have the web ui. I've checked the obvious, double checked my files from the initial conversion and everything is perfect. I just can't see how a small firmware update has bricked them both. Brought 4 of them, 2 converted with zero issues.

Checking the mst status results in the correct info:
[admin@switch-5d084c ~]# mst status
MST modules:
------------
MST PCI module loaded
MST PCI configuration module loaded

MST devices:
------------
/dev/mst/dev-i2c-0 - Embedded I2C master
/dev/mst/dev-i2c-1 - Embedded I2C master
/dev/mst/mt51000_pciconf0 - PCI configuration cycles access.
domain:bus:dev.fn=0001:81:00.0 addr.reg=88 data.reg=92
Chip revision is: 02

flint -override_cache_replacement -d /dev/mst/mt51000_p

-W- Firmware flash cache access is enabled. Running in this mode may cause the firmware to hang.

-W- Running quick query - Skipping full image integrity checks.

Image type: FS2
FW Version: 9.3.1260
Device ID: 51000
Description: Node Sys image
GUIDs: e41d2xxxxxxx2cc0 e41d2xxxxxx
MACs: e41dxxx2cc0 e41d2xxx2d20
VSD: n/a
PSID: MT_1270110020

So far I have tried:
loading a later firmware - no change
Starting from scratch and converting again - no change
Stripping the switch down and reseating everything - no change

At this point I'm thinking it is scrap :(
 

klui

༺༻
Feb 3, 2019
1,060
625
113
Try swapping one of the management modules from your working switches to see if that's a problem or something else.
 
  • Like
Reactions: Marc_

Marc_

Chief breaker of switches
Jul 22, 2022
115
21
18
Try swapping one of the management modules from your working switches to see if that's a problem or something else.
That was the final step really. Will give it a go tonight. If that fails at least I have some spares I guess :)
 

cktm57

New Member
Mar 1, 2021
22
3
3


Subject: Stuck on 3.5.1006: Need help correcting FRU to SX6012 (mellaggra available, no U-Boot access)

Hi everyone,

I'm looking for specific advice on fixing the FRU on an EMC SX6012 that's been converted. I've read through the massive EMC switch thread and tried many things, but I'm stuck at a very specific point.

Current state:
- OS: MLNX-OS 3.5.1006 (PPC_M460EX). System is stable, CLI works.
- Problem: The system model is 'ppc', not 'SX6012'. Web UI crashes with 'fatal internal error'. Port drivers (mlx4) are missing, so IB/Eth ports are unusable.
- U-Boot: Access is locked (password unknown). 'Command prompt' and 'USB menu' require a password that isn't admin/mellanox/root. Hardware reset button did not clear it.
- FRU/PSID: PSID is already correct (MT_1270110020). I have tried patching the FRU EEPROM.

What I have access to:
- Full CLI and 'fae' mode.
- The 'mellaggra' utility with '_read_fru' and '_write_fru' commands.
- I've scanned the I2C bus (mlxi2c scan) and found devices at 0x51 and 0x70.
- I can read/write to these EEPROMs using mellaggra (the FRU dump is 8192 bytes, not 256).

The specific problem:
Using 'mellaggra _write_fru 8 0x51 /tmp/fru_patched.bin' (or 0x70) appears to work (no error), but after a reboot, 'show version' still reports 'Product model: ppc'. The system seems to ignore my changes.

My question:
Does anyone know the *exact* I2C bus, address, and mellaggra parameters to correctly write the FRU for an SX6012 on version 3.5.1006? Alternatively, is there a command in 'fae' mode to force the system profile to 'SX6012'? 'mlxi2c -s SX6012 chassis_fru' fails with an init error.

Any specific guidance would be greatly appreciated. I'm trying to get this stable enough to upgrade to 3.6.x and get the ports working.
 

cktm57

New Member
Mar 1, 2021
22
3
3
Hi everyone,

I've been working on converting an EMC SX6012 following the famous dodgy route guide. I've read the massive EMC switch thread and tried many things, but I'm completely stuck at a specific point and need expert advice.

Current state:
- OS: MLNX-OS 3.5.1006 (PPC_M460EX) on partition 2. System is stable, CLI works.
- Partition 1 has 3.4.0012 installed, but it fails to load port drivers due to 'mlxi2c failed: cant read system type'.
- PSID is correct: MT_1270110020.
- FRU: I have tried patching it using mellaggra, but the system model is still 'ppc', not 'SX6012'. I have a backup of the original 8192-byte FRU dump.

The MAIN problem:
- U-Boot access is COMPLETELY locked. 'Command prompt' and 'USB menu' require a password. I have tried all known defaults (admin, root, mellanox, etc.).
- Hardware reset button (held for 15+ secs) resets the admin password but does NOT clear the U-Boot password.
- I cannot use the 'fae' mode to reset the U-Boot password because the required command fails on 3.5.1006.

What I've tried to force MFG:
- Downgraded to 3.4.0012 and 3.3.5006, but U-Boot password remains.
- Tried to force a network boot by corrupting the OS partitions (flash_erase), hoping U-Boot would fall back to TFTP. It did not; it just looped trying to boot from the corrupted partition.
- Tried booting from a USB drive prepared with the MFG files (vmlinuz, rootfs, fdt in /mlnx460ex/). U-Boot ignores it and boots from NAND.

My specific question:
Given that U-Boot is locked and all software methods to reset the password have failed, is there ANY known method, trick, or exploit to force this switch to boot into Manufacturing Environment (MFG) over the network or from USB?

I'm trying to avoid the hardware programmer route if at all possible. Any insights from the gurus would be greatly appreciated.

Thanks in advance!
 

klui

༺༻
Feb 3, 2019
1,060
625
113
Re-read the guide.

3.4.0012 never gets the system type but you wouldn't be using it normally, only as a point where you can update to other versions.

The guide has a section that mentions removing the bootloader password.
 
  • Like
Reactions: jode

cktm57

New Member
Mar 1, 2021
22
3
3
Re-read the guide.

3.4.0012 never gets the system type but you wouldn't be using it normally, only as a point where you can update to other versions.

The guide has a section that mentions removing the bootloader password.
You're absolutely right. Thank you for pointing that out—it's a crucial distinction that's easy to miss when you're deep in troubleshooting. Re-reading the guide with that perspective makes it clear that 3.4.0012 is just a stepping stone, not the final destination. The bootloader password removal section was indeed the key. Appreciate the insight.
 

cktm57

New Member
Mar 1, 2021
22
3
3
I'm following the EMC conversion guide on an SX6012 and have hit a wall with the FRU modification step. I'm hoping someone with deeper hardware knowledge might have an idea.

Current state:
- OS: MLNX-OS 3.5.1006 and 3.4.0012. CLI works, U-Boot access is unlocked.
- FRU is currently original EMC (system model shows as 'ppc').

The problem:
I am trying to write the patched FRU using the standard command in the guide:
`/opt/tms/bin/mellaggra _write_fru 1 0x51 0 /tmp/fru_patched_new.bin`

The command executes **without any errors**. I can even read back the FRU to a new file, but a binary comparison (`cmp -l`) shows **no changes**—the EEPROM contents remain the original, unmodified version. It's as if the write command is being silently ignored.

I have already:
- Verified the correct I2C bus and address (`1 0x51`).
- Tried writing from both the installed OS and a clean Manufacturing Environment (MFG).
- Attempted a direct `eeprom write` from the U-Boot command line.
- Inspected the board for a Write Protect (WP) jumper. The only jumper present (J39) is a boot enable/disable switch and has no effect on the EEPROM.

The write operation appears to succeed at the software level, but the hardware refuses to change. Has anyone else encountered this? Could there be another software lock, or is the EEPROM write-protected via a pull-up resistor that requires a hardware mod?

Any insights would be greatly appreciate
 

Freebsd1976

Active Member
Feb 23, 2018
431
79
28
/opt/tms/bin/mellaggra _write_fru 1 0x51 1000 fru_patched.bin

btw do not use `eeprom write` from the U-Boot command line. you will brick your switch