Dell VEP/VMWare Edge/Velo Cloud SD-WAN/VeraCloud VEP1400/VEP1400-X firewall units

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

frollic

New Member
Aug 29, 2016
12
1
3
35
This is exactly what worked on my first unit, but just would not work on the second unit.
Strange, I've flashed more than 10 of these (mainly 620s, but also two 640s and one 680), never had this issue, "it just worked".
 

ericloewe

Active Member
Apr 24, 2017
351
169
43
32
That link also contradicts my findings of the 620 not having a blue LED, since they use that to indicate HA status. Maybe later revisions dropped the HA ability and thus the blue LED? Dunno, but I doubt it. Maybe the blue LED is just burnt out on both 620s of mine.
Mine definitely have the blue LED, though they're not particularly recent (late 2019/early 2020 production).

Yeah, this could have been done in the BIOS, but maybe the SoC didn't have the GPIO pins to do all of it, so that's why they added the CPLD and PIC.
How many pins would they really need though? C3000 seems to have at least 14 readily available (not shared with anything), plus a few more that share pins with functions that might be irrelevant for this platform. I count maybe 17 as a ceiling of what they'd need, but it feels like they could get these down quite a bit (e.g. by not providing whatever disconnection mechanism they're using for eMMC, the main SSD, WiFi, and Celular, since those can simply be omitted at the factory):
  • I350
  • X553 SFP
  • X553 copper
  • eMMC
  • SSD
  • WiFi
  • Cellular
  • LED x3?
  • Button x3?
  • Mystery switches x2
  • USB x2
Fans not included because relying on the GPIO interrupt to measure the fan speed would be absolutely insane, and the SuperIO or dedicated fan controller would just go on the LPC or I2C. Most SuperIOs also add a few GPIO pins... Fake edit: Oh wow, going through the datasheet, I just noticed that C3000 has an embedded fan controller, apparently using the dedicated management core inside the SoC - which I suspect few OEMs ever used, instead sticking to whatever stack they already had.
 

individualeleven

New Member
Aug 6, 2026
8
3
3
Mine definitely have the blue LED, though they're not particularly recent (late 2019/early 2020 production).
According to Dell, mine are a year or two newer:
Proxmox 620: March 23, 2021
OPNsense 620: June 4, 2022

I'd say that maybe there was a cutoff date for a new revision without the blue LED, but going back to that VMware employee's blog, he made that post in 2021 so I would assume that unless VMware had a lot of these units sitting around (for this in-house WFH program), he would have gotten a unit made around that year.

How many pins would they really need though? C3000 seems to have at least 14 readily available
Good counterpoint, I hadn't looked up the datasheet, so I had no idea. Guess it's just typical DellEMC over-engineering. Yeah, the fan and the LED are controlled via the second i2c/SMBus controller specific to Denverton and other Atoms (i2c_ismt in Linux and ismt in FreeBSD) (there's also the "common" Intel ICH SMBus controller, but that's only used for the RAM SPDs, AFAIK).
 

Klee

Well-Known Member
Jun 2, 2016
1,302
411
83
Today I traded a four year old gaming case for "some kind of enterprise firewall" and that turned out to be a new in the box DELLEMC VEP1425 with mounting brackets, power brick, power coard, and a usb to micro usb cable and a couple of manuals.

Shows to be preinstalled with Versa OS, never messed with it.

I read some of the posts in this thread today at work so this should be a interesting project.









Started to do a little disassembly, mainly to check the bios battery voltage so I tested it without removing it and its 3.02 v so not dead.

Has a empty sodimm slot, and a Apacer 128 gb m.2 SSD.

Zero dust inside, fan is clean so I think its new.

I guess i'm late to the party on this. LOL
 
Last edited:

nmpu

Active Member
Sep 22, 2023
246
116
43
Bradenton, Florida, USA
Looks good. Also known as Edge 620N in a white shell.

Only disadvantage is that it likely doesn't have the mini-PCIe slot which supports PCIe 3.0 x1 and USB 2.0 (with missing filter choke fitted).
 
Last edited:

Klee

Well-Known Member
Jun 2, 2016
1,302
411
83
I have very modest plans, just a firewall.

Something to replace my current router since it looks like i'll be able to have fiber internet in a few months so this will probably will be a transition router for a while.
 

Klee

Well-Known Member
Jun 2, 2016
1,302
411
83
It's alive!!

Connected via minicom.

Sorry for the MSDOS flashback. :p













Did not change anything in the bios and did not look at all the options yet.

Seems to have a 2022 bios date, so newer than I was expecting.

Version 3.48.0.9-16 so does this need to be updated or is it new enough not to worry about?

"The BIOS version 3.48.0.9-16 is included in the Dell VEP1405 series (which includes the VEP1425, VEP1445, and VEP1485) documentation as part of the Revision A09 release notes dated June 2022. This firmware version was updated alongside DIAG version 3.43.3.81-26 and Firmware updater version 1.9.1.

Key specifications for this BIOS release include:

  • Platform: Dell EMC Virtual Edge Platform 1405 Series.
  • Associated Firmware: PIC v30P and CPLD v07.
  • Security: Supports Trusted Platform Module (TPM) 2.0 with options for SHA-1 or SHA256 in the Provision Coverage Ratio (PCR) banks.
  • Boot Configuration: Allows configuration of Boot Option Priorities and UEFI settings via the BIOS setup screen. "

Plugged a Ethernet cable from my switch in my bedroom to GE5 and can see it on my lan and can ping it.

I just wanted to make sure the thing actually worked as my only goal tonight.

Just downloaded the latest bios and diag files from Dell.

The "diagos-recovery-x86_64-dellemc_vep1400_c3538-r0.3.43.3.81-27" looks like only one version newer than what I have.

I'm about to page 20 in this thread, and seeing all the horror stories about updating the bios and firmware I really would be happy to not have to deal with that.
 
Last edited:

Klee

Well-Known Member
Jun 2, 2016
1,302
411
83
I have one question, I have an older motherboard that has an embedded Celeron that has a M.2 connector that works and boots with a SSD and I have installed Windows 10 on it.

Could I just pull the M.2 128 gb SSD from this device and install it into the other system and install a OS on it then put it back?

Not the end of the world if not, I have done that before with hard drives and SSD's with Linux in other systems and would be nice to have a display during instillation of an OS.
 

Eld

New Member
Aug 3, 2026
1
2
1
Hey all. Thanks to this thread I've been able to make use of some second hand DELL VEP1400-X. All your work is much appreciated! I had noise issues with the original noisy 40mm Delta fans and wasn't able to find silent 40mm replacements, so I made a 3D printer design to replace the bottom plate with one that accommodates a 50mm fan. I'm not sure if the bottom plate is exactly the same in other models such as Edge 6XX, etc?.. but anyway... not that exciting but maybe it will be of help if someone has the same idea! Thanks again! Alternative fan mounting bottom plate for a DELL VEP1400-X by electronicsluckydip
 

Attachments

nmpu

Active Member
Sep 22, 2023
246
116
43
Bradenton, Florida, USA
Could I just pull the M.2 128 gb SSD from this device and install it into the other system and install a OS on it then put it back?
Yes, that would work. The drive is 2242 m.2 SATA. Realistically, you'll need to remove the CPU heatsink to gain access. That means a repaste. It might be easier to install on USB (in a system with display) and then copy the image using DiagOS or some other 'live' Linux.
 

nmpu

Active Member
Sep 22, 2023
246
116
43
Bradenton, Florida, USA
Version 3.48.0.9-16 so does this need to be updated or is it new enough not to worry about?
Simply installing the latest DiagOS to the eMMC should disable the watchdog. Unless you need the eMMC for some other purpose, it's nice to have DiagOS handy.

Otherwise, you don't need to update unless some NICs are not visible. You should be able to view the NICs in the BIOS.

The only functional issue I encountered with early BIOS was related to SR-IOV support. I think there's an SSD firmware update which is included in the package. That update can be installed independently of the rest.

I'd have to check dates, but I'm guessing you're at least 2 BIOS revisions behind.
 

Klee

Well-Known Member
Jun 2, 2016
1,302
411
83
Simply installing the latest DiagOS to the eMMC should disable the watchdog. Unless you need the eMMC for some other purpose, it's nice to have DiagOS handy.

Otherwise, you don't need to update unless some NICs are not visible. You should be able to view the NICs in the BIOS.

The only functional issue I encountered with early BIOS was related to SR-IOV support. I think there's an SSD firmware update which is included in the package. That update can be installed independently of the rest.

I'd have to check dates, but I'm guessing you're at least 2 BIOS revisions behind.

I had it running for at least 30 minutes, it never rebooted by itself.
 

individualeleven

New Member
Aug 6, 2026
8
3
3
that turned out to be a new in the box DELLEMC VEP1425
Nice, I'm kinda curious what board ID/type the CPLD reports, if it's the same as the Edge 620, it should be 0x28. If you want to humor me, you can run the command "i2cget -y 1 0x31 0x0" in Linux or "smbmsg -f /dev/smb1 -s 0x62 -c 0x00 -i 1" in FreeBSD (where 1 or smb1 is the number of the i2c bus with the CPLD on it), or if you are installing OPNsense on it, you could install the plugin I wrote and activate the widget to get that info in the web UI dashboard.

Speaking of which, I have managed to build some custom serial images for OPNsense 26.7.2 for these devices.

VEP1400 link
VEP1400-X link
Plugin pkg link

Both images have the patched kernel to setup the Marvell chip in the VEP1400/610 and the vep1400 plugin preinstalled, the VEP1400 image has the extra loader.conf hints to "point" at the switch and a non-default kernel path to prevent the loader from booting an upgraded (non-patched) kernel. During boot-up the init script will configure the switch and display a message like so:
Screenshot_20260828_140011.png

One thing to note: there is a brief period of time between the kernel initializing the switch and the script running where the switch is in a "dumb switch" mode where all ports are connected, this period is slightly longer (still under a minute) on the live/install media because of all the first-boot setup/import helpers. If this is a concern, unplug the WAN from port 6 during boot in the installer or use one of the SFP ports (ix2 or ix3) for the WAN.


The VEP1400-X image is just the patched kernel, vanilla base and the vep1400 plugin to set things up, and it's ok to boot an upgraded kernel on those (there is no loader.conf.local keeping it to a particular kernel).

The pkg link is just for the plugin itself, if you want to download an official serial image and can figure out how to get the plugin onto the box (over network or USB) and then do a "pkg add (filename)" on the console or SSH.


Also, if anyone has a 640 or 680 for plugin testing (that's already running OPNsense or is available to run it), I would appreciate it if you could report your board ID to me for a small cosmetic fix. The hardware widget right now will report two fans, even on a 620/1425 that has one fan. I'd like to know the board ID for those with two actual fans to see if that is something I can detect for, so that I can hide the "phantom" fan in the UI for a 620.
 

RoyBR

New Member
Sep 1, 2026
1
0
1
I'm dealing with a bricked Dell EMC VEP1400-X (Edge 620) and could really use some advice from anyone familiar with this hardware architecture.

What happened: I was updating the BIOS, and unfortunately, there was a power outage right in the middle of the flashing process. Now the unit is completely unresponsive and failing to POST.

Symptoms:

  • The device is stuck in a continuous hardware boot loop.
  • When plugged in, the fan spins up, the front LED turns Red, it stays on for exactly 5 seconds, and then abruptly cuts power. This repeats endlessly.
  • The serial console is dead. It outputs a single garbled character (▒) right before the power cuts out, meaning it halts before initializing the UART properly.
What I've tried so far:

  • Full cold boot (unplugged power supply for 10+ minutes to drain CPLD/capacitors).
  • Opened the chassis and tried holding the internal S1 and S2 push buttons while applying power.
  • Toggled the internal SW2 DIP switches located next to the BIOS chip (tried all combinations, including both OFF/down).
  • Inspected the board for recovery jumpers, but only found what appears to be factory debug/JTAG headers (J80, J21, J39) which I haven't shorted to avoid electrical damage.

My Question: Since this enterprise unit supposedly features a dual-BIOS design, is there a specific physical method (jumper, hidden button sequence, or pin short) to force the CPLD to ignore the corrupted primary chip and boot from the Backup BIOS?

Or, because it's entering a hardware halt in just 5 seconds, is my only viable path to clip a CH341A SPI programmer directly onto the primary Winbond 25Q128JVSQ (U73) SOIC8 chip and flash a clean .bin externally?

Any guidance, documentation, or tips on recovering these boards would be greatly appreciated. Thanks in advance!
 

Arnaud

Member
Jan 18, 2024
41
15
8
Luxembourg
I had faced the exact same issue (on a 640) and ended up flashing the chip directly. IIRC it was corrupted in a way that it prevented switching to the backup bios
 

ericloewe

Active Member
Apr 24, 2017
351
169
43
32
  • The device is stuck in a continuous hardware boot loop.
  • When plugged in, the fan spins up, the front LED turns Red, it stays on for exactly 5 seconds, and then abruptly cuts power. This repeats endlessly.
  • The serial console is dead. It outputs a single garbled character (▒) right before the power cuts out, meaning it halts before initializing the UART properly.
That's exactly what I saw the other day, but just leaving it alone for a good while (15+ minutes? Didn't time it because I wasn't expecting it to magically recover) was enough for it to recover from the endless boot loops. That said, mine was a probably good flash but with bad config settings. Still, it's worth a try if you haven't left it on for an extended period yet.