Server operations

How to enable PXE boot in BIOS: UEFI and legacy settings by server brand

To enable PXE boot in BIOS, turn on network boot for the NIC port (Network Stack or PXE Device in UEFI mode, the PXE option ROM in legacy mode), pick IPv4 or IPv6, and put the NIC in the boot order, or press F12 at POST to network boot once. Miss one and the NIC never appears.

By Toplink product teamPublished 11 min read

To enable PXE boot in BIOS, three settings have to line up: network boot turned on for the NIC port, the PXE type that matches the boot mode (IPv4 or IPv6 PXE under UEFI, the NIC’s PXE option ROM under legacy BIOS), and a NIC entry in the boot order or the one-time boot menu. When a server refuses to PXE boot, one of these three is almost always off, or it is enabled on a port that has no cable in it. The checklist comes first, followed by the menu paths for Dell, HPE, Lenovo and Supermicro servers.

What you need to turn on for PXE boot

Setting UEFI mode Legacy mode Symptom when it is off
The NIC itself Enabled under Integrated Devices or Onboard LAN Same The NIC does not show up in the operating system either
Network boot driver Network Stack on, plus IPv4 PXE Support or IPv6 PXE Support; on Dell, each PXE Device is configured separately The port’s option ROM set to PXE (Dell calls it Legacy Boot Protocol, Supermicro calls it Onboard LAN Option ROM) No NIC entry in either the boot menu or the boot order
Boot order A UEFI: PXE IPv4 ... entry ahead of the disk in UEFI Boot Order, or a one-time boot The NIC entry ahead of the disk in Boot Sequence or the network device priority list The NIC is listed, but the server boots straight into the OS on disk
Port and protocol Enabled only on the port cabled to the provisioning network, with the protocol that network uses Enabled only on the port cabled to the provisioning network Every port and protocol times out in turn: slow, or an address from the wrong network

One detail that catches people out: UEFI firmware usually builds its boot entries at power-on from the current settings. After you enable PXE on a port, save and reboot once before the NIC entry appears in the boot order.

Check the boot mode first: UEFI PXE and legacy PXE are different

The same NIC runs two entirely separate pieces of boot code in UEFI and legacy mode. The BIOS switches are different, and so are the files the PXE server has to send:

UEFI mode Legacy mode
BIOS switches Network Stack, PXE Device, UEFI PXE Boot Policy NIC option ROM, Network option under CSM
Example boot entry UEFI: PXE IPv4 Intel(R) Ethernet ... IBA GE Slot ..., NIC in Slot ..., depending on the NIC firmware
Client architecture in the DHCP request (option 93) Usually 7 for x64 UEFI, 9 on some firmware 0
Boot file to serve ipxe.efi, or a signed shimx64.efi plus grubx64.efi pxelinux.0, undionly.kpxe
Secure Boot Enforced: the boot loader must carry a signature the firmware trusts Not applicable

The provisioning server reads option 93 to tell the two kinds of client apart and sends each one the matching file. When the BIOS boot mode and the server-side configuration disagree, you get the familiar “got an IP address but could not load the boot file” failure. Legacy boot is on its way out: HPE ProLiant Gen11 no longer offers a legacy boot mode, and other vendors are narrowing legacy support on new platforms (check the documentation for your model). For newly racked servers, standardize on UEFI PXE.

Where the PXE settings are in each server brand’s BIOS

Start with the POST keys. The prompt on the boot screen is the final word:

Brand BIOS setup One-time boot menu Direct network boot
Dell PowerEdge F2 F11 F12
HPE ProLiant Gen9 and later F9 F11 F12
Lenovo ThinkSystem F1 F12 Pick the NIC in the F12 menu
Supermicro Del F11 F12
Other AMI-based and white-box boards Usually Del Usually F11 Usually F12

Dell PowerEdge (14th generation and later, UEFI mode)

  1. Press F2 at POST and go to System BIOS → Network Settings.
  2. Set PXE Device1 to Enabled and open PXE Device1 Settings. Under Interface, choose the port cabled to the provisioning network (for example NIC Integrated 1 Port 1 Partition 1); under Protocol, choose IPv4 or IPv6. If the provisioning network needs a tagged VLAN, enable VLAN here and enter the VLAN ID.
  3. You can configure up to four PXE Devices. Leave the ones you do not need Disabled.
  4. Go back to System BIOS → Boot Settings → UEFI Boot Settings and move PXE Device 1 to the position you want in UEFI Boot Sequence.
  5. Back → Finish, save and reboot.

If an add-in NIC does not appear, check System BIOS → Integrated Devices → Slot Disablement: its slot must not be set to Boot Driver Disabled. On 13th-generation and older machines running in BIOS boot mode, open the port’s NIC Configuration under Device Settings, set Legacy Boot Protocol to PXE, then adjust Boot Sequence under BIOS Boot Settings.

HPE ProLiant (Gen9 and Gen10)

  1. Press F9 at POST and go to System Utilities → System Configuration → BIOS/Platform Configuration (RBSU) → Network Options → Network Boot Options.
  2. Find the port cabled to the provisioning network (Embedded LOM 1 Port 1, Embedded FlexibleLOM or a PCIe slot NIC; names vary by model) and set it to Network Boot.
  3. On the same Network Boot Options page, set UEFI PXE Boot Policy to IPv4 only, IPv6 only, or an order of the two, to match your network. The available choices vary by generation and firmware version.
  4. Press F10 to save and reboot once. After the new network boot entry has been created, adjust its position in UEFI Boot Order under Boot Options.

Lenovo ThinkSystem

  1. Press F1 at POST and choose UEFI Setup → System Settings → Network.
  2. Under Network Stack Settings, enable Network Stack, then IPv4 PXE Support or IPv6 PXE Support as needed.
  3. Some models also offer per-port network boot under Network Boot Settings. Make sure the port cabled to the provisioning network is not turned off there.
  4. Move the NIC entry under Boot Manager → Change Boot Order, then save and exit.

Menu names vary slightly between models and firmware versions, so treat Lenovo’s UEFI setup guide for your model as the reference.

Supermicro and other AMI BIOS boards

  1. Press Del at POST and go to Advanced → Network Stack Configuration. Set Network Stack to Enabled and Ipv4 PXE Support to Enabled, and turn off Ipv6 PXE Support if you do not provision over IPv6. The same page usually has PXE boot wait time and Media detect count; raise Media detect count if the link comes up slowly.
  2. For legacy PXE on Supermicro, also go to Advanced → PCIe/PCI/PnP Configuration, set Onboard LAN Option ROM Type to Legacy and the port’s Onboard LAN Option ROM to PXE. On other AMI boards, check whether the Network item under CSM Configuration loads the UEFI or the legacy driver.
  3. On the Boot page, set Boot mode select to UEFI (or Legacy or Dual if you need them) and move the UEFI Network entry to the position you want in the boot priorities.
  4. Save & Exit.

Other vendors lay their menus out differently, often with per-port PXE settings under a NIC or PXE item in the Advanced menu. The model’s BIOS reference guide is the authority there.

Network boot just once: F12, the boot menu and the BMC

Provisioning usually needs a single network boot, after which the server should boot from disk again. The safer pattern is to keep the disk first in the permanent boot order and request a network boot only when you need one. There are three ways to do that:

  • At the console, local or remote: press F12 at POST for a direct network boot (Dell, HPE, Supermicro), or press F11 or F12 for the boot menu and pick the NIC entry. Network boot still has to be enabled as described above, or there is no NIC entry to pick.
  • Through the BMC: choose PXE as the next boot device in the BMC web interface, or run ipmitool chassis bootdev pxe options=efiboot, then restart. The setting applies to the next boot only.
  • From Linux, if the server still boots: list the boot entries with efibootmgr, then run efibootmgr --bootnext <number> so the next boot uses the NIC.
# Out of band through the BMC: PXE on the next boot only, in UEFI mode
ipmitool -I lanplus -H 10.20.1.11 -U admin -P 'password' chassis bootdev pxe options=efiboot
ipmitool -I lanplus -H 10.20.1.11 -U admin -P 'password' chassis power cycle

# From a running Linux system: find the NIC entry number, boot it once
efibootmgr
efibootmgr --bootnext 0003
reboot

If you put the NIC permanently ahead of the disk instead, every reboot asks for PXE first. If a job is ever left behind on the provisioning server, that machine can be reinstalled on its next restart.

Bulk changes: set BIOS attributes with racadm or Redfish

Walking through the BIOS on dozens of identical servers is slow. You can change BIOS attributes through the BMC instead, and they take effect on the next reboot. Dell’s attribute names are stable:

# Show the current network boot settings
racadm get BIOS.NetworkSettings
# Enable PXE Device1, bind it to onboard port 1 and use IPv4
racadm set BIOS.NetworkSettings.PxeDev1EnDis Enabled
racadm set BIOS.PxeDev1Settings.PxeDev1Interface NIC.Integrated.1-1-1
racadm set BIOS.PxeDev1Settings.PxeDev1Protocol IPv4
# Create a BIOS configuration job; it is applied on reboot
racadm jobqueue create BIOS.Setup.1-1
racadm serveraction powercycle

Other vendors use different attribute names. List them over Redfish first and look for the ones related to PXE and Network Stack:

# Dell's system ID is System.Embedded.1, HPE and many others use 1; GET /redfish/v1/Systems/ to confirm
curl -sk -u admin:'password' https://10.20.1.11/redfish/v1/Systems/System.Embedded.1/Bios \
  | python3 -m json.tool | grep -i -E 'pxe|network'

To change them, send a PATCH to Bios/Settings under the same resource with the attributes inside Attributes; they apply on the next reboot. Whether you also need to create a job, and how each value has to be written, depends on the vendor’s Redfish documentation. Try the change on one server first, confirm the expected NIC entry appears in the boot menu, then roll it out to the rest of the batch.

NIC missing from the boot menu, or PXE gives up at once

Symptom Common cause Fix
No NIC entry in the boot menu or the boot order Network boot not enabled; enabled on a different port; no reboot since the change Enable it on the right port, save, reboot once and look again
Only legacy NIC entries, or only UEFI ones The boot mode does not match the switch you turned on UEFI mode needs Network Stack; legacy mode needs the NIC option ROM
An add-in NIC never appears The slot’s boot driver is disabled, or the NIC’s own boot function is off Check the slot setting; in legacy mode Intel and Broadcom NICs open their boot agent setup with Ctrl+S during POST, in UEFI mode use Device Settings in the BIOS
The NIC entry starts, then reports no DHCP offer and moves on The link has just come up and the switch port is still going through spanning tree; classic STP takes about 30 seconds to start forwarding Make server-facing ports edge ports (spanning-tree portfast on Cisco); on models with a slow link, raise Media detect count
The server’s two ports form an LACP bundle on the switch The NIC does not negotiate LACP during PXE, so the bundle does not forward Enable LACP fallback on the switch (the name varies by vendor), or use a single port while provisioning
Cable in port 2, PXE enabled on port 1 Port mismatch Check which port the PXE settings are bound to, and confirm the cabled port in the switch MAC address table
The provisioning network expects a VLAN tag Firmware sends DHCP requests untagged by default Make the switch port an access port in the provisioning VLAN, or set the VLAN in the BIOS PXE settings (Dell and some others support this)
The boot file downloads, then a security violation or access denied error Secure Boot rejects an unsigned boot loader Use the distribution’s signed shim plus GRUB, or turn off Secure Boot while provisioning

Once the server has an IP address and you see errors that start with PXE-E, the problem is usually no longer in the BIOS. It sits in the DHCP, TFTP or boot file configuration, and you troubleshoot it on the provisioning server.

Making PXE boot routine in a management system

Enabling network boot in the BIOS is a one-time job when a server is racked; after that, every reinstall only needs “PXE on next boot, then restart”. In Toplink DCIM that step lives in IPMI remote management: the boot device can be set to PXE, an online ISO or the disk, for the next boot only. When a whole batch needs reinstalling, set them all to PXE boot and hand the work to the task queue, with each server’s progress visible in the admin panel. The VNC console goes through the BMC, so you can watch the NIC get an address and load the boot file and see exactly where it stops. When the provisioning network and the production network are on different VLANs, you can change the VLAN of a server’s access port in switch management without logging in to each switch.

FAQ

Why does PXE boot sit at Start PXE over IPv6 for so long?

The firmware tries IPv4 and IPv6 in the configured order, and a protocol your provisioning network does not serve has to time out before the next one starts, which looks like a hang. If you only provision over IPv4, set the PXE protocol to IPv4 or turn off IPv6 PXE Support.

Can a server PXE boot through the BMC management port?

No. PXE is started by the host's own NIC, and a dedicated BMC port belongs to the BMC alone. In shared (NC-SI) mode the onboard NIC the BMC borrows can still PXE boot, but the host and the BMC use two different MAC addresses and IP addresses on that port.

How are PXE, iPXE and UEFI HTTP Boot related?

PXE is the standard procedure in NIC firmware: get an address over DHCP, then download a boot file over TFTP. iPXE is an open-source network boot loader, often loaded by PXE first, that fetches the kernel and image over HTTP and other protocols. UEFI HTTP Boot is defined in the UEFI specification and boots straight from an HTTP URL; the BIOS usually has a separate HTTP Support switch for it.

How do I find out which port sent the PXE request?

Check the log of the DHCP server on the provisioning network, which records the client MAC address, then match that MAC to a port in the BMC's NIC inventory or the BIOS NIC information page. If the log shows no request at all, it never reached the provisioning network: check which port is cabled and which VLAN the switch port is in.

See how it works in your data center.

Start with a product demo and map out your next step.

View pricing
Hotline 400-112-2951

Let’s talk about your IDC

Scan with WeChat to book a product demo or request a trial.

Toplink WeCom contact QR code

Save this code or scan it with WeChat / WeCom

Or call
400-112-2951
Telegram
@TopLink88