Preboot Execution Environment
The Preboot eXecution Environment (PXE) specification describes a client-server standardized environment to boot from a network a software assembly on a client. It only requires a PXE capable Network Interface Card (NIC) and a small set of industry standard network protocols like DHCP and TFTP.
Since the beginning of computer networks, there is a persistent need for client systems that are able to boot appropriate software images, using appropriate configuration parameters, both retrieved at boot time from one or more network servers. This goal requires of a client using a set of pre-boot services, based on industry standard network protocols. Additionally, the initially downloaded and run Network Bootstrap Program (NBP) must be built relying on a client (the device to be bootstrapped via PXE) firmware layer providing a hardware independent standardized way to interact with the surrounding network booting environment. In this case the availability and subjection to standards are a key factor required to guarantee the network boot process system interoperability.
One of the first attempts in this regard was the Bootstrap Loading using TFTP standard RFC 906, published in 1984, which established the 1981 published Trivial File Transfer Protocol (TFTP) standard RFC 783 to be used as the standard file transfer protocol for bootstrap loading. It was followed shortly after by the Bootstrap Protocol standard RFC 951 (BOOTP), published in 1985, which allowed a disk-less client machine to discover its own IP address, the address of a TFTP server, and the name of an NBP to be loaded into memory and executed. Difficulties on BOOTP implementation among other reasons eventually led to the development of the Dynamic Host Configuration Protocol standard RFC 2131 (DHCP) published in 1997. This pioneer TFTP/BOOTP/DHCP approach felt short because at the time it was not defined the required standardized client side of the provisioning environment.
The Preboot Execution Environment (PXE) was introduced as part of the Wired for Management  framework by Intel and is described in the specification published by Intel and SystemSoft. PXE version 2.0 was released in December 1998, and the update 2.1 was made public in September 1999. The PXE environment makes use of several standard client-server protocols like DHCP and TFTP (now defined by the 1992 published RFC 1350). Within the PXE schema the client side of the provisioning equation is now an integral part of the PXE standard and it is implemented either as a Network Interface Card (NIC) BIOS extension or today in modern devices as UEFI code. This distinctive firmware layer makes available at the client the functions of a basic Universal Network Driver Interface (UNDI), a minimalistic UDP/IP stack, a Preboot (DHCP) client module and a TFTP client module, conforming all together the PXE application programming interfaces (APIs) used by the NBP when needing to interact with the services offered by the server counterpart of the PXE environment.
The PXE environment relies on a combination of industry-standard Internet protocols, namely UDP/IP, DHCP, and TFTP. These protocols have been selected because they are easily implemented at the client's NIC firmware which leads to small footprint standard PXE ROMs. Small size PXE ROMs are a design goal because they allow getting the client side of the PXE standard identically implemented from highly resourced client computers to very low resourced Single-board computers (SBC) and System on a Chip (SoC) computers.
DHCP is used to provide the appropriate client network parameters and specifically the location (IP address) of the TFTP server hosting, ready for download, the initial bootstrap program (NBP) and complementary files. To initiate a PXE bootstrap session the DHCP component of the client's PXE firmware broadcasts a DHCPDISCOVER packet containing PXE-specific options to port 67/UDP (DHCP server port); it asks for the required network configuration and network booting parameters. The PXE-specific options identify the initiated DHCP transaction as a PXE transaction. Standard DHCP servers (non PXE enabled) will be able to answer with a regular DHCPOFFER carrying networking information (i.e. IP address) but not the PXE specific parameters. A PXE client will not be able to boot if only receives an answer from a non PXE enabled DHCP server.
After parsing a PXE enabled DHCP server DHCPOFFER, the client will be able to set its own network IP address, IP Mask, etc, and to point to the network located booting resources, based on the received TFTP Server IP address and the name of the NBP. The Client next transfers the NBP into its own random-access memory (RAM) using TFTP, possibly verifies it (i.e. UEFI Secure Boot), and finally boots from it. NBPs are just the first link in the boot chain process and they generally request via TFTP a small set of complementary files in order to get running a minimalistic OS executive (i.e. WindowsPE, or a basic Linux kernel+initrd). When the small OS executive is alive it loads its own fully capable network drivers, a full TCP/IP stack, and the rest of transfers for booting or installing a full OS are performed not by TFTP but at this point using more robust transfer protocols like HTTP, CIFS, NFS, etc.
The PXE Client/Server environment was designed so it can be seamlessly integrated with an already in place DHCP and TFTP server infrastructure. This design goal presented a challenge when dealing with the classic DHCP protocol. Corporate DHCP servers are usually subject to strict policies that conspire against easily adding the additional parameters and rules required to support a PXE environment. For this reason the PXE standard developed the concept of DHCP redirection or "proxyDHCP". The idea behind a proxyDHCP is to split the PXE DHCP requirements in two independently run and administered server units:
- The classic DHCP server providing IP address, IP mask, etc. to all booting DHCP clients.
- The proxyDHCP server providing TFTP server IP address and name of the NBP only to PXE identified booting clients.
In a DHCP plus proxyDHCP server environment :18 the PXE client initially broadcasts a single PXE DHCPDISCOVER packet and receives two complementary DHCPOFFERs; one from the regular non PXE enabled DHCP server and a second one from the proxyDHCP server. Both answers together provide the required information to allow the PXE client to continue with its booting process. This non-intrusive approach allows setting a PXE environment without touching the configuration of an already working DHCP server. The proxyDHCP service may also run on the same host as the standard DHCP service but even in this case they are both two independently run and administered applications. Since two services cannot use the same port 67/UDP on the same host, the proxyDHCP runs on port 4011/UDP. The proxyDHCP approach has proved to be extremely useful in a wide range of PXE scenarios going from corporate to home environments.
PXE was conceived considering several system architectures. The version 2.1 of the specification defined architecture identifiers for six system types, including IA-64 and DEC Alpha. However, PXE v2.1 only completely covered IA-32. Despite this apparent lack of completeness Intel has recently decided to widely support PXE within the new UEFI specification extending the PXE functionality to all EFI/UEFI environments. Current Unified Extensible Firmware Interface Specification 2.4A, Section 21 Network Protocols — SNP, PXE, and BIS defines the protocols that provide access to network devices while executing in the UEFI boot services environment. These protocols include the Simple Network Protocol (SNP), the PXE Base Code Protocol (PXE), and the Boot Integrity services Protocol (BIS). Today in a PXE environment the client architecture detection is rarely based on the identifiers originally included with the PXE v2.1 specification, instead each computer that will be booting from the network should have set DHCP option 93 to indicate the client’s architecture. This enables a PXE server to know (at boot time) the exact architecture of the client from the first network boot packet. The client system architecture values are listed (among other PXE parameters) within the 2006 published RFC 4578 (Dynamic Host Configuration Protocol (DHCP) Options for the Intel Preboot eXecution Environment (PXE)).
With the advent of IPv6 DHCP has evolved into DHCPv6; the need for options supporting PXE within the new DHCP protocol has been addressed by the 2010 published RFC 5790 (DHCPv6 Options for Network Boot).
The original PXE client firmware extension was designed as an Option ROM for the IA-32 BIOS, so a personal computer (PC) was originally made PXE-capable by installing a network interface controller (NIC) that provided a PXE Option ROM. Today the client PXE code is directly included within the NIC's own firmware and also as part of the UEFI firmware on UEFI hardware.
Even when the original client PXE firmware has been written by Intel and always provided at no cost as a linkable IA32 object code format module included in their Product Development Kit (PDK), the open source world has produced over the years non-standard derivative projects like gPXE/iPXE offering their own ROMs. While Intel based ROMs have always been rock solid implementing the client side of the PXE standard some people were willing to trade extra features for stability and PXE standard conformance.
PXE acceptance since v2.1 has been ubiquitous; today it is virtually impossible to find a Network Card without PXE firmware on it. The availability of inexpensive Gigabit Ethernet hardware (NICs, switches, routers, etc.) has made of PXE the fastest method available for installing an operating system on a client when competing against the classic CD, DVD, and USB flash drive alternatives.
Over the years several major projects have included PXE support, including:
- All the major Linux distributions.
- Microsoft Remote Installation Services (RIS)
- Microsoft Windows Deployment Services (WDS)
- Microsoft Deployment Toolkit (MDT)
- Microsoft System Center Configuration Manager (SCCM)
In regard to NBP development there are several projects implementing Boot Managers able to offer boot menu extended features, scripting capabilities, etc.:
All the above mentioned projects, when they are able to boot/install more than one OS, work under a "Boot Manager - Boot Loader" paradigm. The initial NBP is a Boot Manager able to retrieve its own configuration and deploy a menu of booting options. The user selects a booting option and an OS dependent Boot Loader is downloaded and run in order to continue with the selected specific booting procedure.
The Apple world has come up with a very similar network boot approach under the umbrella of the Boot Server Discovery Protocol (BSDP) specification. BSDP v0.1 was initially published by Apple in August 1999 and its last v1.0.8 was published in September 2010. The OS X Server includes a system tool called NetBoot. A NetBoot client uses BSDP to dynamically acquire resources that enable it to boot a suitable operating system. BSDP is crafted on top of DHCP using vendor-specific information to provide the additional NetBoot functionality not present in standard DHCP. The protocol is implemented in client firmware. At boot time, the client obtains an IP address via DHCP then discovers boot servers using BSDP. Each BSDP server responds with boot information consisting of:
- A list of bootable operating system images
- The default operating system image
- The client’s currently selected operating system image (if defined)
The client chooses an operating system from the list and sends a message to the server indicating its selection. The selected boot server responds supplying the boot file and boot image, and any other information needed to download and execute the selected operating system.
Microsoft created a non-overlapping extension of the PXE environment with their Boot Information Negotiation Layer (BINL). BINL is implemented as a server service and it is a key component of their Remote Installation Services (RIS) and Windows Deployment Services (WDS) strategies. It includes certain preparation processes and a network protocol that could be somehow considered a Microsoft crafted DHCP extension. BINL is a Microsoft proprietary technology that uses PXE standard client firmware. Currently there is not a publicly available BINL specification.
IETF standards documentation
|RFC #||Title||Date||Author||Obsolete and Update Information|
|RFC 783||The TFTP Protocol (Revision 2)||Jun-81||K. Sollins||Obsoleted by - RFC 1350|
|RFC 906||Bootstrap Loading using TFTP||Jun-84||Ross Finlayson||-|
|RFC 951||Bootstrap Protocol||Sep-85||Bill Croft||Updated by RFC 1395, RFC 1497, RFC 1532, RFC 1542, RFC 5494|
|RFC 1350||The TFTP Protocol (Revision 2)||Jul-92||K. Sollins||Updated by RFC 1782, RFC 1783, RFC 1784, RFC 1785, RFC 2347, RFC 2348, RFC 2349|
|RFC 2131||Dynamic Host Configuration Protocol||Mar-97||R. Droms||Updated by RFC 3396, RFC 4361, RFC 5494, RFC 6842|
|RFC 4578||DHCP Options for the Intel PXE||Nov-06||M. Johnston||-|
|RFC 5970||DHCPv6 Options for Network Boot||Sep-10||T. Huth||-|
- Diskless nodes – diskless computers
- NetBoot – Apple network boot tool
- Boot Service Discovery Protocol – Apple network boot protocol
- Remote Initial Program Load (RIPL or RPL)
- System Deployment Image (SDI) – primarily with Microsoft products
- Unified Extensible Firmware Interface – UEFI network booting
- Wake-on-LAN (WOL)
- Windows Deployment Services – PXE-based deployment for Microsoft Windows
- "Wired for Management Baseline - Version 2.0 Release" (PDF). Intel Corporation. 1998-12-18. Retrieved 2014-02-08.
- "Preboot Execution Environment (PXE) Specification - Version 2.1" (PDF). Intel Corporation. 1999-09-20. Retrieved 2014-02-08.
- "Unified Extensible Firmware Interface Specification" (PDF). UEFI. 2013-12-02. Retrieved 2014-04-04.
- "UEFI PXE Boot Performance Analysis" (PDF). Intel Corporation. 2014-02-02. Retrieved 2014-04-04.
- "NetBoot 2.0: Boot Server Discovery Protocol (BSDP)" (Doc). Apple Corporation. 2003-12-02. Retrieved 2014-04-04.
- PXE specification – The Preboot Execution Environment specification v2.1 published by Intel & SystemSoft
- BIS specification – The Boot Integrity Services specification v1.0 published by Intel
- Intel Preboot Execution Environment – Internet-Draft 00 of the PXE Client/Server Protocol included in the PXE specification
- PXE error codes – A catalogue of PXE error codes