ASUS NUC BIOS Thunderbolt options and the iSetupCfg CLI

ASUS NUC BIOS Thunderbolt options and the iSetupCfg CLI

What is and is not known about the firmware and BIOS of an ASUS NUC 15 Pro for Thunderbolt eGPU use on Linux — the options that could govern the tunnel and the evidence for each, the undocumented-options route through the iSetupCfg setup CLI, the NPSS suite, BIOS updates and recovery risk, and a read-before-write change procedure.


name: asus-nuc15-pro-firmware-for-thunderbolt-egpu-linux title: ASUS NUC 15 Pro (NUC15CRK, Arrow Lake) firmware/BIOS for a Thunderbolt eGPU on Linux description: >- TRIGGER: choosing, reading or changing BIOS/firmware options on an ASUS NUC 15 Pro (NUC15CRK*, Core Ultra 5 225H) that affect Thunderbolt PCIe tunnelling for an eGPU on Linux; using iSetupCfg / NUC Firmware Integrator Tool, NPSS, BIOS updates, recovery, fwupd coverage. SKIP: kernel-side tunnel/bolt/IOMMU, BAR allocation, PCIe PM, fallen-off-bus (see sibling hub references); NVIDIA driver tuning; non-ASUS hosts. Verified as of 2026-09-25.

ASUS NUC 15 Pro firmware for a Thunderbolt eGPU on Linux

Verified-as-of 2026-09-25. Tags: [SOURCED url] published source, [INFERRED] reasoning from sources, [BOX] measured on the reference machine (“the box” below), [UNVERIFIED] could not be confirmed. A BOX tag that names a vendor document (for example “BOX from ASUS TPS”) is a document claim, not a measurement.

Bottom line: the ASUS pages this research reached document almost nothing about Thunderbolt/eGPU in BIOS for this family. The working setup is kernel-command-line driven [BOX]. BIOS options that could matter exist only as generic Thunderbolt and AMI-firmware (AptioV) concepts; treat every menu name below as [UNVERIFIED] on NUC15CRK until you read it from the machine’s own setup dump.

Core Concepts

  1. Firmware connection manager decides tunnel policy. On Intel Thunderbolt (TB)/USB4 hosts the BIOS/firmware sets the security level; Linux only authorises within it. Levels: none, user, secure, dponly, usbonly, nopcie; read at /sys/bus/thunderbolt/devices/domainX/security. If the level is user/secure, PCIe tunnels are created only after the device is authorised. [SOURCED https://www.kernel.org/doc/html/latest/admin-guide/thunderbolt.html]
  2. Security level changed tunnel behaviour on an older Intel NUC; it is not shown on the NUC 15. A Linux kernel bug report on an older Intel NUC (Thunderbolt 3 host) states BIOS level “Unique ID” triggered tunnel attempts while “No Security” prevented any attempt; that host’s PCIe tunnel then failed with a firmware error. It is a different platform, so it shows the lever, not the NUC15 behaviour. [SOURCED https://ratatoskr.run/linux-usb/2026/08/17378667/t]
  3. Kernel DMA protection is checked from Linux, not only BIOS. /sys/bus/thunderbolt/devices/domainX/iommu_dma_protection reads 1 when enabled; the kernel doc ties it to native IOMMU on 2018+ systems. That VT-d must also be on in BIOS is this file’s inference, not the doc’s statement [INFERRED]. [SOURCED kernel doc above]
  4. Secondhand OEM statement: ASUS firmware owns the eGPU-relevant BIOS behaviour. An Intel Community reply on a NUC15CRK eGPU thread (ASMedia ASM2464PDX bridge, RTX 5060 Ti) said Above-4G Decoding, Resizable BAR (ReBAR), security level and cold-boot/sleep/hot-plug behaviour are determined by ASUS firmware and that Intel does not validate them on OEM systems. The page returned HTTP 403 to the research fetch; the content came via a search-result summary, so treat it as secondhand. [SOURCED https://community.intel.com/t5/Mobile-and-Desktop-Processors/NUC15CRK-eGPU-via-TB4-PCIe-tunneling-ASM2464PDX-RTX-5060-Ti/m-p/1756462]
  5. Bandwidth ceiling. The ASUS technical product specification (TPS) lists PCIe tunnelling at 32 Gbps (PCIe 3.0 x4 class) [BOX from ASUS TPS; not re-fetched]. No BIOS option is known to raise this (inferred, untested) [INFERRED].
  6. The box’s BIOS. Product NUC15CRKU5, BIOS CRARL579.0032.2026.0704.0118, rev 5.32, embedded controller (EC) 2.12; fwupd shows only the Internal SPI Controller, no Thunderbolt controller-firmware (NVM) entry [BOX]. ASUS lists BIOS 0032 dated 2026/07/28 on its support page while the box’s build string carries 0704 (read here as 4 July; field order assumed [INFERRED]); do not equate the two dates [SOURCED https://www.asus.com/us/supportonly/nuc15crku5/helpdesk_bios/]. This file flags the gap without resolving it: whether the box runs the exact image ASUS lists as 0032 is [UNVERIFIED].

Options That May Govern the Tunnel

Only items named in the ASUS manuals are confirmed to exist: fan mode, after-power-failure, modern standby, ErP Ready (enter setup with F2 or Del) [BOX from ASUS manuals]. Everything else is a candidate class, not a verified menu.

Concept What it does Evidence on NUC15CRK Status
Thunderbolt security level Gates PCIe tunnel creation (none/user/secure/dponly/usbonly/nopcie) Kernel doc defines levels and says BIOS typically labels them Legacy/Unique ID/One-time key/DP only; older-NUC report shows effect Menu name [UNVERIFIED]; concept [SOURCED kernel doc]
PCIe tunnelling / “nopcie”-style toggle Disables PCIe over TB Kernel doc: nopcie is BIOS-level, USB4 systems [UNVERIFIED] on this NUC
Pre-boot Thunderbolt / PCIe-behind-TB enumeration Firmware enumerates eGPU before OS No ASUS doc found; a Linux-side hotplug works per [BOX] (the fallen-off-bus sibling reference says thunderbolt.host_reset=0 helps only boot-attached enclosures; the two are unreconciled) [UNVERIFIED]
VT-d / Kernel DMA Protection IOMMU for TB DMA safety Read state via iommu_dma_protection Option name [UNVERIFIED]; observable [SOURCED]
Above-4G Decoding / Resizable BAR (ReBAR) Large 64-bit windows for GPU BARs Intel Community reply names them as relevant to NUC15CRK, secondhand [UNVERIFIED]; kernel-side BAR handling is in the sibling BAR reference
PCIe ASPM / native hotplug “OS control” Who owns link PM and hotplug Not documented by ASUS [UNVERIFIED]; kernel params cover it [BOX]
Modern standby (S0ix) vs S3 eGPU sleep/wake behaviour ASUS manual documents a modern-standby option [BOX]; no S3 option known Effect on eGPU [INFERRED] only

Undocumented Options and the Setup CLI

/o reads or exports and /i writes; a wrong write can leave the machine hard to boot or configure [INFERRED]. Read the Safe-change procedure and Anti-patterns before any write.

NPSS on Linux

BIOS Updates and Recovery

Settings vs Symptoms

Symptom BIOS-side suspect Evidence First non-BIOS check
eGPU never authorised / no PCIe tunnel Security level too strict (user/secure/dponly/nopcie) Kernel doc; older-NUC report security and authorized sysfs, bolt
Tunnel creation fails with firmware error Possibly a host/device generation mismatch [UNVERIFIED]; not shown to be a BIOS option Older-NUC report, no fix kernel log for tunnel errors
BAR assignment failures, GPU not initialising Above-4G Decoding / ReBAR options Secondhand OEM statement only [UNVERIFIED] kernel PCI BAR params (sibling ref)
Works only after reboot with eGPU attached Pre-boot TB enumeration No source hotplug and pci params
Fails after sleep/wake Modern standby vs S3 ASUS documents modern standby option [BOX] PCIe PM/D3cold (sibling ref)
Link ~32 Gbps only None known; hardware spec ASUS TPS [BOX] link speed in sysfs
Regression after BIOS update BIOS revision No release-note mention; opaque “Platform issue fix” roll forward/back only with vendor support

Safe-change procedure

  1. Record baseline: dmidecode BIOS version/date, kernel cmdline, TB security and iommu_dma_protection, and a full iSetupCfg export (read-only) saved off-box. Confirm the export exists and is not empty; if it failed, stop, since step 4’s diff needs a baseline.
  2. Read before write: find the target setting and its map string in your own export; read its value with /o /ms:. Note it as the revert value.
  3. Change exactly one setting per boot. Keep the eGPU attached only if that is the test; this is for setting changes, never for a flash.
  4. Reboot, re-export, diff; confirm only the intended line changed.
  5. Test the symptom with the same repro; log the result and revert to the step-2 value if not clearly better.
  6. Keep working kernel-cmdline setup unchanged while testing BIOS changes so effects are separable.
  7. Do not set or change a supervisor password as part of this. iSetupCfg writes need a supervisor password or Bypass (see Password behaviour); with neither, change the one setting by hand in setup (F2 or Del), noting its current value from the screen first [INFERRED]. Enabling Bypass counts as its own single-setting change.
  8. If the machine will not boot after any change, stop. For a bad setting, the power button menu’s F5 “Restore BIOS Settings” returns setup to build-time defaults (not your earlier values; the step-1 export records those) [BOX from ASUS TPS 4.3.2, read from the box’s local copy]. For a failed flash, use the recovery route under BIOS Updates and Recovery.

Anti-patterns

Cross-references

Sibling hub references (not duplicated here), all under references/:

Related references added later: egpu-unattended-remote-recovery-and-out-of-band-linux.md (host-first escalation ladder, remote power control and out-of-band access); egpu-reproducible-bringup-and-drift-detection-linux.md (capturing this wiring as a restorable manifest, drift verifier and restore order).

Sources

  1. ASUS, NUC15CRKU5 BIOS support page: https://www.asus.com/us/supportonly/nuc15crku5/helpdesk_bios/
  2. ASUS, BIOS Update and Recovery Instructions for NUC: https://www.asus.com/support/faq/1052506/
  3. ASUS, AptioV Integrator Tools for NUC: https://www.asus.com/us/support/faq/1052633/
  4. ASUS, How to download the NUC Firmware Integrator Tool: https://www.asus.com/support/faq/1052866/
  5. ASUS, Exporting NUC BIOS settings in Windows: https://www.asus.com/us/support/faq/1052729/
  6. ASUS, What is NUC Pro Software Suite: https://www.asus.com/us/support/faq/1052851/
  7. ASUS, NUC15CRH downloads page (not the box’s NUC15CRKU5): https://www.asus.com/us/supportonly/nuc15crh/helpdesk_download/
  8. Linux kernel, USB4 and Thunderbolt admin guide: https://www.kernel.org/doc/html/latest/admin-guide/thunderbolt.html
  9. iSetupCfg PowerShell write-up (practitioner): https://www.systanddeploy.com/2025/03/managing-bios-settings-on-asus-nuc.html
  10. Linux USB list, PCIe tunnel creation failure report: https://ratatoskr.run/linux-usb/2026/08/17378667/t
  11. Intel Community, NUC15CRK eGPU thread (secondhand, 403 on fetch): https://community.intel.com/t5/Mobile-and-Desktop-Processors/NUC15CRK-eGPU-via-TB4-PCIe-tunneling-ASM2464PDX-RTX-5060-Ti/m-p/1756462
  12. ASUS ZenTalk, Thunderbolt firmware FAQ (title only, 403): https://zentalk.asus.com/t5/faq/nuc-firmware-updates-available-for-thunderbolt-on-nuc-products/ta-p/409754
  13. Phoronix, ASUS LVFS first motherboard: https://www.phoronix.com/news/ASUS-LVFS-First-Motherboard