TL-SG3428X-UPS

JetStream 24-Port Gigabit L2+ Managed Switch with 4 10GE SFP+ Slots and UPS Power Supply

  • 10G Lightning-Fast Uplink: 4× 10 Gbps SFP+ slots enable high-bandwidth connectivity and non-blocking switching capacity. 
  • Gigabit Speeds: 24× gigabit RJ45 ports offer high-speed and reliable connections to other switches and devices.
  • Static Routing: Helps route internal traffic for more efficient use of network resources.
  • Robust Security Strategies: IP-MAC-Port Binding, ACL, Port Security, DoS Defend, Storm control, DHCP Snooping, 802.1X, Radius Authentication, and more.
  • Optimise Voice and Video Applications: L2/L3/L4 QoS and IGMP snooping.
  • Standalone Management: Web, CLI (Console Port, Telnet, SSH), SNMP, RMON, and Dual Image bring powerful management capabilities

 

Overview

TP-Link's JetStream TL-SG3428X-UPS provides high-performance and powerful L2 and L2+ features like static routing, enterprise-level QoS, advanced security strategies and a bundle of ISP features. The IP-MAC-Port Binding (IMPB) and Access Control List (ACL) functions protect against broadcast storm, ARP and Denial-of-Service (DoS) attacks, etc. Quality of Service (QoS, L2 to L4) provides enhanced traffic management capabilities to move your data smoother and faster. The OAM and DDM functions help facilitate network management. Moreover, the easy-to-use web management interfaces, along with CLI, SNMP and Dual Image mean faster setup and configuration with less downtime. TP-Link JetStream L2+ managed Switches TL-SG3428X-UPS provides a reliable, secure solution for ISP networks.

Secure Networking

The TL-SG3428X-UPS provides IP-MAC-Port Binding, Port Security, Storm control and DHCP Snooping which protect against broadcast storms, ARP attacks, etc. It can also protect against DoS attacks more easily than ever before. In addition, the Access Control Lists (ACL, L2 to L4) feature restricts access to sensitive network resources by denying packets based on source and destination MAC address, IP address, TCP/UDP ports and even VLAN ID. Moreover, the switch supports 802.1X authentication, which is used in conjunction with a RADIUS/Tacacs+ server to require authentication information before access to the network is allowed.

 

Advanced QoS features

Integrating voice, data and video service into one traffic line can ensure that voice and video are always clear, smooth and jitter-free with the help of a variety of means including IP or MAC address, TCP or UDP port number, etc. In conjunction with the Voice VLAN, the voice applications is able to have smoother performance.

 

 

Abundant L2 and L2+ features

TL-SG3428X-UPS supports a complete lineup of L2 features, including 802.1Q VLAN, Port Mirroring, STP/RSTP/MSTP, Link Aggregation Control Protocol and 802.3x Flow Control function. Besides, the switch provides advanced features for network maintenance, such as Loopback Detection, Cable Diagnostics and IGMP Snooping. IGMP snooping ensures the switch intelligently forward the multicast stream only to the appropriate subscribers while IGMP throttling & filtering restrain each subscriber on a port level to prevent unauthorized multicast access. Moreover, TL-SG3428X-UPS supports L2+ feature-static routing, which is a simple way to provide segmentation of the network with internal routing through the switch and helps network traffic for more efficient use.

 

ISP Features

TL-SG3428X-UPS supports a bundle of ISP features such as 802.3ah OAM, DDM, sFlow, QinQ, L2PT PPPoE ID Insertion, IGMP authentication etc. 802.3ah OAM and Device Link Detection Protocol (DLDP) functions can improve monitor and troubleshoot Ethernet networks, helping facilitate network management. DDM(Digital Diagnostic Monitoring) function helps view the status of SFP modules and configure alarm settings, warning settings, temperature threshold settings, voltage threshold settings, bias current threshold settings, TX power threshold settings, and RX power threshold settings.

IPv6 Support

TL-SG3428X-UPS supports various IPv6 functions such as Dual IPv4/IPv6 Stack, MLD Snooping, IPv6 ACL, DHCPv6 Snooping, IPv6 Interface, Path Maximum Transmission Unit (PMTU) Discovery and IPv6 Neighbor Discovery, which guarantees your network is ready for the Next Generation Network (NGN) without upgrading your network equipment.

Enterprise Level Management Features

TL-SG3428X-UPS is easy to use and manage. It supports various user-friendly standard management features, such as intuitive web-based Graphical User Interface (GUI) or industry-standard Command Line Interface (CLI), either administration traffic can be protected through SSL or SSH encryptions. SNMP and RMON support enables the switch to be polled for valuable status information and to send traps on abnormal events.

HARDWARE FEATURES
Interface • 24× 10/100/1000 Mbps RJ45 Ports
• 4× 10G SFP+ Slots
• 1× RJ45 Console Port
• 1× Micro-USB Console Port
Fan Quantity Fanless
Power Supply 100-240 V AC~50/60 Hz and 12 V lead-acid battery
Dimensions ( W x D x H ) 17.3 × 7.1 × 1.7 in (440 × 180 × 44 mm)
Mounting Rack Mountable
Max Power Consumption 31.9 W (110 V/60 Hz) (AC powered with 12 V battery charging)
24.0 W (110 V/60 Hz) (AC powered without 12 V battery charging)
20.0 W (12 V battery powered)
Max Heat Dissipation 108.84 BTU/hr (110 V/60 Hz) (AC powered with 12 V battery charging)
81.88 BTU/hr (110 V/60 Hz) (AC powered without 12 V battery charging)
68.24 BTU/hr (12 V battery powered)
PERFORMANCE
Switching Capacity 128 Gbps
Packet Forwarding Rate 95.23 Mpps
MAC Address Table 16 K
Packet Buffer Memory 12 Mbit
Jumbo Frame 9 KB
SOFTWARE FEATURES
Quality of Service • 8 priority queues
• 802.1p CoS/DSCP priority
• Queue scheduling
- SP (Strict Priority)
- WRR (Weighted Round Robin)
- SP+WRR
• Bandwidth Control
- Port/Flow based Rating Limiting
• Smoother Performance
• Action for Flows
- Mirror (to supported interface)
- Redirect (to supported interface)
- Rate Limit
- QoS Remark
L3 Features • 16 IPv4/IPv6 Interfaces
• Static Routing
- 48 static routes
• Static ARP
- 128 Static Entries
• Proxy ARP
• Gratuitous ARP
• DHCP Server
• DHCP Relay
- DHCP Interface Relay
- DHCP VLAN Relay
• DHCP L2 Relay
L2 and L2+ Features • Link Aggregation
- static link aggregation
- 802.3ad LACP
- Up to 8 aggregation groups, containing 8 ports per group
• Spanning Tree Protocol
- 802.1d STP
- 802.1w RSTP
- 802.1s MSTP
- STP Security: TC Protect, BPDU Filter, Root Protect
• Loopback Detection
- Port based
- VLAN based
• Flow Control
- 802.3x Flow Control
- HOL Blocking Prevention
• Mirroring
- Port Mirroring
- CPU Mirroring
- One-to-One
- Many-to-One
- Tx/Rx/Both
L2 Multicast • IGMP Snooping
- IGMP v1/v2/v3 Snooping
- Fast Leave
- IGMP Snooping Querier
- IGMP Authentication
• IGMP Authentication
• MLD Snooping
- MLD v1/v2 Snooping
- Fast Leave
- MLD Snooping Querier
- Static Group Config
- Limited IP Multicast
• MVR
• Multicast Filtering: 256 profiles and 16 entries per profile
Advanced Features • Automatic Device Discovery
• Batch Configuration
• Batch Firmware Upgrading
• Intelligent Network Monitoring
• Abnormal Event Warnings
• Unified Configuration
• Reboot Schedule
VLAN • VLAN Group
- Max 4K VLAN Groups
• 802.1Q Tagged VLAN
• MAC VLAN: 30 Entries
• Protocol VLAN: Protocol Template 16, Protocol VLAN 16
• Private VLAN
• GVRP
• VLAN VPN (QinQ)
- Port-Based QinQ
- Selective QinQ
• Voice VLAN
Access Control List • Time-based ACL
• MAC ACL
- Source MAC
- Destination MAC
- VLAN ID
- User Priority
- Ether Type
• IP ACL
-Source IP
- Destination IP
- Fragment
- IP Protocol
- TCP Flag
- TCP/UDP Port
- DSCP/IP TOS
- User Priority
• Combined ACL
• Packet Content ACL
• IPv6 ACL
• Policy
- Mirroring
- Redirect
- Rate Limit
- QoS Remark
• ACL apply to Port/VLAN
Security • IP-MAC-Port Binding
- 512 Entries
- DHCP Snooping
- ARP Inspection
- IPv4 Source Guard: 100 Entries
• IPv6-MAC-Port Binding
- 512 Entries
- DHCPv6 Snooping
- ND Detection
- IPv6 Source Guard: 100 Entries
• DoS Defend
• Static/Dynamic Port Security
- Up to 64 MAC addresses per port
• Broadcast/Multicast/Unicast Storm Control
- kbps/ratio control mode
• 802.1X
- Port base authentication
- Mac base authentication
- VLAN Assignment
- MAB
- Guest VLAN
- Support Radius authentication andaccountability
• AAA (including TACACS+)
• Port Isolation
• Secure web management through HTTPS with SSLv3/TLS 1.2
• Secure Command Line Interface (CLI) management with SSHv1/SSHv2
• IP/Port/MAC based access control
IPv6 • IPv6 Dual IPv4/IPv6
• Multicast Listener Discovery (MLD) Snooping
• IPv6 ACL
• IPv6 Interface
• Static IPv6 Routing
• IPv6 neighbor discovery (ND)
• Path maximum transmission unit (MTU) discovery
• Internet Control Message Protocol (ICMP) version 6
• TCPv6/UDPv6
• IPv6 applications
- DHCPv6 Client
- Ping6
- Tracert6
- Telnet (v6)
- IPv6 SNMP
- IPv6 SSH
- IPv6 SSL
- Http/Https
- IPv6 TFTP
MIBs • MIB II (RFC1213)
• Interface MIB (RFC2233)
• Ethernet Interface MIB (RFC1643)
• Bridge MIB (RFC1493)
• P/Q-Bridge MIB (RFC2674)
• RMON MIB (RFC2819)
• RMON2 MIB (RFC2021)
• Radius Accounting Client MIB (RFC2620)
• Radius Authentication Client MIB (RFC2618)
• Remote Ping, Traceroute MIB (RFC2925)
• Support TP-Link private MIB
MANAGEMENT
Management Features • Web-based GUI
• Command Line Interface (CLI) through the console port, telnet
• SNMP v1/v2c/v3
- Trap/Inform
- RMON (1,2,3,9 groups)
• SDM Template
• DHCP/BOOTP Client
• 802.1ab LLDP/LLDP-MED
• DHCP AutoInstall
• Dual Image, Dual Configuration
• CPU Monitoring
• Cable Diagnostics
• EEE
• Password Recovery
• SNTP
• System Log
OTHERS
Certification CE, FCC, RoHS
Package Contents • TL-SG3428X-UPS Switch
• Power Cord
• Quick Installation Guide
• Rackmount Kit
• Rubber Feet
System Requirements Microsoft® Windows® 98SE, NT, 2000, XP, Vista™ or Windows 7/8/10/11, MAC® OS, NetWare®, UNIX® or Linux.
Environment • Operating Temperature: 0–45 ℃ (32–113 ℉);
• Storage Temperature: -40–70 ℃ (-40–158 ℉)
• Operating Humidity: 10–90% RH non-condensing
• Storage Humidity: 5–90% RH non-condensing

From United States?

Get products, events and services for your region.