SG3428

JetStream 24-Port Gigabit L2 Managed Switch with 4 SFP Slots

  • Full Gigabit Ports: 24× gigabit RJ45 ports and 4× gigabit SFP Slots provide high-speed connections.
  • Integrated into Omada SDN: Centralized Cloud Management and Intelligent Monitoring.
  • Centralised Management: Cloud access and Omada app for ultra convenience and easy management.
  • Static Routing: Helps route internal traffic for more efficient use of network resources.
  • Robust Security Strategies: IP-MAC-Port Binding, ACL, Port Security, DoS Defend, Storm control, DHCP Snooping, 802.1X, Radius Authentication, and more.
  • Optimise Voice and Video Applications: L2/L3/L4 QoS and IGMP snooping.
  • Standalone Management: Web, CLI (Console Port, Telnet, SSH), SNMP, RMON, and Dual Image bring powerful management capabilities

TP-Link | Omada Centralised Management

Convenient Gigabit Switch
for a Complete Omada Network

JetStream 24-Port Gigabit L2 Managed Switch with 4 SFP Slots

SG3428

  •  

    Reliable Gigabit Connections

    24× Gigabit RJ45 Ports and
    4× Gigabit SFP Ports

  •  

    Advanced L2+ Features

    L2/L3/L4 QoS, ACL,
    Static Routing and More

  •  

    Abundant Secure Strategies

    LAN Area Investment Protection

  •  

    Centralised Cloud Management

    SDN Solutions Integration for a Highly Efficient Network

Software Defined Networking (SDN) with Cloud Access

Omada’s Software Defined Networking (SDN) platform integrates network devices, including access points, switches and gateways, providing 100% centralized cloud management. Omada creates a highly scalable network—all controlled from a single interface. Seamless wireless and wired connections are provided, ideal for use in hospitality, education, retail, offices, and more.

JetStream Switches Omada Routers Omada Access Points Wi-Fi 6 Celling
Mount
Wall
Plate
Outdoor Unified Management Interface Controllers Cloud Access Cloud

Secure Networking

Security features include IP-MAC-Port-VID Binding, Port Security, Storm Control, and DHCP Snooping to defend against a range of network threats. An integrated list of common DoS attacks is available, making it easier than ever to prevent them. In addition, the Access Control Lists (ACL, L2 to L4) feature restricts access to sensitive network resources by denying packets based on source and destination MAC address, IP address, TCP/UDP ports, or VLAN ID. Users’ network access can be controlled via 802.1X authentication, which works with a RADIUS/Tacacs+ server to grant access only when valid user credentials are provided.

Advanced QoS

Voice and video traffic can be prioritized based on IP address, MAC address, TCP port number, UDP port number, and more. With QoS (Quality of Service), voice and video services remain smooth, even when bandwidth is in short supply.

Abundant L2 and L2+ Features*

A complete lineup of L2 features is supported including 802.1Q VLAN, Port Mirroring, STP/RSTP/MSTP, Link Aggregation Control Protocol, and 802.3x Flow Control. Advanced IGMP Snooping ensures the switch intelligently forwards multicast streams to only the appropriate subscribers, cutting out unnecessary traffic, while IGMP throttling & filtering restrict each subscriber on a port level to prevent unauthorized multicast access. Static Routing is a simple way of segmenting the network and internally routes traffic through the switch for improved efficiency.

ISP Features

QinQ, L2PT, PPPoE ID Insertion, and IGMP authentication features are provided and developed with service providers in mind. 802.3ah OAM and Device Link Detection Protocol (DLDP) offer straightforward monitoring and troubleshooting of Ethernet links.

IPv6 Support

IPv6 functions such as Dual IPv4/IPv6 Stack, MLD Snooping, IPv6 ACL, DHCPv6 Snooping, IPv6 Interface, Path Maximum Transmission Unit (PMTU) Discovery and IPv6 Neighbor Discover guarantee your network is ready for the Next Generation Network (NGN) without upgrading your hardware.

Enterprise Level Management Features

Easy to manage via an intuitive web-based Graphical User Interface (GUI) or an industry-standard Command Line Interface (CLI). For both management methods, traffic is protected through SSL or SSH encryption. SNMP (v1/v2c/v3) and RMON support enable the switch to be polled for valuable status information and to send traps on abnormal events.

HARDWARE FEATURES
Interface • 24× 10/100/1000 Mbps RJ45 Ports
• 4× Gigabit SFP Slots
• 1× RJ45 Console Port
• 1× Micro-USB Console Port
Fan Quantity Fanless
Physical Security Lock
Power Supply 100-240 V AC~50/60 Hz
Dimensions ( W x D x H ) 17.3 × 7.1 × 1.7 in (440 × 180 × 44 mm)
Mounting Rack Mountable
Max Power Consumption • V1: 19.22 W (110 V/60 Hz)
• V2: 19.9 W (220 V/50 Hz)
Max Heat Dissipation • V1: 65.58 BTU/hr (110 V/60 Hz)
• V2: 67.73 BTU/h (220 V/50 Hz)
PERFORMANCE
Switching Capacity 56 Gbps
Packet Forwarding Rate 41.66 Mpps
MAC Address Table • V1: 8K
• V2 and above: 16K
Packet Buffer Memory 12 Mbit
Jumbo Frame 9 KB
SOFTWARE FEATURES
Quality of Service • 8 priority queues
• 802.1p CoS/DSCP priority
• Queue scheduling
- SP (Strict Priority)
- WRR (Weighted Round Robin)
- SP+WRR
• Bandwidth Control
- Port/Flow based Rating Limiting
• Smoother Performance
• Action for Flows
- Mirror (to supported interface)
- Redirect (to supported interface)
- Rate Limit
- QoS Remark
L3 Features • 16 IPv4/IPv6 Interfaces
• Static Routing
- 48 static routes
• Static ARP
• 512 ARP Entries
• Proxy ARP
• Gratuitous ARP
• DHCP Server
• DHCP Relay
• DHCP L2 Relay
L2 and L2+ Features • Link Aggregation
- Static link aggregation
- 802.3ad LACP
- Up to 8 aggregation groups and up to 8 ports per group
• Spanning Tree Protocol
- 802.1d STP
- 802.1w RSTP
- 802.1s MSTP
- STP Security: TC Protect, BPDU Filter, BPDU Protect, Root Protect, Loop Protect
• Loopback Detection
- Port-based
- VLAN based
• Flow Control
- 802.3x Flow Control
- HOL Blocking Prevention
• Mirroring
- Port Mirroring
- CPU Mirroring
- One-to-One
- Many-to-One
- Tx/Rx/Both
L2 Multicast • Supports 511 (IPv4, IPv6) IGMP groups
• IGMP Snooping
- IGMP v1/v2/v3 Snooping
- Fast Leave
- IGMP Snooping Querier
- IGMP Authentication
• IGMP Authentication
• MVR
• MLD Snooping
- MLD v1/v2 Snooping
- Fast Leave
- MLD Snooping Querier
- Static Group Config
- Limited IP Multicast
• Multicast Filtering: 256 profiles and 16 entries per profile
Advanced Features • Automatic Device Discovery
• Batch Configuration
• Batch Firmware Upgrading
• Intelligent Network Monitoring
• Abnormal Event Warnings
• Unified Configuration
• Reboot Schedule
VLAN • VLAN Group
- Max 4K VLAN Groups
• 802.1q Tagged VLAN
• MAC VLAN: 30 Entries
• Protocol VLAN: Protocol Template 16, Protocol VLAN 16
• GVRP
• VLAN VPN (QinQ)
- Port-Based QinQ
- Selective QinQ
• Voice VLAN
Access Control List • Time-based ACL
• MAC ACL
- Source MAC
- Destination MAC
- VLAN ID
- User Priority
- Ether Type
• IP ACL
- Source IP
- Destination IP
- Fragment
- IP Protocol
- TCP Flag
- TCP/UDP Port
- DSCP/IP TOS
- User Priority
• Combined ACL
• Packet Content ACL
• IPv6 ACL
• Policy
- Mirroring
- Redirect
- Rate Limit
- QoS Remark
• ACL apply to Port/VLAN
Security • IP-MAC-Port Binding
- DHCP Snooping
- ARP Inspection
- IPv4 Source Guard
• IPv6-MAC-Port Binding
- DHCPv6 Snooping
- ND Detection
- IPv6 Source Guard
• DoS Defend
• Static/Dynamic Port Security
- Up to 64 MAC addresses per port
• Broadcast/Multicast/Unicast Storm Control
- kbps/ratio/pps control mode
• IP/Port/MAC based access control
• 802.1X
- Port based authentication
- Mac based authentication
- VLAN Assignment
- MAB
- Guest VLAN
- Support Radius authentication and
accountability
• AAA (including TACACS+)
• Port Isolation
• Secure web management through HTTPS with SSLv3/TLS 1.2
• Secure Command Line Interface (CLI) management with SSHv1/SSHv2
IPv6 • IPv6 Dual IPv4/IPv6
• Multicast Listener Discovery (MLD) Snooping
• IPv6 ACL
• IPv6 Interface
• Static IPv6 Routing
• IPv6 neighbor discovery (ND)
• Path maximum transmission unit (MTU) discovery
• Internet Control Message Protocol (ICMP) version 6
• TCPv6/UDPv6
• IPv6 applications
- DHCPv6 Client
- Ping6
- Tracert6
- Telnet (v6)
- IPv6 SNMP
- IPv6 SSH
- IPv6 SSL
- Http/Https
- IPv6 TFTP
MIBs • MIB II (RFC1213)
• Bridge MIB (RFC1493)
• P/Q-Bridge MIB (RFC2674)
• Radius Accounting Client MIB (RFC2620)
• Radius Authentication Client MIB (RFC2618)
• Remote Ping, Traceroute MIB (RFC2925)
• Support TP-Link private MIBs
• RMON MIB(RFC1757, rmon 1,2,3,9)
MANAGEMENT
Omada App Yes, through
• Omada Cloud-Based Controller (TL-SG3428 v2 and above)
• OC300
• OC200
• Omada Software Controller
Centralized Management • Omada Cloud-Based Controller (TL-SG3428 v2 and above)
• Omada Hardware Controller (OC300)
• Omada Hardware Controller (OC200)
• Omada Software Controller
Cloud Access Yes, through
• Omada Cloud-Based Controller (TL-SG3428 v2 and above)
• OC300
• OC200
• Omada Software Controller
Zero-Touch Provisioning Yes. Requiring the use of Omada Cloud-Based Controller (TL-SG3428 v2 and above).
Management Features • Web-based GUI
• Command Line Interface (CLI) through console port, telnet
• SNMPv1/v2c/v3
- Trap/Inform
- RMON (1, 2, 3, 9 groups)
• SDM Template
• DHCP/BOOTP Client
• 802.1ab LLDP/LLDP-MED
• DHCP AutoInstall
• Dual Image, Dual Configuration
• CPU Monitoring
• Cable Diagnostics
• EEE
• Password Recovery
• SNTP
• System Log
OTHERS
Certification CE, FCC, RoHS
Package Contents • TL-SG3428 Switch
• Power Cord
• Quick Installation Guide
• Rackmount Kit
• Rubber Feet
System Requirements Microsoft® Windows® 98SE, NT, 2000, XP, Vista™ or Windows 7/8/10/11, MAC® OS, NetWare®, UNIX® or Linux.
Environment • Operating Temperature: 0–45 ℃ (32–113 ℉);
• Storage Temperature: -40–70 ℃ (-40–158 ℉)
• Operating Humidity: 10–90% RH non-condensing
• Storage Humidity: 5–90% RH non-condensing

*Some features are only supported by Standalone Management or Centralized Management, or may require further software upgrades.