JetStream 24-Port Gigabit L2+ Managed Switch with 4 SFP Slots (TL-SG3428)
The JetStream 24-Port Gigabit L2+ Managed Switch with 4 SFP Slots delivers full gigabit performance, advanced L2+/L3 features, and seamless integration with Omada SDN for powerful, centralized network management.
Key Features
- Full Gigabit Connectivity
- 24× 10/100/1000 Mbps RJ45 ports
-
4× gigabit SFP slots for high-speed uplinks
-
Omada SDN Integration
- Zero-Touch Provisioning (ZTP)
- Centralized cloud management
-
Intelligent network monitoring
-
Centralized Management
- Cloud access for remote administration
-
Omada app support for convenient management
-
Static Routing (L3)
-
Routes internal traffic for more efficient use of network resources
-
Robust Security Strategies
- IP-MAC-Port Binding, ACL, Port Security
- DoS Defend, Storm Control, DHCP Snooping
-
802.1X and RADIUS authentication
-
Optimized for Voice & Video
- L2/L3/L4 QoS
-
IGMP snooping to optimize multicast traffic
-
Standalone Management Options
- Web-based GUI
- CLI via console port, Telnet, SSH
- SNMP, RMON
-
Dual Image for enhanced reliability
-
Fanless Design
- Silent operation with fanless hardware
Omada SDN with Cloud Access
Omada’s Software Defined Networking (SDN) platform integrates access points, switches, and routers into a single, centrally managed solution. With Omada SDN, you get:
- 100% centralized cloud management
- A highly scalable network architecture
- Unified control from a single interface
This provides seamless wireless and wired connectivity, suitable for environments such as hospitality, education, retail, offices, and more.
Advanced L3 and L2+ Features
The switch supports a wide range of L2+ and L3 capabilities to build scalable, robust networks for enterprises, campuses, and ISPs, including:
- Static IPv4/IPv6 routing
- Multiple IPv4/IPv6 interfaces
- Static ARP and Proxy ARP
- DHCP server, relay, and L2 relay
Secure Networking
Comprehensive security features help protect your infrastructure:
- Binding & Guard Features
- IP-MAC-Port-VID Binding
- IPv6-MAC-Port Binding
- DHCP Snooping / DHCPv6 Snooping
- ARP Inspection / ND Detection
-
IPv4 and IPv6 Source Guard
-
Threat Defense
- DoS Defend with integrated common attack profiles
-
Broadcast/Multicast/Unicast Storm Control (kbps/ratio/pps)
-
Access Control
- L2–L4 ACLs (MAC, IP, TCP/UDP ports, VLAN ID, user priority, DSCP/IP TOS, fragment, protocol, packet content, IPv6 ACL)
- Time-based ACL and combined ACL
- ACL actions: mirror, redirect, rate limit, QoS remark
-
ACL application at port/VLAN level
-
Port & User Security
- Static/Dynamic Port Security (up to 64 MAC addresses per port)
-
Port Isolation
-
Authentication & AAA
- 802.1X (port-based and MAC-based)
- VLAN assignment, MAB, Guest VLAN
- RADIUS authentication and accountability
-
AAA including TACACS+
-
Secure Management
- HTTPS with SSLv3/TLS 1.2
- Secure command line access
Enterprise-Level L2+ Features
Enhance stability and flexibility with comprehensive L2+ functions:
- VLAN & Control
- 802.1Q VLAN
-
802.3x Flow Control and HOL blocking prevention
-
Spanning Tree Protocols
- STP (802.1d)
- RSTP (802.1w)
- MSTP (802.1s)
-
STP Security: TC Protect, BPDU Filter, BPDU Protect, Root Protect, Loop Protect
-
Link Aggregation
- Static link aggregation
- 802.3ad LACP
-
Up to 8 aggregation groups with up to 8 ports per group
-
Loopback & Mirroring
- Port-based and VLAN-based loopback detection
- Port mirroring, CPU mirroring
- One-to-One or Many-to-One, Tx/Rx/Both
Advanced Multicast & QoS
L2 Multicast
- Supports 511 IPv4/IPv6 IGMP groups
- IGMP Snooping (v1/v2/v3) with Fast Leave and Snooping Querier
- IGMP Authentication
- MVR
- MLD Snooping (v1/v2) with Fast Leave and Snooping Querier
- Static group configuration and limited IP multicast
- Multicast filtering: 256 profiles, 16 entries per profile
Advanced QoS
- 8 priority queues
- 802.1p CoS/DSCP priority
- Queue scheduling: SP, WRR, SP+WRR
- Bandwidth control with port/flow-based rate limiting
- Actions for flows: mirror, redirect, rate limit, QoS remark
Voice and video traffic can be prioritized by IP address, MAC address, TCP/UDP port, and more, helping keep services smooth even when bandwidth is limited.
ISP-Oriented Features
Developed with service providers in mind, the switch offers:
- sFlow
- QinQ
- L2PT
- PPPoE ID insertion
- IGMP authentication
- 802.3ah OAM
- Device Link Detection Protocol (DLDP) for link monitoring and troubleshooting
IPv6-Ready Networking
The switch is equipped with IPv6 capabilities to support Next Generation Networks (NGN) without hardware upgrades:
- Dual IPv4/IPv6 stack
- MLD Snooping
- IPv6 ACL and IPv6 interface
- Static IPv6 routing
- IPv6 Neighbor Discovery (ND)
- Path MTU discovery
- ICMPv6, TCPv6, UDPv6
- IPv6 applications:
- DHCPv6 client
- Ping6, Tracert6
- Telnet (v6)
- IPv6 SNMP, IPv6 SSH, IPv6 SSL
- HTTP/HTTPS
- IPv6 TFTP
Management & Monitoring
Manage and monitor with flexible options:
- Interfaces
- Web-based GUI
-
CLI via console port and Telnet
-
Protocols & Tools
- SNMP v1/v2c/v3 with Trap/Inform
- RMON (1, 2, 3, 9 groups)
- 802.1ab LLDP/LLDP-MED
- DHCP/BOOTP client
- DHCP AutoInstall
- SDM Template
- CPU monitoring
- Cable diagnostics
- EEE
- Password recovery
- SNTP
-
System log
-
Advanced Management Features
- Dual Image, dual configuration
- Reboot schedule
Omada Centralized Management
Fully compatible with Omada’s controller options:
- Omada App
-
Access via:
- Omada Cloud-Based Controller (TL-SG3428 v2 and above)
- OC300
- OC200
- Omada Software Controller
-
Centralized Management
- Omada Cloud-Based Controller (TL-SG3428 v2 and above)
- Omada Hardware Controllers (OC300, OC200)
-
Omada Software Controller
-
Cloud Access
-
Through Omada Cloud-Based Controller (TL-SG3428 v2 and above), OC300, OC200, or Omada Software Controller
-
Zero-Touch Provisioning (ZTP)
-
Requires Omada Cloud-Based Controller (TL-SG3428 v2 and above)
-
Advanced Omada Features
- Automatic device discovery
- Batch configuration and firmware upgrading
- Intelligent network monitoring
- Abnormal event warnings
- Unified configuration
Hardware Specifications
| Category | Details |
|---|---|
| Interfaces | 24× 10/100/1000 Mbps RJ45 ports; 4× Gigabit SFP slots |
| Console Ports | 1× RJ45 console port; 1× Micro-USB console port |
| Fan Quantity | Fanless |
| Power Supply | 100–240 V AC, 50/60 Hz |
| Dimensions (W×D×H) | 17.3 × 7.1 × 1.7 in (440 × 180 × 44 mm) |
| Mounting | Rack mountable |
| Max Power Consumption | 19.9 W (220 V/50 Hz) |
| Max Heat Dissipation | 67.73 BTU/h (220 V/50 Hz) |
Performance Specifications
| Category | Details |
|---|---|
| Switching Capacity | 56 Gbps |
| Packet Forwarding Rate | 41.66 Mpps |
| MAC Address Table | 16K |
| Packet Buffer Memory | 12 Mbit |
| Jumbo Frame | 9 KB |
L3 Features
- 16 IPv4/IPv6 interfaces
- Static routing with up to 48 static routes
- Static ARP, 512 ARP entries
- Proxy ARP and Gratuitous ARP
- DHCP server, DHCP relay, DHCP L2 relay
MIB Support
- MIB II (RFC1213)
- Bridge MIB (RFC1493)
- P/Q-Bridge MIB (RFC2674)
- RADIUS Accounting Client MIB (RFC2620)
- RADIUS Authentication Client MIB (RFC2618)
- Remote Ping/Traceroute MIB (RFC2925)
- RMON MIB (RFC1757, RMON 1,2,3,9)
- TP-Link private MIBs
Certifications
- CE
- FCC
- RoHS
Package Contents
- TL-SG3428 Switch
- Power cord
- Quick Installation Guide
- Rackmount kit
- Rubber feet
System Requirements
- Microsoft Windows 98SE, NT, 2000, XP, Vista, 7, 8, 10, 11
- MAC OS
- NetWare
- UNIX
- Linux
Environmental Specifications
- Operating Temperature: 0–45 °C (32–113 °F)
- Storage Temperature: -40–70 °C (-40–158 °F)
- Operating Humidity: 10–90% RH, non-condensing
- Storage Humidity: 5–90% RH, non-condensing
