-
€
The SG3210XHP-M2 is a managed L2+ layer JetStream network switch integrated with the Omada SDN system, designed for environments requiring high throughput and high-power PoE supply. The device is equipped with 8 ports of 2.5 Gigabit Ethernet (2.5G), all supporting the PoE+ standard (802.3at/af), with a total PoE power budget of 240 W (up to 30 W per port). Additionally, the switch features 2 SFP+ 10 Gigabit (10 Gbps) slots, which serve as uplink ports for high-speed connection to the backbone network or servers. The switch supports L2/L2+ features, including static routing, VLAN 802.1Q, Link Aggregation Control Protocol (LACP), and advanced Quality of Service (QoS) mechanisms. The total switching capacity is 80 Gbps. Thanks to integration with Omada SDN, it enables centralized cloud management. The device is suitable for 13-inch Rack mounting and is equipped with an active cooling system (fans).

Unlock the Potential of Wi-Fi 6 Technology with Multi-Gigabit PoE+ Ports
Wi-Fi 7 has arrived and introduced stunning performance - greater bandwidth, lower latency, stronger resistance to network congestion, and higher efficiency. Join the professionals and experience the highest performance of next-generation Wi-Fi networks.

Business Switch with 10G Uplink Ports
Two 10 Gbps SFP+ slots provide non-blocking switching performance and minimize latency. This ensures that connections to servers and other switches are established instantly and are highly reliable.


Software Defined Networking (SDN) Control with Cloud Access
The Omada Software Defined Networking (SDN) platform integrates network devices, including access points, switches, and gateways, providing 100% centralized cloud management. Omada enables the creation of a highly scalable network — fully controlled from a single interface. This translates into seamless wired and wireless connections essential in hospitality, education, retail, offices, and many other industries and facilities.
Advanced Layer 3 Features
Extensive L2+ and L3 features help build a highly scalable and well-secured network that is a reliable and efficient solution — ideal for offices, campuses, and service provider applications.

Effective Security
IP-MAC-Port-VID Binding, Port Security, Storm Control, and DHCP Snooping are SG3210XHP-M2 switch features that protect the network from threats. The device has an integrated list of the most common DoS attacks, allowing it to detect and prevent them early. Additionally, the ACL function (L2 to L4) is applied to block access to sensitive network resources. Denial of packet transmission can be set for specific source or destination MAC addresses, IP addresses, TCP or UDP ports, or VLAN IDs. Furthermore, the switch uses 802.1X authentication in conjunction with RADIUS/Tacacs+ server functions to verify users attempting to access the network. The server will only grant access to users who provide valid authentication credentials.
L2+ Layer Features
Thanks to extensive Layer 2 features, including 802.1Q VLAN support, Port Mirroring, STP/RSTP/MSTP, Link Aggregation (LACP), and 802.3x Flow Control, the SG3210XHP-M2 switches are highly versatile. The IGMP Snooping function enables intelligent routing of multicast streams only to specific subscribers, and IGMP Throttling and IGMP Filtering effectively restrict access to multicast transmissions for unauthorized users. The SG3210XHP-M2 also supports the Static Routing function, which allows network segmentation, internal traffic steering through the switch, and increased network efficiency.
Advanced QoS
To ensure better audio and video transmission in a single network traffic stream, network administrators can prioritize traffic, e.g., for specific IP addresses, MAC addresses, TCP or UDP ports, etc. This ensures smooth and delay-free audio and video transmission.
Features for Service Providers
The SG3210XHP-M2 is an excellent solution for Internet Service Providers due to the availability of the following features: QinQ, L2PT, PPPoE ID Insertion, and IGMP Authentication. The 802.3ah OAM functions and Device Link Detection Protocol (DLDP) offer easy monitoring and troubleshooting of Ethernet links.
IPv6 Support
The switch supports numerous IPv6 features, such as IPv4/IPv6 Dual Stack, MLD Snooping, IPv6 ACL, DHCPv6 Snooping, IPv6 Interface, PMTU Discovery, and IPv6 Neighbor Discovery, ensuring your network conforms to NGN standards, and hardware replacement will not be necessary.
Specifications:
| TL-SG3210XHP-M2 | |
| HARDWARE FEATURES | |
|---|---|
| Ports | • 8× 100/1000/2500 Mbps RJ45 Ports • 2× 10G SFP+ Slots • 1× RJ45 Console Port • 1× microUSB Console Port |
| Fanless | No, 2 fans |
| Power Supply | 100-240 V AC~50/60 Hz |
| Dimensions (W x D x H) | 440 × 180 × 44 mm (17.3 × 7.1 × 1.7 in) |
| Mounting | Rack Mountable |
| Max Power Consumption | 17.24 W (110 V/50 Hz) (no PoE device connected) 291.49 W (110 V/50 Hz) (with 240 W power draw) |
| Max Heat Dissipation | 58.82 BTU/h (no PoE device connected) 994.56 BTU/h (with 240 W power draw) |
| PERFORMANCE | |
| Switching Capacity | 80 Gbps |
| Packet Forwarding Rate | 59.52 Mpps |
| MAC Address Table | 16 K |
| Jumbo Frame | 9 KB |
| SOFTWARE FEATURES | |
| Quality of Service (QoS) | • 8 priority queues • Supports 802.1p CoS/DSCP priority • Priority Scheduling Mode: - SP (Strict Priority) - WRR (Weighted Round Robin) - SP+WRR • Bandwidth Control - Port/Flow based Rating Limiting • Smoother Performance • Action for Flows - Mirror (to supported interface) - Redirect (to supported interface) - Rate Limit - QoS Remark |
| L2 and L2+ Features | • Link Aggregation - Static Link Aggregation - 802.3ad LACP - Up to 8 aggregation groups and up to 8 ports per group • Spanning Tree Protocol (STP) - 802.1D STP - 802.1w RSTP - 802.1s MSTP - STP Security: TC Protect, BPDU Filter, BPDU Protect, Root Protect • Loopback Detection - Port-based - VLAN based • Flow Control - 802.3x Flow Control - HOL Blocking Prevention • Mirroring - Port Mirroring - CPU Mirroring - One-to-One transmission - Many-to-One transmission - Tx/Rx/Both Ports |
| L2 Multicast | • IGMP Snooping - IGMP v1/v2/v3 Snooping - Fast Leave - IGMP Snooping Querier - IGMP Authentication • IGMP Authentication • MVR • MLD Snooping - MLD v1/v2 Snooping - Fast Leave - MLD Snooping Querier - Static Group Config - Limited IP Multicast Forwarding • Multicast Filtering: 256 profiles and 16 entries per profile |
| VLAN | • VLAN Groups - Max 4K VLAN Groups • 802.1Q Tagged VLAN • MAC VLAN: 7 Entries • Protocol VLAN • GVRP • VLAN VPN (QinQ) - Port-Based QinQ - Selective QinQ • Voice VLAN |
| Access Control List (ACL) | • Time-based ACL • MAC ACL - Source MAC - Destination MAC - VLAN ID - User Priority - Ethertype • IP ACL - Source IP - Destination IP - Fragment - IP Protocol - TCP Flag - TCP/UDP Port - DSCP/IP TOS - User Priority • IPv6 ACL • Packet Content ACL • Combined ACL • Access Control Policy - Mirroring - Rate Limit - Redirect - QoS Remark • ACL apply to Port/VLAN |
| Security | • IP-MAC-Port Binding - 512 entries - DHCP Snooping - ARP Inspection - IPv4 Source Guard: 100 entries • IPv6-MAC-Port Binding - 512 entries - DHCPv6 Snooping - ND Detection - IPv6 Source Guard: 100 entries • DoS Defend • Static/Dynamic/Permanent Port Security - Up to 64 MAC addresses per port • Broadcast/Multicast/Unicast Storm Control - Control mode (kbps/ratio) • 802.1X Authentication - Port based authentication - Mac based authentication - VLAN Assignment - MAB - Guest VLAN - Support Radius authentication and accountability • AAA (including TACACS+) • Port Isolation • Secure web management through HTTPS with SSLv3/TLS 1.2 encryption • Secure Command Line Interface (CLI) management with SSHv1/SSHv2 encryption • IP/Port/MAC based Access Control |
| IPv6 | • IPv6 Dual IPv4/IPv6 • Multicast Listener Discovery (MLD) Snooping • IPv6 ACL • IPv6 Interface • Static IPv6 Routing • IPv6 neighbor discovery (ND) • Path maximum transmission unit (MTU) discovery • ICMP v6 • TCP v6/UDP v6 • IPv6 Applications: - DHCPv6 Client - Ping6 - Tracert6 - Telnet (v6) - IPv6 SNMP - IPv6 SSH - IPv6 SSL - Http/Https - IPv6 TFTP |
| L3 Switch Features | • 16 IPv4/IPv6 Interfaces • Static Routing - 48 static routes • Static ARP Entries - 128 static entries • Proxy ARP • Gratuitous ARP • DHCP Server • DHCP Relay - DHCP Interface Relay - DHCP VLAN Relay • DHCP L2 Relay |
| Management | • Web-based GUI • Command Line Interface (CLI) • SNMP v1/v2c/v3 - Trap/Inform - RMON (1, 2, 3, 9 groups) • SDM Template • DHCP/BOOTP Client • 802.1ab LLDP/LLDP-MED • DHCP AutoInstall • Dual Image, Dual Configuration • CPU Monitoring • Cable Diagnostics • EEE • Password Recovery • SNTP • System Log |
| Advanced Features | • Supports Omada Hardware Controller (OC200/OC300), Software Controller, Cloud-Based Controller • Automatic Device Discovery • Batch Configuration • Batch Firmware Upgrading • Intelligent Network Monitoring • Abnormal Event Warnings • Unified Configuration • Reboot Schedule • Zero-Touch Provisioning (ZTP) |
| MIBs | • MIB II (RFC1213) • Port MIB (RFC2233) • Ethernet Interface MIB (RFC1643) • Bridge MIB (RFC1493) • P/Q-Bridge MIB (RFC2674) • RMON MIB (RFC2819) • RMON2 MIB (RFC2021) • Radius Accounting Client MIB (RFC2620) • Radius Authentication Client MIB (RFC2618) • Ping and Traceroute MIB (RFC2925) • Supports TP-Link Private MIBs |
| OTHERS | |
| Certification | CE, FCC, RoHS |
| Package Contents | • TL-SG3210XHP-M2 Switch • Power Cord • Installation Guide • Rackmount Kit • Rubber Feet |
| Environment | • Operating Temperature: 0℃~45℃ (32℉~113℉); • Storage Temperature: -40℃~70℃ (-40℉~158℉); • Operating Humidity: 10%~90% RH non-condensing • Storage Humidity: 5%~90% RH non-condensing |










