JetStream 28-Port Gigabit L2+ Managed Switch with 24-Port PoE+
The TP-Link SG3428MP JetStream is a high-performance 28-port Gigabit managed switch designed for businesses that demand reliable, scalable, and secure network connectivity. With 24 PoE+ ports, 4 Gigabit SFP slots, and a total power budget of 384 W, this switch simplifies deployment of network devices while supporting advanced management and security features.
The SG3428MP delivers seamless power and data transmission over a single Ethernet cable, making it ideal for IP cameras, VoIP phones, and wireless access points. Integrated into the Omada SDN platform, it enables centralized cloud management, intelligent monitoring, and easy zero-touch provisioning. Enhanced QoS, static routing, and robust security measures ensure efficient and secure network operation for small and medium-sized businesses, hospitality, retail, and office environments.
Dedicated 24-Port PoE+ for Flexible Deployments
Equipped with 24 PoE+ ports, each delivering up to 30 W, this switch allows you to power devices while transmitting data through a single cable. The 384 W total PoE budget supports multiple devices, reducing installation costs and simplifying network setups.
High-Speed Connections and L2+ Capabilities
The SG3428MP includes 24 full Gigabit RJ45 ports and 4 Gigabit SFP slots, offering reliable high-speed connections. Advanced L2+ capabilities, such as static routing, VLAN support, and IGMP snooping, allow for efficient traffic management and network segmentation.
Cloud-Based Software Defined Networking (SDN)
Integrated with the Omada SDN platform, the switch allows centralized cloud management of switches, access points, and routers. The intuitive Omada app enables easy deployment, monitoring, and troubleshooting from a single interface, supporting highly scalable wired and wireless networks.
Enhanced Network Security
Protect your network with comprehensive security measures including IP-MAC-Port binding, port security, ACLs, DHCP snooping, 802.1X authentication, and DoS attack prevention. These features safeguard sensitive resources and control user access effectively.
Optimized Performance for Voice and Video
Quality of Service (QoS) ensures that voice and video traffic receive priority, maintaining smooth communication even when network bandwidth is constrained. Advanced L2/L3/L4 QoS supports prioritization based on IP, MAC, or port numbers.
Designed with ISPs in mind, the switch includes QinQ, L2PT, PPPoE ID insertion, IGMP authentication, and Ethernet link monitoring through 802.3ah OAM and DLDP.
Future-Proof IPv6 Support
With dual IPv4/IPv6 stacks, DHCPv6 snooping, MLD snooping, IPv6 ACL, and PMTU discovery, the SG3428MP ensures your network is ready for next-generation networking without additional hardware upgrades.
Enterprise-Level Management
Manage the switch easily through a web-based GUI or command-line interface with SSL/SSH encryption. SNMP (v1/v2c/v3 ) and RMON support allow monitoring, polling, and event alerts for proactive network management.
| ©2026 Respective owners and brand holders. This table has been carefully researched and generated by ComXpert International CC (//www.comx-computers.co.za), however, errors and omissions may occur. Only references to South Africa apply. All products are sourced in South Africa from the official suppliers and the warranty is that of the local supplier. E&OE. This table and our site's content may be used on condition that this notice and link remains intact and unaltered. | |
Specifications![]() | |
| Product Code | TP-SG3428MP![]() |
| HARDWARE FEATURES | |
| Interface | 24x 10/100/1000Mbps RJ45 Ports |
| 4x Gigabit SFP Slots | |
| 1x RJ45 Console Port | |
| 1x Micro-USB Console Port | |
| Fan Quantity | 2 |
| Power Supply | 100-240 V AC~50/60 Hz |
| PoE Ports (RJ45) | Standard: 802.3at/af compliant |
| PoE+ Ports: 24 Ports, up to 30 W per port | |
| Power Budget: 384 W | |
| Dimensions ( W x D x H ) | 17.3 x 13.0 x 1.7 in (440 x 330 x 44 mm) |
| Mounting | Rack Mountable |
| Max Power Consumption | V1: 463.8 W (110 V/60 Hz) (with 384 W PD connected), 31.0 W (110 V/60 Hz) (no PD connected) |
| V2: 465.8 W (110 V/60 Hz) (with 384 W PD connected), 34.4 W (110 V/60 Hz) (no PD connected) | |
| V3: 442.1 W (220 V/50 Hz) (with 384 W PD connected) | |
| V4: 460.8 W (110 V/60 Hz) (with 384 W PD connected) | |
| V5: 456.4 W (110 V/60 Hz) (with 384 W PD connected) | |
| Max Heat Dissipation | V1: 1582.49 BTU/h (110 V/60 Hz) (with 384 W PD connected), 105.78 BTU/h (110 V/60 Hz) (no PD connected) |
| V2: 1589.31 BTU/hr (110 V/60 Hz) (with 384 W PD connected), 117.38 BTU/hr (110 V/60 Hz) (no PD connected) | |
| V3: 1508.67 BTU/hr (220 V/50 Hz) (with 384 W PD connected) | |
| V4: 1572.48 BTU/hr (110 V/60 Hz) (with 384 W PD connected) | |
| V5: 1557.47 BTU/hr (110 V/60 Hz) (with 384 W PD connected) | |
| PERFORMANCE | |
| Switching Capacity | 56 Gbps |
| Packet Forwarding Rate | 41.66 Mpps |
| MAC Address Table | V1: 8K |
| V2 and above: 16K | |
| Packet Buffer Memory | 4.1 Mbit |
| Jumbo Frame | 9 KB |
| SOFTWARE FEATURES | |
| Quality of Service | 8 priority queues |
| 802.1p CoS/DSCP priority | |
| Queue scheduling | |
| - SP (Strict Priority) | |
| - WRR (Weighted Round Robin) | |
| - SP+WRR | |
| Bandwidth Control | |
| - Port/Flow based Rating Limiting | |
| Smoother Performance | |
| Action for Flows | |
| - Mirror (to supported interface) | |
| - Redirect (to supported interface) | |
| - Rate Limit | |
| - QoS Remark | |
| L2 and L2+ Features | Link Aggregation |
| - Static link aggregation | |
| - 802.3ad LACP | |
| - Up to 8 aggregation groups and up to 8 ports per group | |
| Spanning Tree Protocol | |
| - 802.1d STP | |
| - 802.1w RSTP | |
| - 802.1s MSTP | |
| - STP Security: TC Protect, BPDU Filter, BPDU Protect, Root Protect, Loop Protect | |
| Loopback Detection | |
| - Port-based | |
| - VLAN based | |
| Flow Control | |
| - 802.3x Flow Control | |
| - HOL Blocking Prevention | |
| Mirroring | |
| - Port Mirroring | |
| - CPU Mirroring | |
| - One-to-One | |
| - Many-to-One | |
| - Tx/Rx/Both | |
| L2 Multicast | Supports 511 (IPv4, IPv6) IGMP groups |
| IGMP Snooping | |
| - IGMP v1/v2/v3 Snooping | |
| - Fast Leave | |
| - IGMP Snooping Querier | |
| - IGMP Authentication | |
| IGMP Authentication | |
| MVR | |
| MLD Snooping | |
| - MLD v1/v2 Snooping | |
| - Fast Leave | |
| - MLD Snooping Querier | |
| - Static Group Config | |
| - Limited IP Multicast | |
| Multicast Filtering: 256 profiles and 16 entries per profile | |
| VLAN | VLAN Group |
| - Max 4K VLAN Groups | |
| 802.1Q Tagged VLAN | |
| MAC VLAN: 30 Entries (12 Entries for TL-SG3428MP V1.0) | |
| Protocol VLAN: Protocol Template 16, Protocol | |
| VLAN 16 | |
| Private VLAN | |
| GVRP | |
| VLAN VPN (QinQ) | |
| - Port-Based QinQ | |
| - Selective QinQ | |
| Voice VLAN | |
| Access Control List | Time-based ACL |
| MAC ACL | |
| - Source MAC | |
| - Destination MAC | |
| - VLAN ID | |
| - User Priority | |
| - Ether Type | |
| IP ACL | |
| -Source IP | |
| - Destination IP | |
| - Fragment | |
| - IP Protocol | |
| - TCP Flag | |
| - TCP/UDP Port | |
| - DSCP/IP TOS | |
| - User Priority | |
| Combined ACL | |
| Packet Content ACL | |
| IPv6 ACL | |
| Policy | |
| - Mirroring | |
| - Redirect | |
| - Rate Limit | |
| - QoS Remark | |
| ACL apply to Port/VLAN | |
| Security | IP-MAC-Port Binding |
| - DHCP Snooping | |
| - ARP Inspection | |
| - IPv4 Source Guard | |
| IPv6-MAC-Port Binding | |
| - DHCPv6 Snooping | |
| - ND Detection | |
| - IPv6 Source Guard | |
| DoS Defend | |
| Static/Dynamic Port Security | |
| - Up to 64 MAC addresses per port | |
| Broadcast/Multicast/Unicast Storm Control | |
| - kbps/ratio/pps control mode | |
| IP/Port/MAC based access control | |
| 802.1X | |
| - Port based authentication | |
| - Mac based authentication | |
| - VLAN Assignment | |
| - MAB | |
| - Guest VLAN | |
| - Support Radius authentication and accountability | |
| AAA (including TACACS+) | |
| Port Isolation | |
| Secure web management through HTTPS with SSLv3/TLS 1.2 | |
| Secure Command Line Interface (CLI) management with SSHv1/SSHv2 | |
| IPv6 | IPv6 Dual IPv4/IPv6 |
| Multicast Listener Discovery (MLD) Snooping | |
| IPv6 ACL | |
| IPv6 Interface | |
| Static IPv6 Routing | |
| IPv6 neighbor discovery (ND) | |
| Path maximum transmission unit (MTU) discovery | |
| Internet Control Message Protocol (ICMP) version 6 | |
| TCPv6/UDPv6 | |
| IPv6 applications | |
| - DHCPv6 Client | |
| - Ping6 | |
| - Tracert6 | |
| - Telnet (v6) | |
| - IPv6 SNMP | |
| - IPv6 SSH | |
| - IPv6 SSL | |
| - Http/Https | |
| - IPv6 TFTP | |
| L3 Features | 16 IPv4/IPv6 Interfaces |
| Static Routing | |
| - 48 static routes | |
| Static ARP | |
| - 128 static entries | |
| 316 ARP Entries (512 ARP Entries for TL-SG3428 V2.0 & TL-SG3428MP V2.0) | |
| Proxy ARP | |
| Gratuitous ARP | |
| DHCP Server | |
| DHCP Relay | |
| - DHCP interface relay | |
| - DHCP VLAN relay | |
| DHCP L2 Relay | |
| Advanced Features | Automatic Device Discovery |
| Batch Configuration | |
| Batch Firmware Upgrading | |
| Intelligent Network Monitoring | |
| Abnormal Event Warnings | |
| Unified Configuration | |
| Reboot Schedule | |
| MIBs | MIB II (RFC1213) |
| Bridge MIB (RFC1493) | |
| P/Q-Bridge MIB (RFC2674) | |
| Radius Accounting Client MIB (RFC2620) | |
| Radius Authentication Client MIB (RFC2618) | |
| Remote Ping, Traceroute MIB (RFC2925) | |
| Support TP-Link private MIBs | |
| RMON MIB(RFC1757, rmon 1,2,3,9) | |
| MANAGEMENT | |
| Omada App | Yes, through |
| Omada Cloud-Based Controller (Not Supported by TL-SG2210P v4) | |
| OC300 | |
| OC200 | |
| Omada Software Controller | |
| Centralized Management | Omada Cloud-Based Controller (Not Supported by TL-SG2210P v4) |
| Omada Hardware Controller OC300 | |
| Omada Hardware Controller OC200 | |
| Omada | |
Sold by ComX Computers