| Quality of Service | • 8 priority queues • 802.1p CoS/DSCP priority
 • Queue scheduling
 - SP (Strict Priority)
 - WRR (Weighted Round Robin)
 - SP+WRR
 • Bandwidth Control
 - Port/Flow based Rating Limiting
 • Smoother Performance
 • Action for Flows
 - Mirror (to supported interface)
 - Redirect (to supported interface)
 - Rate Limit
 - QoS Remark
 | 
			
				| L3 Features | • 32 IPv4/IPv6 Interfaces (v1); 128 IPv4/IPv6 Interfaces (v2~v6) • Static Routing
 - 48 static routes
 • Static ARP
 - 128 static entries
 • 316 ARP Entries (512 ARP Entries for TL-SG3428 V2.0 & TL-SG3428MP V2.0)
 • Proxy ARP
 • Gratuitous ARP
 • DHCP Server
 • DHCP Relay
 - DHCP interface relay
 - DHCP VLAN relay
 • DHCP L2 Relay
 | 
			
				| L2 and L2+ Features | • Link Aggregation - Static link aggregation
 - 802.3ad LACP
 - Up to 8 aggregation groups and up to 8 ports per group
 • Spanning Tree Protocol
 - 802.1d STP
 - 802.1w RSTP
 - 802.1s MSTP
 - STP Security: TC Protect, BPDU Filter, BPDU Protect, Root Protect, Loop Protect
 • Loopback Detection
 - Port-based
 - VLAN based
 • Flow Control
 - 802.3x Flow Control
 - HOL Blocking Prevention
 • Mirroring
 - Port Mirroring
 - CPU Mirroring
 - One-to-One
 - Many-to-One
 - Tx/Rx/Both
 | 
			
				| L2 Multicast | • Supports 511 (IPv4, IPv6) IGMP groups • IGMP Snooping
 - IGMP v1/v2/v3 Snooping
 - Fast Leave
 - IGMP Snooping Querier
 - IGMP Authentication
 • IGMP Authentication
 • MVR
 • MLD Snooping
 - MLD v1/v2 Snooping
 - Fast Leave
 - MLD Snooping Querier
 - Static Group Config
 - Limited IP Multicast
 • Multicast Filtering: 256 profiles and 16 entries per profile
 | 
			
				| Advanced Features | • Automatic Device Discovery • Batch Configuration
 • Batch Firmware Upgrading
 • Intelligent Network Monitoring
 • Abnormal Event Warnings
 • Unified Configuration
 • Reboot Schedule
 | 
			
				| VLAN | • VLAN Group - Max 4K VLAN Groups
 • 802.1Q Tagged VLAN
 • MAC VLAN: 30 Entries (12 Entries for TL-SG3428MP V1.0)
 • Protocol VLAN: Protocol Template 16, Protocol
 VLAN 16
 • Private VLAN
 • GVRP
 • VLAN VPN (QinQ)
 - Port-Based QinQ
 - Selective QinQ
 • Voice VLAN
 | 
			
				| Access Control List | • Time-based ACL • MAC ACL
 - Source MAC
 - Destination MAC
 - VLAN ID
 - User Priority
 - Ether Type
 • IP ACL
 -Source IP
 - Destination IP
 - Fragment
 - IP Protocol
 - TCP Flag
 - TCP/UDP Port
 - DSCP/IP TOS
 - User Priority
 • Combined ACL
 • Packet Content ACL
 • IPv6 ACL
 • Policy
 - Mirroring
 - Redirect
 - Rate Limit
 - QoS Remark
 • ACL apply to Port/VLAN
 | 
			
				| Security | • IP-MAC-Port Binding - DHCP Snooping
 - ARP Inspection
 - IPv4 Source Guard
 • IPv6-MAC-Port Binding
 - DHCPv6 Snooping
 - ND Detection
 - IPv6 Source Guard
 • DoS Defend
 • Static/Dynamic Port Security
 - Up to 64 MAC addresses per port
 • Broadcast/Multicast/Unicast Storm Control
 - kbps/ratio/pps control mode
 • IP/Port/MAC based access control
 • 802.1X
 - Port based authentication
 - Mac based authentication
 - VLAN Assignment
 - MAB
 - Guest VLAN
 - Support Radius authentication and accountability
 • AAA (including TACACS+)
 • Port Isolation
 • Secure web management through HTTPS with SSLv3/TLS 1.2
 • Secure Command Line Interface (CLI) management with SSHv1/SSHv2
 | 
			
				| IPv6 | • IPv6 Dual IPv4/IPv6 • Multicast Listener Discovery (MLD) Snooping
 • IPv6 ACL
 • IPv6 Interface
 • Static IPv6 Routing
 • IPv6 neighbor discovery (ND)
 • Path maximum transmission unit (MTU) discovery
 • Internet Control Message Protocol (ICMP) version 6
 • TCPv6/UDPv6
 • IPv6 applications
 - DHCPv6 Client
 - Ping6
 - Tracert6
 - Telnet (v6)
 - IPv6 SNMP
 - IPv6 SSH
 - IPv6 SSL
 - Http/Https
 - IPv6 TFTP
 | 
			
				| MIBs | • MIB II (RFC1213) • Bridge MIB (RFC1493)
 • P/Q-Bridge MIB (RFC2674)
 • Radius Accounting Client MIB (RFC2620)
 • Radius Authentication Client MIB (RFC2618)
 • Remote Ping, Traceroute MIB (RFC2925)
 • Support TP-Link private MIBs
 • RMON MIB(RFC1757, rmon 1,2,3,9)
 |