
DGS-3420-28PCEOL
xStack L2+ Managed Stackable Gigabit Switch with 20 ports 10/100/1000BASE-T, 4 Combo 10/100/1000BASE-T PoE/SFP ports and 4 ports SFP+
Description
	The DGS-3120 Series xStack switches are enhanced 2+ Gigabit switches designed to connect end-users in a secure campus or enterprise network. These switches support physical stacking1, multicast, and enhanced security, making them an ideal Gigabit access layer solution. The DGS-3120-24TC/48TC provides 20 or 44 10/100/1000Mbps Gigabit Ethernet ports, and 4 combo 1000BASE-T/SFP Gigabit Ethernet ports. The DGS-3120-24PC/48PC provides 24 or 48 10/100/1000Mbps PoE Gigabit Ethernet ports and 4 combo 1000BASE-T/SFP Gigabit Ethernet ports. The DGS-3120-24SC/24SC-DC provides 16 SFP Gigabit Ethernet ports and 8 combo 1000BASE-T/SFP Gigabit ports. Each 10/100/1000 Mbps port on the DGS-3120-24PC/48PC supports the 802.3af and 802.3at Power over Ethernet standards. The default power budget for these models is 370 watts and can be expanded to 760 watts with the DPS-700 RPS. The switches are also equipped with an SD Card slot, allowing the user to boot images and upload configuration files directly from an SD Card as well as conveniently save syslog files onto the SD Card.
	Standard, Enhanced and Routed Images
	The DGS-3120 Series has support for three different software images - the Standard Image (SI), Enhanced Image (EI), and Routed Image (RI). The Standard Image provides sophisticated features for campus or enterprise usage. It includes advanced Quality of Service (QoS), traffic shaping, L2 multicasting, robust security features, and IPv6 features which are suitable for next-generation IPv6 networks or triple play applications over Metro Ethernet. The Enhanced Image supports ERPS, Double VLAN (Q-in-Q), Ethernet OAM, Static Route, IMPB, and sFlow. The Routed Image supports DHCP Server, VRRP, IPv6 Tunneling, RIP, OSPF, IGMP, MLD, PIM, and DVMRPv3.
	Enhanced Network Reliability
	The DGS-3120 Series targets enterprises, campuses, and customers who require a high level of network security and maximum uptime. All the models in the DGS-3120 Series except the DGS-3120-24SC-DC support an external redundant power supply so that continued operation can be assured. They also include other features, such as 802.1D Spanning Tree (STP), 802.1w Rapid Spanning Tree (RSTP), and 802.1s Multiple Spanning Tree (MSTP), Loopback Detection (LBD), and Broadcast Storm Control, that enhances network resilience. G.8032 Ethernet Ring Protection Switching (ERPS)2 minimizes the recovery time to 50ms. For load sharing and redundancy backup in a switch cascading/server attachment configuration, the DGS-3120 Series provides dynamic 802.3ad Link Aggregation Port Trunking.
	Comprehensive Security
	The DGS-3120 Series provides users with the latest security features such as Multi-layer and Packet Content Access Control Lists (ACL), Storm Control, and IP-MAC-Port Binding (IMPB)2 with DHCP Snooping. The IP-MAC-Port Binding feature allows administrators to bind a source IP address with an associated MAC and also define the port number to enhance user access control. With the DHCP Snooping feature, the switch automatically learns IP/MAC pairs by snooping DHCP packets and saving them to the IMPB white list. In addition, the D-Link Safeguard Engine identifies and prioritizes “CPU interested” packets to prevent malicious traffic from interrupting normal network flows, and to protect switch operation.
	Identity Driven Network Policies
	The DGS-3120 Series supports authentication mechanisms such as 802.1X, Web-based Access Control (WAC), and MAC-based Access Control (MAC) for strict access control and easy deployment. After authentication, individual policies such as VLAN membership, QoS policies, and ACL rules can be assigned to each host. In addition, the switch also supports Microsoft® NAP (Network Access Protection). NAP is a policy enforcement technology that allows customers to protect network assets from compromised computers by enforcing compliance with network health policies.
	Traffic Management for Triple Play
	The DGS-3120 Series implements a rich set of multilayer QoS/CoS features to ensure that critical network services such as VoIP, video conferencing, IPTV, and IP surveillance are given high priority. Traffic Shaping features guarantee bandwidth for these services when the network is busy. L2 Multicast support enables the DGS-3120 to handle growing IPTV applications. Host-based IGMP/MLD Snooping allows multiple multicast subscribers per physical interface and ISM VLAN to send multicast streams in a multicast VLAN to save bandwidth and to provide better security to the backbone network. The ISM VLAN profiles allow users to bind/replace the pre-defined multicast registration information to subscriber ports quickly and easily.
	Proactive, Effective Network Management
	To uphold enterprise customers’ Service Level Agreements (SLA), service providers must reduce their Mean Time to Repair (MTTR) and increase service availability. Ethernet OAM features address these challenges and enable service providers to offer carrier-grade services. The DGS-3120 Series supports industry-standard OAM tools, including IEEE 802.3ah, IEEE802.1ag, and ITU-TY.1731. Connectivity Fault Management (CFM) provides tools to monitor and troubleshoot end-to-end Ethernet networks, allowing service providers to check connectivity, isolate network issues, and identify customers affected by network issues.
	IPv6 Technology
	The DGS-3120 Series is fully compliant with future IPv6 networks. It supports remote IPv6 manageability from telnet, HTTP, or SNMP. To create secure IPv6 networks, the DGS-3120 Series uses IPv6 ACL, DHCPv6 Snooping, and Neighbor Discovery (ND) Snooping functions to protect the network from illegal IPv6 clients. The DGS-3120 Series has been certified with IPv6 Ready Logo Phase 2 from the IPv6 forum, a worldwide IPv6 advocacy consortium. The IPv6 Ready Logo Program ensures the conformance and interoperability of IPv6 products.
	Green Technology
	D-Link is striving to take the lead in developing innovative and power-saving technology that does not sacrifice operational performance or functionality. The DGS-3120 Series implements the D-Link Green Technology, which includes a power saving mode, Smart Fan, reduced heat, and cable length detection. The power-saving feature automatically powers down ports that have no link or link partner. The Smart Fan feature enables the built-in fans to automatically turn on at a certain temperature, providing continuous, reliable, and ecofriendly operation of the switch.  Energy Efficient Ethernet (EEE) standard is also supported, which helps to reduce the operating cost of the DGS-3120 Series.
	Manageability
	D-Link’s Single IP Management (SIM) simplifies and speeds up management tasks, allowing multiple switches to be configured, monitored, and maintained from any workstation running a web browser through one unique IP address. This virtual stack is managed as a single object, having all units maintained by one IP address. The DGS-3120 Series also supports standard-based management protocols such as SNMP, RMON, Telnet, Console, Web-based GUI, and SSH/SSL security authentication.
General features
		General 
	
		• Interfaces
	
		  • 20 10/100/1000BASE-T ports
	
		  • 4 Combo 10/100/1000BASE-T PoE/SFP ports
	
		  • 4 SFP+ ports
	
		• Optional Redundant Power Supply: DPS-700
	
		• Console Port: RJ-45
	
		• Management Port: 10/100BASE-T
	
		• Alarm Port: 1
	
		• SD Card Slot: 1 
	
		Performance
	
		• Switch Fabric: 128Gbps
	
		• Packet Forwarding Rate: 95.24Mpps
	
		• Packet Buffer Memory: 2MB
	
		• MAC Address Table: 16K Entries
	
		• IP v4/v6 Routing Table: 1K/512 Entries
	
		• IP v4/v6 L3 Forwarding Table: 2K/1K Entries
	
		• Jumbo Frame Size: 13000 bytes
	
		PoE
	
		PoE Standard: 802.3af and 802.3at
	
		PoE Power Budget: 370 watts (740 watts with DPS-700 RPS)
	Software Features 
	Standard Image (SI) Features 
	Stackability 
	• Physical Stacking
	  • Up to 40G Stacking Bandwidth
	  • Up to 6 units per Stack
	• Virtual Stacking:
	  • D-Link Single IP Management (SIM)
	  • Up to 32 units per Virtual Stack 
	L2 Features 
	• MAC Address Table: 16K entries 
	• Flow Control
	  • 802.3x Flow Control 
	  • HOL Blocking Prevention 
	• Jumbo Frames up to 13 Kbytes
	• 802.3ad Link Aggregation
	  • Max. 32 groups per device, 8 Gigabit ports per group 
	• Spanning Tree Protocols
	  • 802.1D STP
	  • 802.1w RSTP
	  • 802.1s MSTP
	  • BDPU Filtering
	  • Root Restriction
	• Loopback Detection
	• Port Mirroring
	  • One-to-One
	  • Many-to-One
	  • Flow-based
	  • RSPAN Mirroring
	L2 Multicasting
	• IGMP Snooping
	  • IGMP v1/v2/v3 Snooping
	  • Supports 1024 IGMP groups
	  • Port/Host-based IGMP Snooping Fast Leave
	• Limited IP Multicast
	  • Up to 24 IGMP filtering profiles, 32 ranges per profile
	• MLD Snooping
	  • MLD v1/v2 Snooping
	  • Support 1024 MLD Groups
	  • Host-based MLD Snooping Fast Leave
	VLAN
	• VLAN Group
	  • Max.4K VLAN Groups
	• GVRP
	  • Max. 255 Dynamic VLAN Groups
	• 802.1Q Tagged VLAN
	• Port-based VLAN
	• 802.1v Protocol VLAN
	• Voice VLAN
	• MAC-based VLAN
	• ISM VLAN
	• Assymetric VLAN
	• Private VLAN
	• VLAN Trunking
	QoS (Quality of Service)
	• 802.1p
	• 8 queues per port
	• Queue Handling
	  • Strict Priority
	  • Weighted Round Robin (WRR)
	  • Strict + WRR
	• Supports following actions for flows
	  • Remark 802.1p Priority Tag
	  • Remark TOS/DSCP Tag
	  • Bandwidth Control
	• CoS based on
	  • Switch Port
	  • VLAN ID
	  • 802.1p Priority Queues
	  • MAC Address
	  • IPv4 Address
	  • DSCP
	  • Protocol Type
	  • TCP/UDP Port
	  • User-Defined Packet Content
	  • IPv6 Address
	  • IPv6 Traffic Class
	  • IPv6 Flow Label
	• Bandwidth Control
	  • Port-based (Ingress/Egress, Min. Granularity 8Kbps)
	  • Flow-based (Ingress/Egress, Min. Granularity 8Kbps)
	• Three Color Marker
	  • CIR/PIR minimum granularity: 8kbps
	  • Two Rate Three Color Marker (trTCM), CBS/PBS
	  • Single Rate Three Color Marker (srTCM), CBS/EBS
	Access Control List (ACL) 
	• ACL based on
	  • 802.1p Priority
	  • VLAN ID
	  • MAC Address
	  • Ether Type
	  • IPv4 Address
	  • DSCP
	  • Protocol Type
	  • TCP/UDP Port Number
	  • User-Defined Packet Content
	  • IPv6 Address
	  • IPv6 Flow Label
	  • IPv6 Traffic Class
	  • Supports up to 1.5K Ingress access rules
	  • Time-based ACL
	  • CPU Interface Filtering
	Security
	• SSH v2
	• SSL v1/v2/v3
	• Port Security
	  • Up to 64 MAC addresses per port/VLAN
	• Broadcast/Multicast/Unicast Storm Control
	• Traffic Segmentation
	• D-Link Safeguard Engine
	• NetBIOS/NetBEUI Filtering
	• DHCP Server Screening
	• ARP Spoofing Prevention
	• DoS Attack Prevention
	• BPDU Attack Protection
	AAA
	• 802.1X
	  • Port-based Access Control
	  • Host-based Access Control
	  • Identity-driven Policy (VLAN, ACL or QoS) Assignment
	  • Authentication Database Failover
	• Web-based Access Control (WAC):
	  • Port-based Access Control
	  • Host-based Access Control
	  • Identity-driven Policy (VLAN, ACL or QoS) Assignment
	  • Authentication Database Failover
	• MAC-based Access Control (MAC):
	  • Port-based Access Control
	  • Host-based Access Control
	  • Identity-driven Policy (VLAN, ACL or QoS) Assignment
	  • Authentication Database Failover
	• Japan Web-based Access Control (Host-based JWAC)
	• Guest VLAN
	• Microsoft® NAP
	  • Support 802.1X NAP
	  • Support DHCP NAP
	• RADIUS Accounting
	• TACACS+ Accounting
	• RADIUS and TACACS authentication for switch access
	• Four levels of User Account control
	Green Features
	• Compliant with RoHS
	• Power Saving by Link Status
	• Power Saving by Cable Length
	• IEEE 802.3az Energy Efficient Ethernet (EEE)
	Operation, Administration & Management (OAM)
	• Cable Diagnostics
	Management
	• Web-based GUI
	• Command Line Interface (CLI)
	• Telnet Server
	• Telnet Client
	• TFTP Client
	• ZModem
	• SNMP v1/v2c/v3
	• SNMP Traps
	• System Log
	• RMON v1:
	  • Supports 1,2,3,9 groups
	• RMON v2:
	  • Supports ProbeConfig group
	• LLDP
	• BootP/DHCP Client
	• DHCP Auto-Configuration
	• DHCP Relay
	• DHCP Relay Option 12
	• DHCP Relay Option 82
	• Flash File System
	• Multiple Images
	• Multiple Configurations
	• CPU Monitoring
	• Debug Command
	• SNTP
	• Password Recovery
	• Password Encryption
	• Trusted Host
	• Microsoft® NLB (Network Load Balancing) Support
	• ICMPv6
	MIB
	• RFC 1213 MIB II
	• RFC 4188 Bridge MIB
	• RFC 1157, 2571-2576 SNMP MIB
	• RFC 1907 SNMPv2 MIB
	• RFC 1757, 2819 RMON MIB
	• RFC 2021 RMONv2 MIB
	• RFC 1398, 1643, 1650, 2358, 2665 Ether-like MIB
	• RFC 2674 802.1p MIB
	• RFC 2233, 2863 IF MIB
	• RFC 2618 RADIUS Authentication Client MIB
	• RFC 2620 RADIUS Accounting Client MIB
	• RFC 2925 Ping & Traceroute MIB
	• RFC 2674, 4363 802.1p MIB
	• RFC1065, 1066, 1155, 1156, 2578 MIB Structure
	• RFC 1215 MIB Traps Convention
	• RFC1212 Concise MIB Definitions
	• RFC1215 MIB Traps Convention
	• RFC1157, 2571-2576 SNMP MIB
	• RFC4022 MIB for TCP
	• RFC4113 MIB for UDP
	• RFC4293 IPv6 SNMP Mgmt Interface MIB
	RFC Standard Compliance 
	• RFC 768 UDP
	• RFC 791 IP
	• RFC 792, 2463, 4443 ICMP
	• RFC 793 TCP
	• RFC 826 ARP
	• RFC 3513, 4291, IPv6 Addressing Architecture
	• RFC 2893, 4213 IPv4/IPv6 dual stack function
	• RFC 2463, 4443 ICMPv6
	• RFC 2462, 4862 IPv6 Stateless Address Auto
	• RFC 2462, 4862 IPv6 Stateless Address Auto Configuration
	• RFC 2464 IPv6 Ethernet and definition
	• RFC 1981 Path MTU Discovery for IPv6
	• RFC 2460 IPv6
	• RFC 2461, 4861 Neighbor Discovery for IPv6
	• RFC 783 TFTP
	• RFC 2068 HTTP
	• RFC 1492 TACACS
	• RFC 2866 RADIUS Accounting
	• RFC 2474, 3260 DiffServ
	• RFC 1321, 2284, 2865, 3580, 3748 Extensible
	• Authentication Protocol (EAP)
	• RFC 2571, 2572, 2573, 2574, SNMP
	• IPv6 Ready Logo Phase 2
	• RFC 854 Telnet
	• RFC 951, 1542 BootP
	Authentication Protocol (EAP)
	• RFC 2571, 2572, 2573, 2574, SNMP
	• IPv6 Ready Logo Phase 2
	Enhanced Image (EI) Features 
	L2 Features 
	• Ethernet Ring Protection Switching (ERSP)
	VLAN
	• Double VLAN (Q-in-Q)
	  • Port-based Q-in-Q
	L3 Features
	• Max. 16 IP Interfaces
	• ARP Proxy
	• IPv6 Neighbour Discovery (ND)
	L3 Routing
	• Static Route
	  • 512 static routing entries for IPv4/IPv6
	Access Control List (ACL)
	• Supports up to 512 egress access rules
	Security
	• IP-MAC-Port Binding
	• ARP Packet Inspection
	• IP Packet Inspection
	• DHCP Snooping
	• IPv6 ND Snooping
	• Support up to 510 Address Binding Entries per Device
	AAA
	• Compound Authentication
	Operation, Administration & Management (OAM)
	• 802.3ah Ethernet Link OAM
	• 802.3ah D-Link Extension: D-link Unidirectional Link Detection (DULD)
	• 802.1ag Connectivity Fault Management (CFM)
	• ITU-T Y.1731
	Management
	• sFlow
	• PPPoE Circuit-ID Tag Insertion 
Certificates
Order info
DGS-3420-28PC xStack L2+ Managed Stackable Gigabit Switch with 20 ports 10/100/1000BASE-T, 4 Combo 10/100/1000BASE-T PoE/SFP ports and 4 ports SFP+

