xStack L2+ Managed Stackable Gigabit Switch with 20 SFP ports, 4 combo 10/100/1000Base-T/SFP ports and 4 SFP+ ports


The xStack DGS-3420 Series of next generation Layer 2+ Gigabit switches deliver performance, flexibility, security, multi-layer QoS, and accessibility, along with redundant power solutions for SMBs and enterprises. With high Gigabit port densities, Gigabit SFP, 10-Gigabit SFP+ support, and advanced software solutions, these switches can act as either departmental access layer devices or aggregation switches to form a multilevel network structured with backbone and centralized high-speed servers.
Service providers can take advantage of the high SFP density switches (such as DGS-3420-28SC/26SC) to structure the aggregation of Fiber to the Building (FTTB) networks that are extended to the subscribers’ sites.
Unparalleled Flexibility
Easily deployed and simple to manage, the DGS-3420 can be stacked with any switch that supports D-Link’s Single IP Management to form a multi-level network structured with backbone and centralized high-speed servers. The virtual stack can include units located anywhere on the same network domain, and uses optional 10-Gigabit uplinks to move intra-stack traffic at 20Gbps full duplex speeds.
Redundant Ring Stacking
Alternatively, depending on whether linear or fault-tolerant ring stacking is implemented, users can use one or two 10-Gigabit SFP+ ports to create a physical stack. 12 units or 576 Gigabit ports can be configured for a stack using direct attach cables to provide high-bandwidth on the DGS-3420 Series with cost efficiency.
Security, Performance & Availability
The DGS-3420 Series provides a complete set of security features including L2/L3/L4 multi-layer Access Control Lists and 802.1X user authentication via TACACS+ and RADIUS servers.
The DGS-3420 Series offers extensive VLAN support including GVRP and 802.1Q VLAN to enhance security and performance. A robust set of L2/L3/L4 QoS/CoS solutions help ensure that critical network services such as VoIP, ERP, Intranet, and video conferencing are served with proper priority. The series also provides D-Link’s Safeguard Engine to increase the switch’s reliability, serviceability, and availability to prevent malicious flooding traffic caused by worms or virus infections. Bandwidth Control can be flexibly set for each port using pre-defined thresholds to assure a committed level of service for end users. For advanced applications, flow-based bandwidth control allows easy fine-tuning of service types based on specific IP addresses or protocols.
IPv6 Technology
The DGS-3420 Series also features comprehensive IPv6 support, including IPv6 Tunnel, ICMPv6, DHCPv6, RIPng, and more. With 10-Gigabit connectivity and IPv6 support, the series enables you to future-proof your network for cost efficiency and longevity while meeting the requirements that future IPv6 capable network devices require.
D-Link Green Technology
D-Link is striving to take the lead in developing innovative and power-saving technology that does not sacrifice operational performance or functionality. The DGS-3420 Series implements D-Link Green technology, which includes a power saving feature, smart fan design, reduced heat dissipation, and cable length detection. The power saving feature automatically powers down ports that have no link or link partner. The Smart Fan design allows the built-in fans to automatically turn on only at a certain temperature, providing continuous, reliable and eco-friendly operation of the switch.

General features

• 20 SFP ports
• 4 Combo 10/100/1000BASE-T/SFP ports
• 4 SFP+ ports
• 1 Alarm Port
• 1 SD Card Slot
Optional Redundant Power Supply
Console Port
Management Port
• Switching Capacity: 128Gbps
• Packet Forwarding Rate: 95.24Mpps
• Packet Buffer: 2MB
• MAC Address Table: 16K Entries
• IP v4/v6 Routing Table: 1K/512 Entries
• IP v4/v6 L3 Forwarding Table: 2K/1K Entries
• Jumbo Frame Size: 13Kbytes
• Virtual Stacking
- D-Link Single IP Management (SIM)
- Up to 32 units per Virtual Stack
- Up to 20G stacking bandwidth
• Physical Stacking
- Supports Duplex Chain/Ring topology
- Up to 40G stacking bandwidth
- Up to 12 units per stack
L2 Features
• MAC Address Table: 16K
• Flow Control
- 802.3x Flow Control
- HOL Blocking Prevention
• Jumbo Frames up to 13K Bytes
• IGMP snooping
- IGMP v1/v2/v3 Snooping
- Supports 960 groups
- Host/port-based Fast Leave
• MLD Snooping
- MLD v1/v2 Snooping
- Supports 480 groups
- Host-based MLD Snooping Fast Leave
• Spanning Tree
- 802.1D-2004 STP
- 802.1w RSTP
- 802.1Q-2005 MSTP
- BPDU filtering
- Root Restriction
• Loopback Detection
• 802.3ad Link Aggregation
• Max. 32 groups per device
- 8 Gigabit ports or 2 10 Gigabit ports per group
• Port Mirroring
- Support 4 Mirroring Groups
- Support One-to-One, Many-to-One, Flow-based, and RSPAN mirroring
• L2 Protocol Tunneling
• ERPS (Ethernet Ring Protection Switching)
• VLAN Group
- Max. 4K Static VLAN Groups
- Max. 255 Dynamic VLAN Groups
• 802.1Q Tagged VLAN
• 802.1v Protocol VLAN
• Double VLAN (Q-in-Q)
- Port-based Q-in-Q
- Selective Q-in-Q 2
• MAC-based VLAN
• VLAN Trunking
• 802.1Qbb 2
L3 Features
• 256 IP interfaces
• Loopback Interface
• IPv6 Tunneling
• Proxy ARP
• Gratuitous ARP
L3 Routing
• 1K routing entries shared by IPv4/v6
- Max. 1K IPv4 routes
- Max. 512 IPv6 routes
• 2K L3 forwarding entries shared by IPv4/v6
- Max. 2K IPv4 entries
- Max. 1K IPv6 entries
• 256 static routing entries for IPv4, 128 entries for IPv6
• RIP v1/v2
• RIPng
QoS (Quality of Service)
• 802.1p Class of Service (CoS)
• 8 Queues per Port
• Queue Handling
- Strict Priority
- Weighted Round Robin (WRR)
- Strict + WRR
• CoS based on
- Switch Port
- 802.1p Priority Queues
- MAC Address
- IPv4/v6 Address
- Protocol Type
- IPv6 Traffic Class
- IPv6 Flow Label
- TCP/UDP Port
- User-defined Packet Content
• Supports following actions for flows:
- Remark 802.1p Priority Tag
- Remark TOS/DSCP Tag
- Bandwidth Control
- Flow Statistics
- Committed Information Rate (CIR), min. granularity 1Kbps
• Bandwidth Control
- Port-based (Ingress/Egress, min. granularity 64Kbps)
- Flow-based (Ingress, min. granularity 64Kbps)
• Time-based QoS
Access Control List (ACL)
• Ingress ACL: support up to 6 profiles and 256 rules per profile
• Egress ACL: support up to 4 profiles and 128 rules per profile
• ACL based on
- 802.1p Priority
- MAC Address
- Ether Type
- IPv4/IPv6 Address
- Protocol Type
- TCP/UDP Port Number
- IPv6 Traffic Class
- IPv6 Flow Label
- User-defined Packet Content
• ACL Statistics
• Time-based ACL
• CPU Interface Filtering
• SSH v2
• SSL v1/v2/v3
• Port Security up to 64 MAC addresses per port
• Broadcast/Multicast/Unicast Storm Control
• Traffic Segmentation
• IP-MAC-Port Binding
- ARP Packet Inspection
- IP Packet Inspection
- DHCP Snooping
- DHCPv6 and NDP Snooping
- Supports up to 500 Address Binding Entries per device
• D-Link Safeguard Engine
• DHCP Server Screening
• CPU Interface Filtering
• ARP Spoofing Prevention
• BPDU Attack Protection
• 802.1X
- Port-based Access Control
- Host-based Access Control
- Dynamic VLAN Assignment
• Web-based Access Control (WAC)
- Port-based Access Control
- Host-based Access Control
- Dynamic VLAN Assignment
• MAC-based Access Control (MAC)
- Port-based Access Control
- Host-based Access Control
- Dynamic VLAN Assignment
• Japan Web-based Access Control (Host-based JWAC)
- Host-based Access Control
• Microsoft®NAP
- 802.1X NAP support
- DHCP NAP support
• Guest VLAN
• RADIUS and TACACS+ authentication for switch access
• 4-Level user account
• Web-based GUI
• Command Line Interface (CLI)
• Telnet Server
• Telnet Client
• TFTP Client
• ZModem
• SNMP v1/v2c/v3
• SNMP Traps
• System Log
• RMON v1
- Supports 1,2,3,9 groups
• RMON v2
- Supports ProbeConfg Group
• sFlow
• BootP/DHCP Client
• DHCP Auto-Configuration
• DHCP Relay
• DHCP Relay Option 60, 61, 82
• DHCP Server
• Flash File System
• Multiple Images
• Multiple Configurations
• CPU Monitoring
• Debug Command
• ICMPv6
• DHCPv6 Client
• DHCPv6 Relay
• DHCPv6 Server
• Trusted Host
• MTU Setting
• Microsoft®NLB Support
• UDP helper
• 802.3ah Ethernet Link OAM
• 802.3ah D-Link Extension: D-Link
Unidirectional Link Detection (DULD)
• IEEE1588 Precision Time Protocol (PTP)
• Cable Diagnostics
• Connectivity Fault Management (CFM)
• ITU-T Y.1731
• Power saving by Link Status
• Power saving by Cable Length
• Time-based PoE
MIB/IETF Standards
• RFC1213 MIB-II
• RFC1493 Bridge MIB
• RFC1907 SNMPv2 MIB
• RFC2571~2576 SNMP MIB
• RFC1271, 2819 RMON MIB
• RFC2021 RMON v2 MIB
• RFC2665 Ether-like MIB
• RFC2674 802.1p MIB
• RFC2233, 2863 IF MIB
• RFC2618 RADIUS Authentication Client MIB
• RFC1724 RIP v2 MIB
• RFC2096 IP Forwarding Table MIB (CIDR)
• RFC2620 RADIUS Accounting Client MIB
• Ping MIB
• Traceroute MIB
• D-Link Private MIB
• RFC768 UDP
• RFC 791 IP
• RFC 793 TCP
• RFC 826 ARP
• RFC854 Telnet
• RFC951, 1542 BootP
• RFC2068 HTTP
• RFC3056, 5214 IPv6 Tunnel
• RFC2139 RADIUS Accounting
• RFC3176 sFlow
• RFC2598 DiffServ Expedited Forwarding


Order info

DGS-3420-28SC xStack L2+ Managed Stackable Gigabit Switch with 20 SFP ports, 4 combo 10/100/1000Base-T/SFP ports and 4 SFP+ ports


Front view
Back view


Support Resources