| Item | Features | 
                
                
                  
                    | Standard Compliance | 
                        
                          IEEE 802.3u 100BASE-TX Ethernet*IEEE 802.3ab 1000BASE-T Ethernet*IEEE 802.3z 1000BASE-X*IEEE 802.3af PoE*IEEE 802.3at PoE plus*IEEE 802.3az EEE*IEEE 802.3x flow control* (support on Nebula Cloud mode from ZyNOS 5.00)IEEE 802.1AB LLDP/LLDP-MEDIEEE 802.3ad LACP aggregation*IEEE 802.1D Spanning Tree Protocol (STP)*IEEE 802.1w Rapid Spanning Tree Protocol (RSTP)*IEEE 802.1s Multiple Spanning Tree Protocol (MSTP)IEEE 802.1Q VLAN tagging*IEEE 802.1p Class of Service (CoS) prioritization*IEEE 802.1X port authentication* | 
                
                
                  
                    | Resilience and Availability | 
                        
                          IEEE 802.1D Spanning Tree Protocol (STP)*IEEE 802.1w Rapid Spanning Tree Protocol (RSTP)*IEEE 802.1s Multiple Spanning Tree Protocol (MSTP)IEEE 802.3ad LACPLoop guard*Root guard*BPDU guard*ErrDisable recoveryMRSTP (Zyxel Proprietary)Dual configuration filesDual images*Flex link | 
                
                
                  
                    | Traffic Control | 
                        
                          802.1Q static VLANs*/dynamic VLANs: 1 K/4 KPort-based VLANProtocol-based VLANIP subnet-based VLANMAC-based VLANPrivate VLANVoice VLAN*Vendor ID based VLAN*VLAN ingress filtering*LACP algorithm of source/ destination IP or MAC*GVRPL2PT | 
                
                
                  
                    | Security | 
                        
                          Port security*Layer 2 MAC filtering*Layer 3 IP filteringLayer 4 TCP/UDP socket filteringStatic MAC forwardingMultiple RADIUS servers (IPv4*/IPv6)Multiple TACACS+ serversCompound authentication802.1x VLAN* and 802.1p assignment by RADIUSLogin authentication by RADIUSLogin authentication by TACACS+TACACS+ accountingRADIUS accountingAuthorization on RADIUSAuthorization on TACACS+SSH v2*SSLMAC freezeDHCP snooping IPv4DHCP snooping IPv6ARP inspectionStatic IP-MAC-Port bindingPolicy-based security filteringPort isolation*IP source guard (IPv4*/IPv6)MAC search*Guest VLAN*ACL packet filtering* (IPv4)CPU protectionInterface related trap enable disable (by port)MAC-based authentication per VLANNew for ZyNOS 5.00 Password encryptionNew for ZyNOS 5.00 Password complexityNew for ZyNOS 5.00 Brute-force attack protectionNew for ZyNOS 5.00 SSH public key authentication | 
                
                
                  
                    | Quality of Service (QoS) | 
                        
                          No. of hardware queues per port: 8*Storm control and event log: Broadcast, multicast, unknown unicast (DLF)*Port-based rate limiting* (ingress/ egress)Rate limiting per IP/TCP/UDP per portPolicy-based rate limiting802.1p Class of Service (SPQ, WFQ, WRR, hybrid-SPQ combination capable)DiffServ (DSCP) | 
                
                
                  
                    | Layer 2 Multicast | 
                        
                          L2 multicast*IGMP snooping (v1, v2, v3)*IGMP snooping fast leave*Configurable IGMP snooping timer and priority*IGMP snooping statistics*IGMP throttling*MVR supportIGMP filtering*IGMP snooping immediate leave*IGMP proxy mode & snooping mode selection*MLD snooping | 
                
                
                  
                    | Manageability | 
                        
                          SNMP* v1, v2c, v3SNMP trap groupRMON (1, 2, 3, 9)ICMP echo/echo replySyslog*IEEE 802.1AB LLDP*IEEE 802.1AB LLDP-MED*Custom defaultDisplay port utilization*Support NebulaFlex Pro for Cloud ManagementNew for ZyNOS 5.00 DHCP relay option 82*New for ZyNOS 5.00 SSH Remote Command ExecutionDHCP relay per VLANDHCP server guardDHCP smart relay | 
                
                
                  
                    | IPv6 Management | 
                        
                          IPv6 over Ethernet (RFC 2464)IPv6 addressing architecture (RFC 4291)Dual stack (RFC 4213)ICMPv6 (RFC 4443)Path MTU (RFC 1981)Minimum path MTU size of 1280 (RFC 5095)Encapsulation for maximum PMTU of 1500Neighbor discovery (RFC 4861)DHCPv6 relayDefault DHCP client mode* | 
                
                
                  
                    | Device Management | 
                        
                          Cloud management by Nebula Control Center*Zyxel iStackingTMWeb interfaceManagement through Web interface, Console, Telnet, SNMPRemote firmware upgrade by FTP/ Web/TFTPNetworked AV mode by Web InterfaceNew for ZyNOS 5.00 Optimized Dante and AES67 in Networked AV modeConfiguration saving and retrieving*Multiple logins supportedConfigure clone*Multilevel CLI*CLI (Cisco-like)DHCP server guardDHCP client IPv4*DHCP client IPv6DHCP option 82Auto PD Recovery*Daylight saving*NTP supports IPv4/IPv6Port mirroring*RS-232 out-of-band console portScheduled PoE*PoE default consumption mode*Restore to last custom defaultNew for ZyNOS 5.00 SSH Remote Command ExecutionAuto configuration recovery (only for cloud mode) | 
                
                
                  
                    | MIB | 
                        
                          Zyxel Private MIBZyxel Common MIBRFC 1066 TCP/IP-based MIBRFC 1213, 1157 SNMPv2c/v3 MIBRFC 1493 bridge MIBRFC 1643 Ethernet MIBRFC 1757 RMON group 1, 2, 3, 9RFC 2011, 2012, 2013 SNMPv2 MIBRFC 2233 SMIv2 MIBRFC 2358 Ethernet-like MIBRFC 2674 bridge MIB extensionRFC 2819, 2925 remote management MIBRFC 3621 power Ethernet MIBRFC 4022 management information base for transmission control protocolRFC 4113 management information base for user datagram protocolRFC 4292 IP forwarding table MIBRFC 4293 Management Information Base (MIB) for IPCable diagnostic MIB | 
                
                
                  
                    | Certifications | 
                        Safety EMC 
                          FCC Part 15 (Class A)CE (Class A)BSMI ENC RoHS | 
                
                
                  
                    | Zyxel One Network | 
                        ZON Utility *
                         
                          Discovery of Zyxel switches, APs and gatewaysCentralized and batch configurations 
                              IP configurationIP renewDevice factory resetDevice rebootDevice locatingWeb GUI accessPassword configurationOne-click quick association with Zyxel AP Configurator (ZAC)Automatic detection of the latest firmwareDisplays device serial number and hardware versionCloud mode on/off option for Hybrid series devicesIntuitive Cloud connection status Smart Connect 
                          Discover neighboring devicesOne-click remote management access to the neighboring Zyxel devicesReset neighboring devices remotely to factory defaultsPower cycle neighboring powered devices (PoE switches only) | 
                
                
                  
                    | Limited life-time warranty | 
                        
                          Warranty terms, service availability, and service response times may vary from country or region to country or region | 
                
              
             
           
         
       
     
   
 
  
  All specifications are subject to change without notice.
 *Nebula Cloud and Standalone modes supported features. Some Nebula features may need an extra license to work. For more details on the features and licenses, check Nebula Licensing Table.