DP420

The DP418G/420G-16GP and DS418G/420G are industrial Layer 2+ switches designed for essential applications in industrial automation, surveillance, and edge networks. The DP418G/420G-16GP features 16 Gigabit PoE+ ports and 2/4 100M/1G/2.5G SFP uplinks, while the DS418G/420G offers the same 18/20-port configuration without PoE. Both models support Surveillance VLAN, LLDP-MED, VLANs, ACL/QoS, and core security functions, ensuring optimized network performance and control. ERPS and STP/RSTP/MSTP provide network redundancy to maintain uninterrupted operation. With intuitive management via Web GUI, CLI, SNMP, and Telnet, and rugged features such as metal housing, IP40 protection, 6KV surge immunity, dual DC power input, and fan less operation, the DP418G/420G-16GP and DS418G/420G deliver stable, high-speed connectivity for diverse lite industrial deployments—with or without PoE.
Inquiry cart

High Throughput Ethernet Switching & Extreme 802.3at PoE+ Capacity
・18/20-port  with 16-port GbE RJ45, and 2/4-Port 100M/1G/2.5G SFP Ports
・ 16-port PoE 802.3af/at 30W per port, total 300W
・Energy-Efficient Ethernet for power saving
・Non-blocking switch fabric design
・8 flexible Class of Service(CoS) queues, 1K  
   Multicast Groups for video applications
・16K MAC address table, 10KB Jumbo Frame
・PoE management including per-port PoE Status,
   PoE Scheduling

 

Industrial Design
 

•Enhanced Protection: Service ports include 6KV anti-surge protection, overload safeguards for secure use.
•Durable Build: Aluminum alloy shell ensures excellent heat dissipation, interference shielding, rust resistance, and long-lasting durability.
•Flexible Power Options: Dual DC redundant power supply (DC48-58V) meets industrial wide-voltage requirements.
•Industrial Design: IP40-rated, DIN35 rail mounting, and wide temperature range (-25°C to +60°C) provide stability in harsh environments.

Cyber Security
・MAC/IPv4/IPv6 Access Control List (ACL)
・DHCP Snooping, IP Source Guard, Dynamic ARP Inspection
・802.1Q VLAN, Port Security
・ Multi-Level user passwords
・ TACACS+, IEEE 802.1X, SNMPv3, HTTPS, and SSH
    to enhance network security
・ 802.1X MAB for non-802.1X compliant end devices
・ RADIUS/TACACS+ centralized password authentication

ITU-T G.8032 v2 ERPS Ring Redundancy
•ITU-T G.8032 v1/v2 ERPS Standard Ring Redundancy protocol
•Less than 50ms recovery time, seamless restoration time
•Inter-Operability with 3rd party industrial switch and still remain fast recovery time
•Replace Ring + Chain + Dual Homing

Industrial Grade Management
・Various configuration paths, including WebGUI, CLI,
    SNMP and RMON
・ Command line interface (CLI) for quickly configuring major
    managed functions
・ SNMPv1/v2c/v3 for different levels of network management
・ RMON enables proactive monitoring, real-time insights, and efficiency.
・Surveillance VLAN simplify the deployment of network security monitoring systems by isolating monitoring traffic from data traffic, while improving security and improving network performance.
・ LLDP and LLDP-MED enhance device discovery, automate network configuration, improve interoperability, and support location-based services.

 

ITU-T G.8032 ERPSv2 gives ultimate Inter-Operability, Flexibility, and Scalability




G.8032 v.2 ERPS is becoming the most common standard for redundancy on industrial networks and replacing proprietary ring redundancy and standard Ethernet Ring Switching, as it provides stable protection of the entire Ethernet Ring from any loops and open standard for 3rd party devices. The ITU-T G.8032 v2 ERPS recovers the network break within less than 50ms recovery time thus significantly increases network reliability for critical IIoT applications, such as heavy industrial automation (power substation and oil and gas vertical markets), ITS (traffic control, public transportation), railway networks, and other smart city applications concerning public safety.

 








G.8032 v1 only supports single ring topology, whilst G.8032 version 2 additionally features recovery switching for Ethernet traffic in Multiple Ring (ladder) of conjoined Ethernet Rings by one or more interconnections which saves deployment costs by providing wide-area multipoint connectivity with a reduced number of links. Deploying switches with support of G.8032 v2 ERPS ensures highly resilient Ethernet infrastructure whilst simultaneously saving costs, as they can interoperate with third-party switches and still guarantee fast network recovery time without any data loss.



 

√ ITU-T G.8032 ERPSv2 reduces coupling Ring failure recovery time

The G.8032 ERPS v2 technology effectively saves the recovery time for coupling ring link breakdown from 300 sec to less than 50ms by immediately change the topology of both major ring and subring.  
       

 

√ WoMaster ERPS v2 PLUS Technology – Fast Giga Copper Recovery Time

The adaption of Broadcom® CFM Technology can reduce CFM Transmission for link failure within 3.3ms, thus to detect the ring link fault within 11.55ms (3.5 times the CFM Interval) for ERPSv2 mechanism to respond. Once the ring port fails, the ERPS RPL-Owner will forward the backup port and recover the GbE copper within 50ms under the condition that 250pcs nodes in one ring
​.
          

√ Advanced Port Based Security- IEEE802.1 x MAB (MAC Authentication Bypass)​

MAB enables port-based access control by bypassing the MAC address authentication process to TACACS+/Radius Server. Prior to MAB, the endpoint's (ex. PLC) identity is unknown and all traffic is blocked. The switch examines a single packet to learn and authenticate the source MAC address. After MAB succeeds, the endpoint's identity is known and all traffic from that endpoint is allowed. The switch performs source MAC address filtering to help ensure that only the MAB-authenticated endpoint is allowed to send traffic.

        
In addition to MAB, the authentication can also be done by the pre-configured static or auto-learn MAC address table in the switch.
  • MAC address Auto Learning enables the switch to be programmed to learn (and to authorize) a preconfigured number of the first source MAC addresses encountered on a secure port. This enables the capture of the appropriate secure addresses when first configuring MAC address-based authorization on a port. Those MAC addresses are automatically inserted into the Static MAC Address Table and remained there until explicitly removed by the user.
  • The port security is further enhanced by the Sticky MAC setting. If Sticky MAC address is activated, the MACs/Devices authorized on the port 'sticks’ to the port and the switch will not allow them to move to a different port.
  • Port Shutdown Time allows users to specify for the time period to auto shutdown the port if a security violation event occurs.
           

 DHCP Snooping

DHCP snooping acts like a firewall between untrusted hosts and trusted DHCP servers. It performs the following activities:

  • Validates DHCP messages received from untrusted sources and filters out invalid messages.
  • Rate-limits DHCP traffic from trusted and untrusted sources.
  • Builds and maintains the DHCP snooping binding database, which contains information about untrusted hosts with leased IP addresses.
  • Utilizes the DHCP snooping binding database to validate subsequent requests from untrusted hosts.

DHCP snooping is enabled on a per-VLAN basis. By default, the feature is inactive on all VLANs. You can enable the feature on a single VLAN or a range of VLANs.
cccccccccc



 Dynamic ARP Inspection (DAI)



DAI validates the ARP packets in a network. DAI intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings. This capability protects the network from some man-in-the-middle attacks.

DAI ensures that only valid ARP requests and responses are relayed. The switch performs these activities:
  • Intercepts all ARP requests and responses on untrusted ports
  • Verifies that each of these intercepted packets has a valid IP-to-MAC address binding before updating the local ARP cache or before forwarding the packet to the appropriate destination
  • Drops invalid ARP packets.
DAI determines the validity of an ARP packet based on valid IP-to-MAC address bindings stored in a trusted database, the DHCP snooping binding database. This database is built by DHCP snooping if DHCP snooping is enabled on the VLANs and on the switch. If the ARP packet is received on a trusted interface, the switch forwards the packet without any checks. On untrusted interfaces, the switch forwards the packet only if it is valid.





​√ IP Source Guard


IP source guard provides source IP address filtering on a Layer 2 port to prevent a malicious host from impersonating a legitimate host by assuming the legitimate host's IP address. The feature uses dynamic DHCP snooping and static IP source binding to match IP addresses to hosts on untrusted Layer 2 access ports.

Initially, all IP traffic on the protected port is blocked except for DHCP packets. After a client receives an IP address from the DHCP server, or after static IP source binding is configured by the administrator, all traffic with that IP source address is permitted from that client.

Traffic from other hosts is denied. This filtering limits a host's ability to attack the network by claiming a neighbor host's IP address.

 
 

√ Effective PoE Management

 






The Web GUI shows detailed PoE status and the operating status of each PoE Port, including PoE mode, Operation status, and PD class, Power Consumption, Voltage,
 and Current.

The PoE switch can effectively maintain the PD’s status by sending requests to the powered device. If the PoE device does not echo the request, then the PoE port will be shut down to reboot the device. The scheduling can also be configured for better organizing the PoE power forwarding.





                       


 
 
 
Specifications
 Technology
Standard IEEE 802.3u 100Base-TX Fast Ethernet 
IEEE 802.3u 100Base-FX Fast Ethernet Fiber
IEEE 802.3ab 1000Base-T Gigabit Ethernet copper
IEEE 802.3z Gigabit Ethernet Fiber
IEEE 802.3x Flow Control and back-pressure 
IEEE 802.3az (Energy Efficient Ethernet)
IEEE 802.1p Class of Service (CoS) 
IEEE 802.1Q VLAN and GVRP
IEEE 802.1AB Link Layer Discovery Protocol(LLDP)  
IEEE 802.1D-2004 Rapid Spanning Tree Protocol(RSTP) 
IEEE 802.1S Multiple Spanning Tree Protocol (MSTP)
IEEE 801.1AX/802.3ad Link Aggregation Control Protocol (LACP)
IEEE 802.1x Port based Network Access Protocol
IEEE 1588 Precision Time Protocol v2
ITU-T G.8032 version 2 Ethernet ring protection switching(ERPSv2)

IEEE 802.3af/at Power-over-Ethernet  

 Performance
Switch Technology

Store and Forward Technology with Non-Blocking Switch Fabric

Number of MAC Address 16K

Packet Forwarding

Cache

50.59Mbps

Jumbo Frame 10K Bytes

Transfer performance

Backplane Bandwidth: 68 Gbps

 Interface
Ethernet Port 16 x 100/1000Base-T RJ45 Auto Negotiation, Auto MDI/MDIX, 802.3at/af PoE+ PSE port
2 / 4 x 100/1G/2.5G SFP (by Software Configuration)
System LED

1 x Power,:Green ON(Power is on)

1 x SYS:Green Blinking (System is ready)

Ethernet Port LED

PoE Port:Link (Green On), Activity (Green Blinking),Powering(Amber On)

non PoE:Link (Green On), 10/100M(Amber Off), 1000M(Amber Off), Activity (Green Blinking)

SFP LED

Link (Green On), Activity (Green Blinking)

Reset

Default Settings Reset(over 7 Seconds)

Console

3-pin TX/RX/GND

Relay Output

2-pin F1/F2

Power Input

3-pin P1+/P1P2- / P2+

 Power Requirement
Input Voltage

Non PoE:DC12-58V (DS418G/DS420G)

PoE:DC48-58V (DP418G-16GP/DP420G-16GP)

Reverse Polarity Protect Yes
Power Consumption

Non PoE < 26W (DS418G/DS420G)

PoE < 386W (DP418G-16GP/DP420G-16GP)

 PoE 
Power forwarding mode Alternative A
PoE Power Budget

System: Up to 300W@54Vin
Port 1~16: IEEE 802.3at/af, Max. 30W/port

PoE Mode

IEEE 802.3af/at

Management

System/Port Power Budget Control, PoE Scheduling, PD Alive Check, PoE Status

 Software
Management  

Web-based, CLI command line (Console, Telnet), SNMP (V1/V2c/V3), HTTP, TFTP file upload/download, RMON 1, 2, 3 and 9 groups, one key to restore factory settings

NTP clock and local clock, local logs and system logs (SYSLOG), Ping detection, cable status checking, instant CPU utilization status, Link Layer Discovery Protocol LLDP, NMS (LLDP+SNMP)

DHCP

DHCP Server, DHCP Client, DHCP Snooping v1/v2/v3

IGMP IGMP Snooping
VLAN port-based VLANs (4K),IEEE802.1q VLANs, protocol-based VLANs
Access, Trunk, and Hybrid port configurations.
Link Aggregation up to 64 aggregation groups
Redundancy STP/RSTP/MSTP/ERPS v2
QoS

port-based, 802.1P and DSCP/ToS prioritization, and supports 8 output queues per port. Four priority scheduling modes: Equ, SP, WRR, SP+WRR.
Priority Mark/Remark, Flow-based rate limiting, packet filtering, redirection

Security

Hierarchical management and password protection, Port-based IEEE802.1X authentication

AAA & RADIUS with TACACS+ authentication, MAC address learning number limit, MAC address blacklist, address binding, SSH 2.0 encrypted channel for user login, Port isolation, ARP message speed limit function, IP source address protection, ARP intrusion detection, Anti-DoS attacks, Port broadcast message suppression, Host data backup/restore mechanism, IP+MAC+VLAN+Port Quad Binding 

ACL

L2 to L4 packet filtering function and provides ACLs defined based on source MAC address, destination MAC address, source IP address, destination IP address, IP protocol type, TCP/UDP port, TCP/UDP port range, VLAN, etc. Port-based and VLAN-based ACL issuance

Redundancy
WoMaster ERPSv2 PLUS, HW CFM, Rapid Spanning Tree Protocol includes STP/RSTP/MSTP, eRSTP, Loop Protection, Port Trunk/801.1AX/802.3ad LACP
eRSTP (Enhanced Rapid Spanning Tree), up to 80 switches in one Ring
MIB ERPS MIB, MIB-II, Ethernet-like MIB*, P-BRIDGE MIB, Q-BRIDGE MIB, Bridge MIB, RMON MIB Group 1, 2, 3, 9*, Private MIB
 Mechanical
Installation DIN Rail
Enclosure Material System: Up to 300W@54Vin
Port 1~16: IEEE 802.3at/af, Max. 30W/port
Dimension

75X104X143mm

Ingress Protection IP40
Weight 0.8kg without package (TBD)
Packing 20pcs(220*172*100mm) per carton (520*360*460mm), total 20KG
 Environmental
Operating Temperature & Humidity -40°C~70°C , 0%~95% Non-Condensing
Storage Temperature -40°C~85°C
MTBF >200,000 hours
Warranty 5 years
 Standard

Surge Protection of Power

IEC 61000-4-5  Level X(6KV/6KV)(1.2/50us)

Surge Protection of Ethernet

IEC 61000-4-5  Level 4(4KV/4KV)(10/700us)

ESD

IEC 61000-4-2  Level 4(8K/15K)

RS IEC 61000-4-3  Level 3(10V/m)
EFI IEC 61000-4-4  Level 3(1V/2V)
CS IEC 61000-4-6  Level 3(10V/m)
PFMF IEC 61000-4-8  Level 4(30A/m)
DIP IEC 61000-4-11  Level 3(10V)

Ordering Information
 Model Name
DP418G-16GP Din-rail 18-port L2+ Managed PoE Switch with 16xGiga PoE and 2x100M/1G/2.5G SFP  , Dual 48-58VDC Power Input

DP420G-16GP Din-rail 20-port L2+ Managed PoE Switch with 16xGiga PoE and 4x100M/1G/2.5G SFP  , Dual 48-58VDC Power Input
DS418G Din-rail 18-port L2+ Managed PoE Switch with 16xGiga and 2x100M/1G/2.5G SFP, Dual 12-58VDC Power Inputs
DS420G Din-rail 20-port L2+ Managed PoE Switch with 16xGiga and 4x100M/1G/2.5G SFP, Dual 12-58VDC Power Inputs
Package List
1 x Product Unit (Without SFP transceiver)
1 x 8-pin Removable Terminal Block Connector
1 x Attached Din Clip
1 x Quick Installation Guide
 
Optional Accessory
 Item
MK-D1-2 Wall-mounting kit with 2 plates and 8 screws
CBL-RJ45F9-1.5M Serial RS232 console cable RJ45 to DB9 Female 1.5 Meter
SFPGEM05 SFP, 1000Mbps, LC, multi, 550M, 0~70°C
SFPGEM05T SFP, 1000Mbps, LC, multi, 550M, -40~85°C
SFPGEM05D SFP, 1000Mbps, LC, multi, DDM, 550M, 0~70°C
SFPGEM05DT SFP, 1000Mbps, LC, multi, DDM, 550M, -40~85°C
SFPGEM2 SFP, 1000Mbps, LC, multi, 2KM, 0~70°C
SFPGEM2T SFP, 1000Mbps, LC, multi, 2KM, -40~85°C
SFPGEM2D SFP, 1000Mbps, LC, multi, DDM, 2KM, 0~70°C
SFPGEM2DT SFP, 1000Mbps, LC, multi, DDM, 2KM, -40~85°C
SFPGES10 SFP, 1000Mbps, LC, single, 10KM, 0~70°C
SFPGES10T SFP, 1000Mbps, LC, single, 10KM, -40~85°C
SFPGES10D SFP, 1000Mbps, LC, single, DDM, 10KM, 0~70°C
SFPGES30 SFP, 1000Mbps, LC, single, 30KM, 0~70°C
SFPGES30T SFP, 1000Mbps, LC, single, 30KM, -40~85°C
SFPGES30D SFP, 1000Mbps, LC, single, DDM, 30KM, 0~70°C
SFPXGM03D SFP+, 10Gbps, LC, multi, DDM, 300KM, 0~70°C
SFPXGS10D SFP+, 10Gbps, LC, single, DDM, 10KM, 0~70°C
SFPGES10-A SFP, 1000Mbps, LC, single, 10KM, BiDi TX-1310nm RX-1550nm, 0~70°C
SFPGES10-B SFP, 1000Mbps, LC, single, 10KM, BiDi TX-1550m RX-1310nm, 0~70°C
SFPGES10T-A SFP, 1000Mbps, LC, single, 10KM, BiDi TX-1310nm RX-1550nm, -40~85°C
SFPGES10T-B SFP, 1000Mbps, LC, single, 10KM, BiDi TX-1550m RX-1310nm, -40~85°C
SFPGES10D-A SFP, 1000Mbps, LC, single, DDM, 10KM, BiDi TX-1310nm RX-1550nm, 0~70°C
SFPGES10D-B SFP, 1000Mbps, LC, single, DDM, 10KM, BiDi TX-1550m RX-1310nm, 0~70°C