The HP ProCurve Switch 3500 Series consists of the most advanced intelligent edge switches in the HP ProCurve Networking product line. The 3500 series includes 24-port and 48-port fixed-port switches. The foundation for all these switches is a purpose-built, programmable ProVision ASIC that allows the most demanding networking features, such as Quality of Service (QoS) and security, to be implemented in a scalable yet granular fashion. With a variety of Gigabit and 10/100 interfaces, integrated PoE+, PoE and Non-PoE options, versatile 10-GbE connectivity (CX4, X2, and SFP+) on Gigabit switches, the 3500 switches offer excellent investment protection, flexibility, and scalability, as well as ease of deployment, operation, and maintenance.
Products within this series have achieved sufficient scores in each of the rated criteria to achieve the Miercom Certified Green distinction Award. See the Specifications section of this series for more information.
Product overview
Advanced access layer and small distribution
Enterprise-class performance and security
Intelligent Edge feature set with L2 to L4 support
Scalable 10/100/1000 PoE+ and 10/100 PoE
Unified core-to-edge ProVision software
Industry-leading warranty
Lifetime Warranty: for as long as you own the product, with next-business-day advance replacement (available in most countries)
Management
Remote Intelligent Mirroring: mirrors selected ingress/egress traffic based on ACL, port, MAC address, or VLAN to a local or remote 8200zl/6600/6200yl/5400zl/3500 switch anywhere on the network
RMON, XRMON, and sFlow v5: provide advanced monitoring and reporting capabilities for statistics, history, alarms, and events
IEEE 802.1AB Link Layer Discovery Protocol (LLDP): automated device discovery protocol provides easy mapping by network management applications
Uni-Directional Link Detection (UDLD): monitors cable between two switches and shuts down the ports on both ends if the cable is broken turning the bi-directional link into uni-directional; this prevents network problems such as loops
Management simplicity: provides ProCurve-common networking features and CLI implementation (common across ProCurve 8200zl/6600/6200yl/5400zl/3500 switches)
Command authorization: leverages RADIUS to link a custom list of CLI commands to an individual network administrator's login; also provides an audit trail
Friendly port names: allow assignment of descriptive names to ports
Dual flash images: provide independent primary and secondary operating system files for backup while upgrading
Multiple configuration files: can be stored to the flash image
Connectivity
IPv6:
IPv6 host: enables switches to be managed and deployed at the IPv6 network's edge
Dual stack (IPv4/IPv6): transitions from IPv4 to IPv6, supporting connectivity for both protocols
MLD snooping: forwards IPv6 multicast traffic to the appropriate interface
IPv6 ACL/QoS: supports ACL and QoS for IPv6 network traffic
IPv6 ready: switch hardware can support IPv6 routing, tunneling, and security; available when enabled via software updates in follow-on releases
IEEE 802.3af Power over Ethernet (POE): provides up to 15.4 W per port to IEEE 802.3af-compliant PoE-powered devices such as IP phones, wireless access points, and security cameras
IEEE 802.3at Power Over Ethernet Plus (PoE+): provides up to 30 W per port to IEEE 802.3 for PoE/PoE+ powered devices such as video IP phones, IEEE 802.11n wireless access points, and advanced pan/zoom/tilt security cameras New!
Prestandard PoE support: detects and provides power to prestandard PoE devices; see list of supported devices in the product FAQs at www.procurve.com
Jumbo frames: on Gigabit and 10-Gigabit ports, allow high-performance remote backup and disaster-recovery services
Auto-MDIX: automatically adjusts for straight-through or crossover cables on all 10/100 and 10/100/1000 ports
Performance
High-speed/capacity architecture: up to 153.6 Gbps crossbar switching fabric provides intra- and inter-module switching with up to 111.5 million pps throughput on the purpose-built ProVision ASICs
Selectable queue configurations: increase performance by selecting the number of queues and associated memory buffering that best meet the requirements of your network applications
Resiliency and high availability
Virtual Router Redundancy Protocol (requires Premium License): VRRP allows groups of two routers to dynamically back each other up to create highly available routed environments
IEEE 802.1s Multiple Spanning Tree Protocol: provides high link availability in multiple VLAN environments by allowing multiple spanning trees; encompasses IEEE 802.1D Spanning Tree Protocol and IEEE 802.1w Rapid Spanning Tree Protocol
Server-to-switch distributed trunking: allows a server to connect to two switches with one logical trunk that consists of multiple physical connections; enables load-balancing and increases resiliency
IEEE 802.3ad Link Aggregation Control Protocol (LACP) and ProCurve trunking: support up to 60 trunks, each with up to 8 links (ports) per trunk
Layer 2 switching
IEEE 802.1ad Q-in-Q (requires Premium License): increases the scalability of an Ethernet network by providing a hierarchical structure; connects multiple LANs on high-speed campus or metro network
ProCurve switch meshing: dynamically load-balances across multiple active redundant links to increase available aggregate bandwidth
VLAN support and tagging: supports the IEEE 802.1Q standard and 2,048 VLANs simultaneously
IEEE 802.1v protocol VLANs: isolate select non-IPv4 protocols automatically into their own VLANs
GARP VLAN Registration Protocol: allows automatic learning and dynamic assignment of VLANs
Layer 3 services
UDP helper function: allows UDP broadcasts to be directed across router interfaces to specific IP unicast or subnet broadcast addresses and prevents server spoofing for UDP services such as DHCP
Loopback interface address: defines an address in RIP and OSPF that can always be reachable, improving diagnostic capability
Layer 3 routing
Static IP routing: provides manually configured routing; includes ECMP capability
RIP: provides RIPv1 and RIPv2 routing
OSPF (requires Premium License): includes host-based ECMP to provide link redundancy/scalable bandwidth and NSSA
Security
Access control lists (ACLs): provide filtering based on the IP field, source/destination IP address/subnet, and source/destination TCP/UDP port number on a per-VLAN or per-port basis
Multiple user authentication methods:
IEEE 802.1X users per port: provides authentication of multiple IEEE 802.1X users per port; prevents user “piggybacking” on another user’s IEEE 802.1X authentication
Web-based authentication: authenticates from Web browser for clients that do not support IEEE 802.1X supplicant; customized remediation can be processed on an external Web server
MAC-based authentication: client is authenticated with the RADIUS server based on client's MAC address
Concurrent IEEE 802.1X, Web, and MAC authentication schemes per port: switch port will accept up to 32 sessions of IEEE 802.1X, Web, and MAC authentications
Virus throttling: detects traffic patterns typical of WORM-type viruses and either throttles or entirely prevents the virus from spreading across the routed VLANs or bridged interfaces, without requiring external appliances
Secure management access: securely encrypts all access methods (CLI, GUI, or MIB) through SSHv2, SSL, and/or SNMPv3
USB Secure Autorun (requires HP ProCurve Manager Plus): deploys, diagnoses, and updates switch using a USB flash drive; works with a secure credential to prevent tampering
Switch CPU protection: provides automatic protection against malicious network traffic trying to shut down the switch
ICMP throttling: defeats ICMP denial-of-service attacks by enabling any switch port to automatically throttle ICMP traffic
Identity-driven ACL: enables implementation of a highly granular and flexible access security policy and VLAN assignment specific to each authenticated network user
STP BPDU port protection: blocks Bridge Protocol Data Units (BPDUs) on ports that do not require BPDUs, preventing forged BPDU attacks
Dynamic IP lockdown: works with DHCP protection to block traffic from unauthorized hosts, preventing IP source address spoofing
Dynamic ARP protection: blocks ARP broadcasts from unauthorized hosts, preventing eavesdropping or theft of network data
STP Root Guard: protects root bridge from malicious attack or configuration mistakes
Detection of malicious attacks: monitors 10 types of network traffic and sends a warning when an anomaly that potentially can be caused by malicious attacks is detected
Port security: allows access only to specified MAC addresses, which can be learned or specified by the administrator
MAC address lockout: prevents particular configured MAC addresses from connecting to the network
Source-port filtering: allows only specified ports to communicate with each other
RADIUS/TACACS+: eases switch management security administration by using a password authentication server
Secure Shell (SSHv2): encrypts all transmitted data for secure, remote command-line interface (CLI) access over IP networks
Secure Sockets Layer (SSL): encrypts all HTTP traffic, allowing secure access to the browser-based management GUI in the switch
Secure FTP: allows secure file transfer to and from the switch; protects against unwanted file downloads or unauthorized copying of switch configuration file
Management Interface Wizard: helps ensure that management interfaces such as SNMP, telnet, SSH, SSL, Web, and USB are secured to the desired level
Switch management logon security: can require either RADIUS or TACACS+ authentication for secure switch CLI logon
Security banner: displays a customized security policy when users log in to the switch
Convergence
IP multicast routing (requires Premium License): includes PIM Sparse and Dense modes to route IP multicast traffic
IP multicast snooping (data-driven IGMP): automatically prevents flooding of IP multicast traffic
LLDP-MED (Media Endpoint Discovery): a standard extension of LLDP that stores values for parameters such as QoS and VLAN to automatically configure network devices such as IP phones
RADIUS VLAN for voice: uses standard RADIUS attribute and LLDP-MED to automatically configure VLAN for IP phones
PoE allocations: supports multiple methods (automatic, IEEE 802.3af class, LLDP-MED, or user specified) to allocate PoE power for more efficient energy savings
Quality of Service (QoS)
Advanced classifier-based QoS: classifies traffic using multiple match criteria based on L2/3/4 information; applies QoS policies such as setting priority level and rate limit to selected traffic on a per-port or per-VLAN basis
Layer 4 prioritization: enables prioritization based on TCP/UDP port numbers
Traffic prioritization: allows real-time traffic classification into eight priority levels mapped to eight queues
Bandwidth shaping:
Port-based rate limiting: provides per-port ingress/egress enforced maximum bandwidth
Classifier-based rate limiting: uses ACL to enforce maximum bandwidth for ingress traffic on each port
Class of Service (CoS): sets the IEEE 802.1p priority tag based on IP address, IP Type of Service (ToS), L3 protocol, TCP/UDP port number, source port, and DiffServ
Warranty and support
ProCurve Lifetime Warranty: for as long as you own the product, with next-business-day advance replacement (available in most countries)
Electronic and telephone support: limited electronic and telephone support is available from HP; refer to the HP website at www.procurve.com/support for details on the support provided and the period during which support is available
Software releases: refer to the HP website at www.procurve.com/support for details on the software releases provided and the period during which software releases are available
Model specifications
HP ProCurve Switch 3500yl-24G-PWR Intelligent Edge (J8692A)
HP ProCurve 3500yl-24G-PoE+ Switch (J9310A)
HP ProCurve Switch 3500yl-48G-PWR Intelligent Edge (J8693A)
Ports
1 open module slot
20 auto-sensing 10/100/1000 ports (IEEE 802.3 Type 10Base-T, IEEE 802.3u Type 100Base-TX, IEEE 802.3ab Type 1000Base-T)
Media Type: Auto-MDIX
Duplex: 10Base-T/100Base-TX: half or full; 1000Base-T: full only
4 dual-personality ports
each port can be used as either an RJ-45 10/100/1000 port (IEEE 802.3 Type 10Base-T; IEEE 802.3u Type 100Base-TX; IEEE 802.3ab 1000Base-T Gigabit Ethernet) with PoE or an open mini-GBIC slot (for use with mini-GBIC transceivers)
Supports a maximum of 4 10-GbE ports, with optional module
1 open module slot
20 auto-sensing 10/100/1000 ports (IEEE 802.3 Type 10Base-T, IEEE 802.3u Type 100Base-TX, IEEE 802.3ab Type 1000Base-T)
Media Type: Auto-MDIX
Duplex: 10Base-T/100Base-TX: half or full; 1000Base-T: full only
1 RJ-45 serial console port
4 dual-personality ports
each port can be used as either an RJ-45 10/100/1000 port (IEEE 802.3 Type 10Base-T; IEEE 802.3u Type 100Base-TX; IEEE 802.3ab 1000Base-T Gigabit Ethernet) with PoE or an open mini-GBIC slot (for use with mini-GBIC transceivers)
Supports a maximum of 4 10-GbE ports
1 open module slot
44 auto-sensing 10/100/1000 ports (IEEE 802.3 Type 10Base-T, IEEE 802.3u Type 100Base-TX, IEEE 802.3ab Type 1000Base-T)
Media Type: Auto-MDIX
Duplex: 10Base-T/100Base-TX: half or full; 1000Base-T: full only
4 dual-personality ports
each port can be used as either an RJ-45 10/100/1000 port (IEEE 802.3 Type 10Base-T; IEEE 802.3u Type 100Base-TX; IEEE 802.3ab 1000Base-T Gigabit Ethernet) with PoE or an open mini-GBIC slot (for use with mini-GBIC transceivers)
Supports a maximum of 4 10-GbE ports, with optional module
Physical characteristics
Dimensions
15.43(d) x 17.44(w) x 1.73(h) in. (39.2 x 44.3 x 4.4 cm) (1U height)
15.43(d) x 17.44(w) x 1.73(h) in. (39.2 x 44.3 x 4.4 cm) (1U height)
16.93(d) x 17.44(w) x 1.73(h) in. (43.0 x 44.3 x 4.4 cm) (1U height)
Mounts in an EIA-standard 19 in. telco rack or equipment cabinet (hardware included); horizontal surface mounting only
Mounts in an EIA-standard 19 in. telco rack or equipment cabinet (hardware included); horizontal surface mounting only
Mounts in an EIA-standard 19 in. telco rack or equipment cabinet (hardware included); horizontal surface mounting only
Performance
1000 Mb Latency
< 3.4 µs (FIFO 64-byte packets)
< 3.4 µs (FIFO 64-byte packets)
< 3.4 µs (FIFO 64-byte packets)
10 Gbps Latency
< 2.1 µs (FIFO 64-byte packets)
< 2.1 µs (FIFO 64-byte packets)
< 2.1 µs (FIFO 64-byte packets)
Throughput
up to 75.7 million pps
up to 75.7 million pps
up to 111.5 million pps
Routing/Switching capacity
101.8 Gbps
101.8 Gbps
149.8 Gbps
Switch fabric speed
105.6 Gbps
105.6 Gbps
153.6 Gbps
Routing table size
10,000 entries
10,000 entries
10,000 entries
MAC address table size
64,000 entries
64,000 entries
64,000 entries
Environment
Operating temperature
32ºF to 131ºF (0ºC to 55ºC); 32°F to 104°F (40°C) when used with any X2 10-GbE
32ºF to 131ºF (0ºC to 55ºC); 32°F to 104°F (40°C) when used with any X2 10-GbE
32ºF to 131ºF (0ºC to 55ºC); 32°F to 104°F (40°C) when used with any X2 10-GbE
Operating relative humidity
15% to 95% @ 104ºF (40ºC), non-condensing
15% to 95% @ 104ºF (40ºC), non-condensing
15% to 95% @ 104ºF (40ºC), non-condensing
Non-operating/Storage temperature
-40ºF to 158ºF (-40ºC to 70ºC)
-40ºF to 158ºF (-40ºC to 70ºC)
-40ºF to 158ºF (-40ºC to 70ºC)
Non-operating/Storage relative humidity
15% to 90% @ 149ºF (65ºC), non-condensing
15% to 90% @ 149ºF (65ºC), non-condensing
15% to 95% @ 149ºF (65ºC), non-condensing
Altitude
up to 15,000 ft. (4.6 km)
up to 15,000 ft. (4.6 km)
up to 15,000 ft. (4.6 km)
Acoustic
Power: 55.1 dB, Pressure: 44.8 dB ISO 7779, ISO 9296
Power: 57.0 dB, Pressure: 40.5 dB ISO 7779, ISO 9296
Power: 55.6 dB, Pressure: 45.3 dB ISO 7779, ISO 9296
Electrical characteristics
Achieved Miercom Certified Green Award
Description
The switch automatically adjusts to any voltage between 100-127 and 200-240 volts and either 50 or 60 Hz
The switch automatically adjusts to any voltage between 100-127 and 200-240 volts and either 50 or 60 Hz
The switch automatically adjusts to any voltage between 100-127 and 200-240 volts with either 50 or 60 Hz
Maximum heat dissipation
865 BTU/hr (912.9 kJ/hr)
865 BTU/hr (912.9 kJ/hr)
1144 BTU/hr (1206.9 kJ/hr)
Voltage
100-127 / 200-240 VAC
100-127 / 200-240 VAC
100-127 / 200-240 VAC
Current
10.0 / 5.0 A
6.6 / 3.0 A
10.0 / 5.0 A
Idle power
98 W
94 W
142 W
Maximum power rating
623 W
616 W
705 W
PoE power
398 W
398 W
398 W
Frequency
50 / 60 Hz
50 / 60 Hz
50 / 60 Hz
Notes
Idle power is the actual power consumption of the device with no ports connected. Maximum power rating and maximum heat dissipation are the worst-case theoretical maximum numbers provided for planning the infrastructure with fully loaded PoE (if equipped), 100% traffic, all ports plugged in, and all modules populated. The amount of PoE power delivered is dependent on the number and type of power supplies connected. The switches offer optional external power supplies (EPS) for maximum PoE power.
Idle power is the actual power consumption of the device with no ports connected. Maximum power rating and maximum heat dissipation are the worst-case theoretical maximum numbers provided for planning the infrastructure with fully loaded PoE (if equipped), 100% traffic, all ports plugged in, and all modules populated. The amount of PoE power delivered is dependent on the number and type of power supplies connected. The switches offer optional external power supplies (EPS) for maximum PoE power.
Idle power is the actual power consumption of the device with no ports connected. Maximum power rating and maximum heat dissipation are the worst-case theoretical maximum numbers provided for planning the infrastructure with fully loaded PoE (if equipped), 100% traffic, all ports plugged in, and all modules populated. The amount of PoE power delivered is dependent on the number and type of power supplies connected. The switches offer optional external power supplies (EPS) for maximum PoE power.
Safety
CSA 22.2 No. 60950 UL 60950 IEC 60950 EN 60950
CSA 22.2 No. 60950 UL 60950 IEC 60950 EN 60950
CSA 22.2 No. 60950 UL 60950 IEC 60950 EN 60950
Notes
When using mini-GBICs with this product, mini-GBICs with revision "B" or later (product number ends with the letter "B" or later, e.g., J4858B, J4859C) are required.
When using mini-GBICs with this product, mini-GBICs with revision "B" or later (product number ends with the letter "B" or later, e.g., J4858B, J4859C) are required.
When using mini-GBICs with this product, mini-GBICs with revision "B" or later (product number ends with the letter "B" or later, e.g., J4858B, J4859C) are required.