Simgenet L3 Ethernet Switch

Simgenet SMG-SW Series — Top-Tier IEC 61850 L3 Ethernet Switch

The Simgenet SMG-SW Series is a top-tier modular L2/L3 switch family built for harsh field conditions, for IEC 61850 substation networks (station and process bus), rail systems, industrial plants and operator access networks, with software developed entirely in-house at Simgenet. When the ring breaks the protection message is not lost (HSR/PRP), time reaches every device (hardware-timestamped PTP) and unauthorised devices cannot join the network (802.1X, port security, IEC 62443). All three models are 19-inch rack-mount (1U/2U); port layout is defined by cards: SMG-SW411 (1U compact), SMG-SW104 (1U, 4 slots) and SMG-SW818 (2U, 8 slots, up to 100G) run the same SMG-SW operating system.

Simgenet SMG-SW Series — Top-Tier IEC 61850 L3 Ethernet Switch


The Simgenet SMG-SW Series is a managed L2/L3 switch family for harsh field conditions, built for the station and aggregation layers of critical-infrastructure networks. It delivers the upper-segment feature set expected in power-utility automation, rail systems, industrial plants and telecom/ISP access networks — seamless rings, hardware-timestamped time distribution, built-in OT security and a complete routing stack — in a single operating system — SMG-SW. The three chassis (SMG-SW411, SMG-SW104, SMG-SW818) differ only in slot count and port capacity; operating system, management and feature set are identical. The SMG-SW operating system is developed entirely in-house at Simgenet and shares the same management concepts as the Simgenet SMGOS router family, so network teams manage the device with the concepts and show output they already know.

IEC 61850 Substation Network: Station Bus and Process Bus

SMG-SW serves both network layers of the IEC 61850 digital substation: the station bus (IEC 61850-8-1 MMS and GOOSE, IEC 60870-5-104 / DNP3 telecontrol) and the process bus (IEC 61850-9-2 Sampled Values, GOOSE, between merging units and IEDs). Timely delivery of the protection message, sample alignment to a common time and keeping unauthorised devices off the bus are solved at switch level:

  • Protection-traffic priority (QoS-61850): GOOSE (0x88B8) and SV (0x88BA) frames are protected by PCP; a PCP-selective policer limits low-priority traffic and never touches PCP ≥ 4 protection traffic; priority-class ordering on egress. Latency and loss budgets are held under background saturation (per the IEC 61850-90-4 engineering guide).
  • Multicast discipline: IGMP snooping forwards GOOSE/SV and video multicast only to member ports; storm control and CoPP protect the control plane on the bus.
  • Zero-loss redundancy: HSR/PRP RedBox (IEC 62439-3) on the process bus — dual paths where the loss of a single frame is unacceptable; VLAN-tagged and QinQ-encapsulated HSR.
  • Power-profile time: IEC/IEEE 61850-9-3 PTP boundary clock with hardware timestamping on 1G/10G ports; an end-to-end time chain from the Simgenet GNSS Server grandmaster to IEDs, PMUs and recorders. PTP power profile and GOOSE priority pass through the same port over HSR/PRP.
  • GOOSE/SV security: port allowlist (only defined APPIDs and IEDs pass on that port, tagged and untagged frames), flood limit, GOOSE-IDS (stNum/sqNum inconsistency, replay, spoofed source), IEC 62351-6 HMAC verification, OT asset inventory.
  • Example placement: process bus — SMG-SW104 RedBox (SV/GOOSE, HSR/PRP, power-profile PTP) · station bus — MMS, GOOSE, IEC 104 allowlist, QoS-61850, IGMP snooping · WAN/centre — SMG-SW818 or SMG router (OSPF/BGP, IPsec, R-GOOSE transport).

At substation acceptance, ring, time and protection priority are measured in a single run with the Simgenet SVP and documented with their standard reference.

Modular Chassis: Port Count Defined by the Project

SMG-SW has no fixed port count; the port layout is the number of slots × the cards fitted. 1G copper, 10G fibre and 100G cards can be mixed in the same chassis, and the device grows later by adding cards.

  • SMG-SW411 — 1U rackmount, compact; 1G and 10G cards. Branch, field cabinet, access edge.
  • SMG-SW104 — 1U rackmount, 4 expansion slots; 1G / 10G / 40G / 100G cards. Substation, aggregation layer.
  • SMG-SW818 — 2U rackmount, 8 expansion slots, redundant power; cards from 1G to 100G. Backbone, control centre, high port density.

Card catalogue: 8×/4× 1G SFP, 8×/4× 1G RJ45, 2×/4× 10G SFP+, 2× 40G QSFP+, 2× 100G QSFP28. Example: SMG-SW818 with 8 slots × 8×1G = 64 × 1G, or 6 × (8×1G) + 2 × (2×100G) = 48 × 1G + 4 × 100G uplinks. Fitted cards are detected automatically and ports are named in slot/port order.

Ring Redundancy and Time: The Ring Breaks, the Protection Message Doesn't

Three ring protocols in one image: ERPS (ITU-T G.8032) for operator and campus rings, MRP (IEC 62439-2) for the industrial-automation ecosystem, and HSR/PRP RedBox (IEC 62439-3) for protection and process-bus networks where the loss of a single frame is unacceptable. VLAN-tagged and QinQ-encapsulated HSR is a product differentiator.

The multi-port PTP boundary clock (IEEE 1588-2019) takes time from upstream with hardware timestamping on 1G/10G ports and regenerates it towards downstream ports. Profiles: IEC/IEEE 61850-9-3 power profile, 1588 default and 802.1AS (gPTP). Together with the Simgenet GNSS Server it forms an end-to-end time chain from the control centre to the IED.

Operational Technology Security

Every network with PLCs, IEDs, RTUs and sensors asks the same two questions: who may connect, and what may pass? SMG-SW answers them at switch level within the IEC 62443 framework:

  • Access control: 802.1X authenticator (RADIUS/EAP, dynamic VLAN), MAB, CoA/Disconnect (RFC 5176), port security (maximum / violation / sticky / aging). Works with the Simgenet NAC Server and third-party NAC/RADIUS servers.
  • Layer-2 security: DHCP snooping, IP Source Guard, Dynamic ARP Inspection, IPv4/IPv6/MAC ACLs, control-plane policing (CoPP), storm control.
  • Power-utility automation: IEC 61850 GOOSE/SV priority protection (QoS-61850), GOOSE/SV port allowlist and flood limit, GOOSE-IDS (stNum/sqNum inconsistency, replay, spoofed source), IEC 62351-6 HMAC verification, OT asset inventory.
  • Management policy: IEC 62443-4-2 session/lockout/password policy, role separation, RFC 5424 event log, secret masking, signed software updates.

Layer 3: The Same Routing Stack as the Router Family

SMG-SW is a Layer-3 switch and carries a complete routing stack in the same scope as the Simgenet router family: OSPFv2, IS-IS, EIGRP, RIP, BGP (including FlowSpec), PIM/IGMP/MSDP, VRF-lite, VRRP, BFD/S-BFD, TI-LFA; LDP, MPLS L3VPN, pseudowire, SR-MPLS/SR-TE, PCEP, EVPN-VXLAN; IPsec/IKEv2, OpenVPN and DMVPN. It connects the aggregation layer to the backbone without a separate router.

Management: Web and CLI, One Configuration Source

The HTTPS web interface (TR/EN) and the SSH CLI share a single configuration source; every change is validated, applied and read back from the device. Live SVG front panel, port table, MAC table, policer counters; backup/restore/rollback; SNMP v2c/v3 (SIMGENET MIB) and remote syslog for integration with common NMS/SIEM systems; CFM 802.1ag / Y.1731 service OAM; SFP DDM optical diagnostics.

Evidence-Based Delivery

Spanning tree, LLDP, LACP, IGMP, port security and PTP behaviour are developed by measuring against independent peer devices with the Simgenet SVP test platform. We measure the switch network we build with SVP and document the result with its standard reference: a numbered run record and a lockable report instead of an "it works" statement.

Application Areas

  • Power transmission and distribution — transmission (TEİAŞ) substations, distribution substations, power plants: station and process bus (IEC 61850 GOOSE/SV, HSR/PRP RedBox, 61850-9-3 PTP boundary clock), GOOSE/SV priority and allowlist, IEC 104/DNP3 telecontrol routing, IEC 62443-aligned management; secure IPsec/MPLS exit to the control centre.
  • Rail — mainline, metro, tram, light rail: station and trackside rings (ERPS/MRP), QoS priority and PTP for signalling and SCADA traffic, OSPF/BGP connection to the centre, port security and 802.1X for field access control, wide temperature range.
  • Water and wastewater SCADA — pump stations, reservoirs, treatment plants, distribution: fibre ring plus radio/LTE mixed access to remote sites, IEC 62443 hardening for RTU/PLC networks (DHCP snooping/IPSG/DAI, ACLs, CoPP), NAC integration, IEC 104/Modbus-TCP transport to the centre.
  • Industrial plants, production lines, ports, defence, public sector: MRP/ERPS rings in PLC/SCADA networks, OT allowlist, AAA (RADIUS/TACACS+/LDAP) and central event logging; answering "who may connect, what may pass" at switch level.
  • Telecom and ISP — access, aggregation, 5G/mobile backhaul: QinQ, LACP, ERPS rings, LDP/MPLS and Segment Routing transport, EVPN-VXLAN, CFM/Y.1731 service OAM; modular ports from 1G to 100G, NMS integration via SNMPv3/NETCONF.
  • 5G and mobile infrastructure — cell-site aggregation, backhaul/midhaul: ERPS rings, QinQ and LACP at site and aggregation points; transport over MPLS/Segment Routing and EVPN-VXLAN; time synchronisation chain via PTP boundary clock; common management end to end with the Simgenet SMGOS router family.
  • Campus and data-centre edge: L3 aggregation, VRF separation, VRRP/ECMP high availability, 10G/100G uplinks, common management concepts with the router family.

The full feature list, reference standards and model positioning are in the product brochure (EN) under the Documents tab.

Platform
Product classManaged L2/L3 switch for harsh field conditions; SMG-SW operating system, developed entirely in-house at Simgenet
Models / chassisSMG-SW411 (1U, compact) · SMG-SW104 (1U, 4 slots) · SMG-SW818 (2U, 8 slots, redundant power, up to 100G)
Port layoutSlots × Simgenet cards: 8×1G SFP · 4×1G SFP · 8×/4× RJ45 · 2×10G SFP+ · 4×10G SFP+ · 2×40G QSFP+ · 2×100G QSFP28; port count defined by the cards fitted (e.g. 8 slots × 8×1G = 64 ports)
Layer 2
L2VLAN (802.1Q) access/trunk · QinQ (802.1ad) · MAC learning/table · jumbo 9000 B · LACP (802.1AX, fast/slow) · LLDP (802.1AB-2016) · SPAN port mirroring
Spanning TreeRSTP + MSTP (instance/VLAN, region) · PortFast · BPDU guard · root guard · loop guard · BPDU filter · err-disable recovery
Ring / redundancyERPS (ITU-T G.8032) · MRP (IEC 62439-2) · HSR/PRP RedBox (IEC 62439-3), VLAN-tagged and QinQ-encapsulated HSR
MulticastIGMP snooping v1/v2/v3 (querier, fast-leave, static mrouter)
Time and QoS
TimePTP boundary clock (IEEE 1588-2019), multi-port; hardware timestamping on 1G/10G ports; profiles IEC/IEEE 61850-9-3 (power), 1588 default, 802.1AS (gPTP) · NTP
QoS802.1p / DSCP mapping · priority classes · IEC 61850 GOOSE/SV priority protection · rate limiting (policer)
IEC 61850Station bus (61850-8-1 MMS/GOOSE) and process bus (61850-9-2 SV) · GOOSE 0x88B8 / SV 0x88BA PCP priority (61850-90-4) · IGMP snooping · HSR/PRP RedBox (62439-3) · 61850-9-3 power-profile PTP BC · GOOSE/SV allowlist + flood limit + GOOSE-IDS · IEC 62351-6 HMAC · R-GOOSE transport
Layer 3 and MPLS
L3 / routingStatic · OSPFv2 · IS-IS · EIGRP · RIP · BGP (community, ECMP, confederation, GR, FlowSpec) · PBR / route-map / prefix-list · PIM / IGMP / MSDP · VRF-lite · VRRP v2/v3 · BFD / S-BFD · TI-LFA
MPLS / overlayLDP · MPLS L3VPN (VPNv4) · pseudowire · SR-MPLS · SR-TE · PCEP · EVPN-VXLAN (Type 1–5, symmetric IRB, ESI multihoming)
VPNIPsec/IKEv2 site-to-site (AES-GCM, ECP-521, Curve25519) · OpenVPN server · DMVPN / NHRP
Security
Access security802.1X authenticator (RADIUS/EAP, dynamic VLAN) · MAB · CoA/Disconnect (RFC 5176) · Filter-Id → dynamic ACL · port security (maximum / violation shutdown-restrict-protect / sticky / aging)
Layer-2 securityDHCP snooping + binding table · IP Source Guard · Dynamic ARP Inspection · IPv4/IPv6/MAC ACL (in/out) · CoPP · storm control (pps/load thresholds)
OT securityIEC 61850 GOOSE/SV port allowlist + flood limit · GOOSE-IDS · IEC 62351-6 HMAC · OT asset inventory · IEC 62443-4-2 session/lockout policy
Management
OAM / monitoringCFM 802.1ag / Y.1731 (CCM, LBM/LTM, DMM delay measurement) · SPAN · SFP DDM optical diagnostics · cable/link diagnostics
ManagementHTTPS web (TR/EN, role-based admin/operator/viewer) · SSH CLI with industry-familiar show family · single-page running-config · validate→apply→read-back · backup / restore / rollback / factory reset · signed software updates
AAALocal + RADIUS + TACACS+ + LDAP; RBAC; brute-force lockout
NMSSNMP v2c/v3 (authPriv) + SIMGENET MIB + traps · remote syslog · event/alarm log (X.733 severity)
Hardware detectionAutomatic slot/card detection, port labelling, SVG front panel
Hardware
Management portDedicated RJ45 Ethernet management port — HTTPS web interface and SSH CLI
Mounting19-inch rack, 1U (SMG-SW411, SMG-SW104) / 2U (SMG-SW818)
Power / environment220 VAC; SMG-SW818 2× redundant PSU · Operating temperature −20 °C to +60 °C
Reference standardsIEEE 802.1Q/D/ad/AX/AB/X/ag/AS · IEEE 1588-2019 · IEC/IEEE 61850-9-3 · IEC 61850-8-1/9-2 · IEC 62351-6 · IEC 62439-2/-3 · IEC 62443-4-2 · ITU-T G.8032 · G.8013/Y.1731 · RFC 2865/2866/8907/5176 · RFC 2328/4271/5575/5880/7880/5036/4364/8402/7432/8365/5798/7296 · RFC 3411–3418 · RFC 5424 · IEC 60870-5-104 · IEEE 1815 · X.733
Back