Ethernet Access Switch MES2424
- Level:
- L3
- Bandwidth:
- 128 Gbps
- Interfaces:
- 24x1G, 4x10G SFP+
- Power supply:
- AC/DC


Description
The Ethernet access switches provide end users connection to networks of large enterprises, small and mid-sized businesses and service providers via 1G/10G interfaces.
The switches support Virtual Local Area Networks (VLAN), multicast groups and advanced security functions.
Advanced warranty and support packages
Extend basic package with additional paid services
Learn moreSpecifications
- Level:
- L3
- Bandwidth:
- 128 Gbps
- Power supply:
- AC/DC
- Interfaces:
- 24x1G, 4x10G SFP+
- MAC table:
- 16384
- VLAN table:
- 4094
- ARP:
- 1000
- QoS:
- 8 egress queues per port
ECCM
Eltex Cloud Configuration Manager is a centralized system for network equipment management

Features and capabilities
For full specifications and manuals see Documents and files section below
Interfaces:
10/100/1000BASE-T (RJ-45)
24
1000BASE-X (SFP)/10GBASE-R (SFP+)
4
Console port RS-232 (RJ-45)
1
Performance:
Bandwidth
128 Gbps
Buffer memory
1,5 MB
RAM (DDR3)
512 MB
ROM (SPI Flash)
64 MB
MAC table
16384
VLAN table
4094
VRRP routers
32
Link Aggregation Groups (LAG)
24 groups, up to 8 ports per LAG
Quality of Service (QoS)
8 egress queues per port
Jumbo frames
12288 bytes
Physical parameters:
Power supply
110–250 V AC, 50–60 Hz
18–72 V DC
Hardware support for Dying Gasp
AC - Yes
DC - No
Operating temperature range
From -20 tо +50 °С
Storage temperature range
From -40 to +70 °С
Cooling
Passive
Operating humidity
No more than 80 %
Form factor
19", 1U
Dimensions
430x44x203
Related products
Components, modules, and software options that are purchased additionally


Free
Basic warranty
Up to 5 years
Extended warranty
Hit

Free
First in, first out
Monday to Friday (GMT +7)
Priority support
Monday to Friday (GMT +7)

Priority support
Monday to Friday (GMT +5)

Support
Hit

Documents and files
Firmware version 10.3.6.11 R0 (Issue date: 17-04-2025)
ZIP, 13.2 Mb
MIB files (Issue date: 17-04-2025)
ZIP, 2.58 Mb
Firmware version upgrade guide (Issue date: 09-04-2025)
PDF, 975 Kb
The firmware is compatible with other device models:
MES2420-48P, MES2410-08DU, MES2408C, MES2408P, MES2428B, MES2408CP, MES2448B, MES2408, MES2428P, MES2420D-24DP, MES3708P, MES2448, MES1428, MES2408PL, MES2428, MES3400-24, MES3400-48F, MES2424B, MES2408B, MES2424P, MES2410-08DP, MES3400-48, MES2420B-24D, MES3400-24F, MES3710P, MES2448P, MES3400I-24, MES2424FB, MES2411X
Firmware updates
Firmware Version 10.3.6.11
Added:
- Added a command to delete the ssh server-address setting;
- Added a command that disables comparing the IP address in the Next server IP address field and the IP address in the ip dhcp relay server configuration;
- Added the ability to change the standard buffer utilization values of batch processes;
- Added support for Accounting for Dot1x/MAC using the RADIUS protocol;
- The output of the show interfaces status command looks like a similar command on MES23xx/33xx/35xx/5324 devices.
Fixed:
- Improved command stability;
- Fixed the hang of the switch when displaying the current configuration;
- Fixed an error that leads to a complete loss of device control;
- Fixed a problem with the switch hanging when executing the default interface range;
- Fixed an error with the speed setting in line telnet/ssh;
- Fixed an error that caused Web interface pages to not load;
- Fixed an error where the cost in STP was incorrectly calculated for interfaces;
- Fixed a problem with the switch hanging when changing the STP mode from RSTP to RPVST;
- Fixed an error where there was no L3 access to the switch after reboot;
- Fixed an error that freezes the SSH session when saving the configuration to the SFTP server;
- Fixed an error where the source ip was incorrectly specified in the SNMP response packets;
- Fixed an error where the POWER-ETHERNET-MIB poll::pethMainPseConsumptionPower returned a value in deciwatts instead of watts;
- Fixed an error that displayed an extra log about duplicating a link local IPv6 address;
- Fixed a dot1x PC authorization error when using RADIUS VLAN Attributes and Voice VLAN together;
- Fixed an error leading to TCP session reset;
- Fixed an error that caused high CPU usage when connected to the switch by a telnet client on TCP port 22.
Previous versions
Firmware Version 10.3.6.6
Added:
- Added a method for encrypting passwords in the CLI using the SHA512 algorithm. ATTENTION. If there are users with a 64-character password, the password must be replaced with a shorter one before updating;
- Added a limit on the number of unsuccessful authorization attempts in the Web;
- Added the ability to specify the number of unsuccessful authorization attempts to log in to the CLI and Web;
- Added the Service-Type attribute to the RADIUS request when authenticating a user using the Dot1x and MAB protocols;
- Increased the maximum key size when configuring radius-server and tacacs-server host to 128;
- Added the setting for option 150 for the DHCP server.
Fixed:
- Fixed a bug where the Tunnel-Private-Group-Id attribute was not processed if the Tag field was present;
- Fixed a bug where authentication via the Dot1x protocol did not work.
Firmware Version 10.3.6.3
Added:
- Added the ability to download configurations from TFTP/SFTP servers via WEB interface;
- Added the ability to choose between MAC and 802.1x authentication.
Fixed:
- Fixed a bug where the original broadcast DHCP Discover was switched on Uplink in a scheme with configured DHCP Relay within the same VLAN;
- Fixed a bug where the lease of an IP address was not renewed in a scheme with configured DHCP Relay within the same VLAN;
- Fixed a bug that caused incorrect display of fan speeds when polling via SNMP;
- Fixed a bug where a GET request would return NULL if it contained an invalid OID;
- Fixed a conflict between the global voice vlan id and active port-channel settings;
- Fixed a bug where the radius vlan attribute did not work in multi-session mode;
- Fixed a bug with simultaneous operation of Dot1x and MAB authorization.
Firmware Version 10.3.6
Added:
- Added the ability to enable DHCPv4/v6 snooping on 64 VLANs;
- Added the ability to set an IP address for accessing the snmp community;
- Added support for the Session-Timeout Radius attribute;
- Added support for the Termination-Action Radius attribute;
- Added support for the Cisco GLC-BX SFP module;
- Added verification of the current software version with the one received via DHCP Option 43, if the versions match, the software will not be updated;
- Added the ability to set a MAC ACL for a host with a MAC address 00:00:00:00:00:00.
Fixed:
- Fixed an error where the lldp med-app-type voice vlan vlan-id string disappeared from running-config after configuring the switchport voice vlan;
- Fixed an error where the ssh auth-type ip setting disappeared from running-config after ssh restart SSH Server error fixes;
- Fixed an error where speed matching with the optical 100M SFP module did not work;
- Fixed an error where the VLAN was not deleted from the port when executing the default interface command;
- Verification of the LACP Admin Key received from the partner is disabled.
Firmware Version 10.3.5
Added:
- Added Rapid-PVST functionality.
Fixed:
- Fixed an error that caused emergency fan logs to appear on the MES2424P device;
- Fixed an issue where configuring backup server sftp led to high CPU usage;
- Fixed the conflict of adding VLANs to interfaces in general mode when Dot1x settings are configured on other interfaces;
- Fixed an error where the default logging setting was displayed in the configuration;
- Fixed an error that occurred when resetting the interface configuration;
- Fixed the error of applying startup-config after restarting the device;
- Fixed an error that causes the switch to freeze while booting a device with a large number of MSTP instances;
- Fixed the problem of unicast ARP packet flooding when ARP Inspection is enabled.
Firmware Version 10.3.4
Added:
- Added support for the RADIUS VLAN attribute for Dot1x;
- Added dynamic distribution of SQinQ and MBV rules;
- Added the ability to change the password using a request from the TACACS+ server;
- Added the ability to issue a DHCP address by a DHCP server by interface number;
- Added counters for ACL rules;
- DNS Client added;
- Increased the maximum number of L3 interfaces to 20;
- Increased the maximum number of L3 IPv4 Unicast routes to 496;
- Increased the maximum number of L3 IPv6 Unicast routes to 124.
Fixed:
- Fixed a bug when sending syslog messages in an SSH session;
- Improved stability of the ERPS protocol;
- Fixed a bug when processing Voice VLAN events;
- Fixed problems with Voice VLAN operation on ports in general mode;
- Fixed incomplete recording of information when redirecting show tech-support to a file;
- Fixed the grep function for the show tech-support team;
- Fixed an error saving a description consisting of several words;
- Added the ability to write the interface type and identifier in commands together and separately;
- Implemented auto-completion of the interface name by Tab;
- Fixed type and values for the eltexPhyTransceiverInfoDiagnosticSupported SNMP table;
- Fixed return values for the SNMP table IF-MIB::ifHighSpeed;
- Fixed visual and syntax errors in MIB files;
- Fixed a bug when removing the switch from the TACACS+ server;
- Fixed interface initialization error when booting after upgrading the switch from older versions;
- Fixed bugs that cause the management switch to hang;
- Fixed a bug when breaking Telnet sessions;
- Fixed pagination when connecting via SSH;
- Fixed the output of the show ip dhcp server pools command.
Firmware Version 10.3.3.1
Fixed:
- Fixed the problem with incorrect routes when the switch receives the address via DHCP via DHCP-relay.
Firmware Version 10.3.3
Added:
- Added support for DHCP packets with Broadcast flag in DHCP Relay;
- Added discard-shutdown option for Port Security;
- Added show-command to view list of ACL rules on interfaces;
- Added the ability to add ACE description;
- Added the ability to delete multiple static routes by mask or all at once via no ip route command;
- Added interface statistics for ARP Inspection;
- Added information about interface media-type to show interfaces status output;
- Added syslog messages display in CLI for TELNET/SSH protocols;
- Added the ability to configure netmask in /xx prefix length format;
- Added show ip route command to show tech-support output;
- Added support for hardware IPv6 routing;
- Added support for dynamic routing protocols OSPFv2/3, RIPv1/2.
Fixed:
- Fixed incorrect MAC address removal from MAC table after exceeding ARP timeout for nexthop static routes;
- Fixed adding incorrect padding for DHCP packets in DHCP Relay;
- Adjusted IGMP Snooping queue limits on CPU to minimize multicast delays with a large volume of IGMP messages;
- Fixed bug in MSTP which caused network loops after the reboot.
Firmware Version 10.3.2
Added:
- Added Voice VLAN feature;
- Added the ability to run Voice VLAN and Dot1x together;
- Added SNMP Trap for Storm Control;
- Added SNMP Trap for Port Security;
- Added logging of critical errors;
- Removed unnecessary firewall messages when connecting via Telnet/SSH to secondary IP addresses;
- Added protection from upgrading to unsupported SW version;
- The System Contact and System Location fields are now empty by default;
- Added L2 support code to SNMP OID sysServices;
- Added the ability to change the parameters of the current user without breaking the session;
- Added the ability to switch to the global configuration mode using the "configure" command;
- The "show ip binding" command is now available to a user with privilege level 1;
- The "show logging" command is now available to a level 1 user;
- Improved appearance and options for configuring VLAN via the WEB interface;
- Added system description command.
Fixed:
- Fixed a bug where the device terminated the session when entering more than 20 characters in the login;
- Fixed removal of Multicast-TV VLAN from all ports when deleting VLAN;
- Fixed switch freezing when performing cable diagnostics via WEB;
- Fixed switch freezing when trying to connect externally via SFTP;
- Fixed a bug where it was impossible to replace a dynamic DHCP Snooping entry with a static one;
- Fixed port blocking issue after reboot when STP is globally disabled;
- Fixed issue with default gateway configuration when receiving DHCP option;
- The System Contact and System Location fields are set to empty by default.
Firmware Version 10.3.1
Added:
- Added support for hardware IPv4 routing;
- Added VRRP support.
Fixed:
- Fixed an issue that caused devices to reboot when interacting with DHCP server binding entries.
Firmware Version 10.2.10
Added:
- Added partial support for Multiple failure processing in ERPS;
- Implemented a mechanism for interacting with ERPS subrings;
- Implemented DHCP server feature;
- Added None method for authorization;
- Implemented Guest and Unauthenticated VLAN features;
- Implemented cause of reboot monitoring via SNMP;
- Added command to enable DHCP-relay for VLAN.
Fixed:
- Fixed incorrect simultanious work of DHCP-relay and DHCP-snooping;
- Increased the maximum number of characters in username to 64;
- Fixed bug with polling SNMP tables when saving the configuration;
- Fixed error when creating interface VLAN in WEB;
- Redesigned VLAN configuration page in WEB;
- Fixed the mechanism of adapting the AAA configuration to the new syntax.
Firmware Version 10.2.9.4
Added:
- Added authorization using SSH keys;
- Added "spanning-tree bpdufilter" command hint when configured in interface-range context;
- All possible special characters for username and SNMP commands are now supported;
- Increased the maximum number of characters in the name, hostname, description fields;
- Increased the maximum number of characters in the name, hostname, description fields;
- DHCP opt 82 and PPPoE IA settings are now separated;
- Added MAC address value to show system info output;
- Added support for the following cryptographic algorithms in SSH: aes192-cbc, aes128-ctr, aes192-ctr, aes256-ctr;
- Added Calling-Station-Id field in access-request packet for 802.1x;
- Added the ability to completely change the configuration from a file without rebooting the device.
Fixed:
- Improved stability of the ERPS protocol;
- Fixed incorrect display of "ipv6 nd inspection" command;
- Fixed interfaces status changing when updating the device;
- Optimized logging of executed commands when using "write startup-config";
- Optimized "show running-config command" output;
- Improved "spanning-tree bpdufilter enable" command hint;
- Transceiver in/out power via SNMP is now displayed in dBm.
Firmware Version 10.2.8.2
Added:
- Implemented cold/warm startup logging;
- Implemented chain authentication method for AAA;
- Added the ability to use both RADIUS and TACACS for authentication;
- Added the ability to set your own value in the NAS-Identifier field;
- Added the ability to configure the service policy without binding it to the interface;
- Added the ability to configure src and dst ports for DHCP Relay;
- Changed ZTP mode;
- Added support for the ERPS protocol;
- Added support for the HTTPS protocol;
- Added the ability to configure DHCP Relay without an IP address on client VLANs;
- Implemented IGMP-Proxy function for MES2424, MES2448 models.
Fixed:
- Fixed RX rate limit logging;
- Fixed xSTP work with LBD-frames;
- Fixed incorrect privilege assigning during RADIUS-authentication;
- Fixed dropping all traffic when setting rate-limit more than 1 Gbps;
- Configuring authorized-manager ip-source 0.0.0.0 0.0.0.0 allows authorization from any ip addresses;
- Optimized work with memory;
- Fixed tips for enable/disable commands;
- Fixed reboot and authentication SNMP-trap;
- Fixed possible duplication of the main MAC address from the MAC LAG of another device;
- Fixed work of dot1x port-control force-authorized in multi-session mode;
- Fixed STP operation when changing the status of a port on which STP is disabled, the MAC address table is no longer being flushed;
- Fixed problem with displaying multicast groups in the forwarding-database table;
- Fixed problem with IGMP-report processing in IGMP Proxy;
- Access to WEB-interface for users with privileges below 15 is prohibited;
- Fixed bootloader version view.