S3300-52X-PoE+

GSM7228PS (S3300) switch

GSM7228PS (S3300)

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152PoE (48)no PoE (4)
Port map as the library addresses these ports — schematic, not a faceplate layout.

A 52-port Smart Managed Pro switch with 48 PoE ports — despite the GSM7228PS part-number family suggesting 28. The registry key is gsm7228ps; s3300 is an alias for the same record, because the firmware’s own sysDescr and the marketing name are both “S3300-52X”.

At a glance

Field

Value

Registry key

gsm7228ps

Product name

GSM7228PS (S3300)

Class

smart managed pro

Ports

52

PoE (PSE) ports

48

Backends

SNMP, HTTP, TELNET

SNMP vendor subtree

1.3.6.1.4.1.4526.11

VLAN write dialect

Q-BRIDGE static PortLists (read-modify-write)

VLAN write quirk

egress and untagged PortLists must travel in SEPARATE PDUs, egress first

Aliases

s3300

MAC/FDB table

yes

Live-verified at 10.1.5.11. Capture: tests/fixtures/captures/gsm7228ps.json; seed: seed_gsm7228ps().

What works, over which protocol

Operation

What it does

SNMP

HTTP

TELNET

get_ports

Per-port link/admin status

✓

✓

✓

get_stats

Per-port octet/packet counters

✓

✓

✓

get_vlans

VLAN list with tagged/untagged members

✓

✓

✓

get_pvids

Per-port PVID

✓

✓

✓

get_lldp

LLDP neighbour table

✓

✓

✓

get_macs

MAC/FDB forwarding table

✓

✓

✓

get_poe

Per-port PoE status and power draw

✓

✓

✓

get_sensors

Fan/PSU/temperature sensors

✓

— [gsm7228ps-1]

✓

get_mgmt_ip

Management IP configuration

✓

✓

✓

get_hostname

The switch’s host name

✓

— [gsm7228ps-2]

✓

get_users

Local login accounts and their access level

— [gsm7228ps-3]

— [gsm7228ps-4]

✓

get_services

Which management services (http/https/telnet/ssh) are enabled

— [gsm7228ps-5]

— [gsm7228ps-6]

✓

get_syslog

Remote-logging configuration and collectors

✓

✓

✓

nsdp_device

Full NSDP device record

— [gsm7228ps-7]

— [gsm7228ps-7]

— [gsm7228ps-7]

set_port_enabled

Bring a port up or down

✓

✓

✓

set_poe

Enable or disable PoE on a port

✓

✓

✓

cycle_poe

Power-cycle a PoE port

✓

✓

✓

clear_poe_fault

Clear a latched PoE fault

✓

✓

✓

set_port_description

Set or clear a port’s description

✓

— [gsm7228ps-8]

✓

set_port_speed

Force a port’s speed/duplex, or restore auto-negotiation

— [gsm7228ps-9]

— [gsm7228ps-10]

✓

set_flow_control

Turn IEEE 802.3x flow control on or off for a port

— [gsm7228ps-11]

— [gsm7228ps-11]

✓

set_pvid

Set a port’s PVID

✓

✓

✓

set_vlan_membership

Set a port tagged/untagged/excluded on a VLAN

✓

✓

✓

create_vlan

Create a VLAN

✓

— [gsm7228ps-12]

✓

delete_vlan

Delete a VLAN

✓

— [gsm7228ps-13]

✓

set_mgmt_ip

Set the management IP/mask/gateway

✓

✓

✓

set_hostname

Set the switch’s host name

✓

— [gsm7228ps-14]

✓

set_syslog_enabled

Turn remote logging on or off

✓

— [gsm7228ps-15]

✓

add_syslog_collector

Add a remote syslog collector

— [gsm7228ps-16]

— [gsm7228ps-16]

✓

remove_syslog_collector

Remove a remote syslog collector

✓

— [gsm7228ps-17]

✓

upload_certificate

Upload an HTTPS certificate over the web UI

— [gsm7228ps-18]

✓

— [gsm7228ps-18]

upload_certificate_scp

Deploy an HTTPS certificate via FASTPATH copy scp://

— [gsm7228ps-19]

— [gsm7228ps-19]

— [gsm7228ps-20]

[gsm7228ps-1]

model ‘gsm7228ps’ web UI has no page for get_sensors (Fan/PSU/temperature sensors)

[gsm7228ps-2]

model ‘gsm7228ps’ web UI has no page for get_hostname (The switch’s host name)

[gsm7228ps-3]

get_users is served only over CONSOLE, HTTP, SSH, TELNET

[gsm7228ps-4]

model ‘gsm7228ps’ web UI has no page for get_users (Local login accounts and their access level)

[gsm7228ps-5]

get_services is served only over CONSOLE, HTTP, SSH, TELNET

[gsm7228ps-6]

model ‘gsm7228ps’ web UI has no page for get_services (Which management services (http/https/telnet/ssh) are enabled)

[gsm7228ps-7] (1,2,3)

nsdp_device is served only over NSDP

[gsm7228ps-8]

model ‘gsm7228ps’ web UI has no page for set_port_description (Set or clear a port’s description)

[gsm7228ps-9]

set_port_speed is served only over CONSOLE, HTTP, SSH, TELNET

[gsm7228ps-10]

model ‘gsm7228ps’ web UI has no page for set_port_speed (Force a port’s speed/duplex, or restore auto-negotiation)

[gsm7228ps-11] (1,2)

set_flow_control is served only over CONSOLE, SSH, TELNET

[gsm7228ps-12]

model ‘gsm7228ps’ web UI carries no CSRF ‘hash’ token, which the HTTP create_vlan writer requires

[gsm7228ps-13]

model ‘gsm7228ps’ web UI carries no CSRF ‘hash’ token, which the HTTP delete_vlan writer requires

[gsm7228ps-14]

model ‘gsm7228ps’ web UI has no page for set_hostname (Set the switch’s host name)

[gsm7228ps-15]

set_syslog_enabled is served only over CONSOLE, SNMP, SSH, TELNET

[gsm7228ps-16] (1,2)

add_syslog_collector is served only over CONSOLE, SSH, TELNET

[gsm7228ps-17]

model ‘gsm7228ps’ web UI has no page for remove_syslog_collector (Remove a remote syslog collector)

[gsm7228ps-18] (1,2)

upload_certificate is served only over HTTP

[gsm7228ps-19] (1,2)

upload_certificate_scp is served only over CONSOLE, SSH, TELNET

[gsm7228ps-20]

model ‘gsm7228ps’ has no known copy-scp SSL-certificate deploy profile

Measured behaviour

Identified by sysObjectID, not sysDescr. Its description text is indistinguishable from the unregistered S3300-28X, so matching on it would be a coin flip. detect_model() prefers the product OID 4526.100.10.19 — the product identifier, distinct from the 4526.11 vendor data subtree its sensors and PoE live under. Confusing the two is what made auto-detection fail on this switch.

Its CLI is telnet on port 60000, not 23, and it runs no SSH listener on any port — its own tcpConnTable shows only 80, 443 and 60000. So the CLI backend here is telnet only, and the transport dials the port from its spec.

Setting a port’s egress bit makes it an untagged member. That side effect beats an untagged varbind carried in the same PDU, so a TAGGED request silently lands untagged:

one PDU  : egress=[1] untagged=[1]   ← untagged intent lost
two PDUs : egress=[1] untagged=[]    ← correct, CLI confirms "Tagged"

snmp_vlan_split_membership_writes turns the two-PDU sequence on for this model alone.

“The SNMP agent is dead” was a wrong credential. This switch has no private community; it publishes pib and public, both read-write. An agent silently drops an unauthorised request, so a wrong write community looks exactly like an unreachable host — reads had worked the whole time.

Certificate upload is an HTTP multipart form, not SCP — the opposite of its FASTPATH cousins. upload_certificate() is the right call for this model.

Protocols