DATA SHEET
ARUBA 3810 SWITCH SERIES
PRODUCT OVERVIEW
The Aruba 3810 Switch Series is an industr y-leading mobile
campus access solution for enterprises, SMBs, and branch
oce networks. With HPE Smart Rate multi-gigabit ports for
high-speed IEEE 802.11ac devices, the Aruba 3810 will prepare
your network for tomorrow. Right-size deployment and back
haul capacity with modular 10GbE and 40GbE uplinks.
Full PoE+ provisioning available on 48-ports. Dual, redundant,
hot-swappable power supplies and innovative backplane
stacking technology delivers resiliency and scalability in a
convenient 1U form factor. Advanced Layer 2 and 3 feature
set with OSPF, IPv6, IPv4 BGP, Dynamic Segmentation,
robust QoS, and policy-based routing are included with no
software licensing.
A powerful Aruba ProVision ASIC delivers performance,
robust feature support, and value with exible
programmability for future applications. Easy to deploy and
manage with advanced security and network management
tools like Aruba ClearPass Policy Manager and Aruba AirWave.
With support from Aruba Central, you can quickly set up
remote branch sites with little or no IT support.
FEATURES AND BENEFITS
Software-dened networks
• Supports multiple programmatic interfaces, including REST
APIs and Openow 1.0 and 1.3, to enable automation of
network operations, monitoring, and troubleshooting
Unied wired and wireless
• Aruba ClearPass Policy Manager provides proling,
authentication, and policy management across multi-
vendor wired and wireless networks
• Switch auto-conguration automatically congures switch
for dierent settings such as VLAN, CoS, PoE max power,
and PoE priority when Aruba AP is detected
• User Role denes a set of switch-based policies in areas
such as security, authentication, and QoS. A user role can
be assigned to a group of users or devices, using switch-
based local user role or download from ClearPass
KEY FEATURES
• Advanced Layer 3 switch series with backplane
stacking, Dynamic Segmentation, low latency
and resiliency
• Security and network management tools with
Aruba ClearPass Policy Manager, AirWave and
Central support
• Modular line rate 10GbE and 40GbE ports for
wireless aggregation
• HPE Smart Rate for high-speed multi-gigabit
bandwidth (IEEE 802.3bz) and PoE+ power
• Ready for the software dened network with REST
APIs and OpenFlow support
• Dynamic Segmentation provides a secure tunnel that
transports network trac on a per-port or per-user role
basis to an Aruba Controller. In a per-user role Tunnel
Node, users are authenticated by the ClearPass Policy
Manager which directs trac to be tunneled to an Aruba
controller or switch locally
• Static IP Visibility allows ClearPass to do accounting for
clients with static IP address
Quality of Service (QoS)
• Advanced classier-based QoS classies trac using multiple
match criteria based on Layer 2, 3, and 4 information; applies
QoS policies such as setting priority level and rate limit to
selected trac on a per-port or per-VLAN basis
• Layer 4 prioritization enables prioritization based on
TCP/UDP port numbers
• Class of Service (CoS) sets the IEEE 802.1p priority tag
based on IP address, IP Type of Service (ToS), Layer 3
protocol, TCP/UDP port number, source port, and DiServ
DATA SHEET
ARUBA 3810 SWITCH SERIES
• Bandwidth shaping
- Port-based rate limiting provides per-port ingress-/
egress-enforced increased bandwidth
- Classier-based rate limiting uses an access control list
(ACL) to enforce increased bandwidth for ingress trac
on each port
- Reduced bandwidth provides per-port, per-queue
egress-based reduced bandwidth
• Remote intelligent mirroring mirrors selected ingress/egress
trac based on an ACL, port, MAC address, or VLAN to a
local or remote HPE 8200 zl, 6600, 6200 yl, 5400 zl, 5400R,
or 3500 Switch anywhere on the network
• Remote monitoring (RMON), Extended RMON (XRMON),
®
and sFlow
v5 provide advanced monitoring and reporting
capabilities for statistics, history, alarms, and events
• Trac prioritization allows real-time trac classication
into eight priority levels that are mapped to eight queues
• Unknown Unicast Rate Limiting throttles unicast packets
with unknown destination addresses and limits ooding on
the VLAN
Management
• Flexible management with same hardware – Supports both
cloud-based Central and on-premise AirWave with the
same hardware ensuring change management platform
without ripping and replacing switching infrastructure
• Aruba Central cloud-based management platform oers
simple, secure, and cost eective way to manage switches
• Built-in programmable and easy to use REST API interface
provides conguration automation for Mobile-rst
campus networks
• Friendly port names allows assignment of descriptive
names to ports
• IEEE 802.1AB Link Layer Discovery Protocol (LLDP)
advertises and receives management information from
adjacent devices on a network, facilitating easy mapping
by network management applications
• Command authorization leverages RADIUS to link a
custom list of CLI commands to an individual network
administrator’s login; an audit trail documents activity
• Multiple conguration les stores easily to the ash image
• Dual ash images provides independent primary and
secondary operating system les for backup while upgrading
• Out-of-band Ethernet management port enables
management over a separate physical management
network; and keeps management trac segmented from
network data trac
• Comware CLI
- Comware-compatible CLI bridges the experience of
Hewlett Packard Enterprise (HPE) Comware CLI users
who are using the ArubaOS-Switch CLI
- Display and fundamental Comware CLI commands are
natively embedded in the switch CLI; display output is
formatted as on Comware-based switches; fundamental
commands provide Comware-familiar initial switch setup
- Conguration Comware CLI commands when Comware
commands are entered, CLI help is elicited to formulate
the correct ArubaOS-Switch software CLI command
• Zero-Touch Provisioning (ZTP) simplied installation of the
switch infrastructure using Aruba Activate-based or DHCP-
based process with AirWave Network Management
• Unidirectional Link Detection (UDLD) supports HPE UDLD
and DLDP protocols to monitor a cable between two
switches and shut down the ports on both ends if a broken
link is detected, preventing network problems such as loops
• IP SLA for Voice Monitor quality of voice trac with UDP
Jitter and UDP Jitter for VoIP tests
Connectivity
• Jumbo frames on Gigabit Ethernet and 10-Gigabit Ethernet
ports, jumbo frames allow high-performance remote
backup and disaster-recovery services
• IEEE 802.3at Power over Ethernet (PoE+) provides up to 30
W per port that allows support of the latest PoE+ capable
devices such as IP phones, wireless access points, and
security cameras, as well as any IEEE 802.3af compliant
end device; eliminates the cost of additional electrical
cabling and circuits that would otherwise be necessary in
IP phone and WLAN deployments
• Pre-standard PoE support detects and provides power to
pre-standard PoE devices
• Choice of uplinks
- SFP+ uplink models provide ber-optic (up to 70 km) or
direct-attach-cable (DAC) connectivity
- 10GBASE-T uplink models oer 10GbE speeds, using
standard RJ-45 connectors and standard twisted-pair
cabling up to 100 m
• Auto-MDIX provides automatic adjustments for straight-
through or crossover cables on all RJ-45 ports
• IPv6
- IPv6 host enables switch management in an IPv6 network
- Dual stack (IPv4 and IPv6) transitions IPv4 to IPv6,
supporting connectivity for both protocols
- MLD snooping forwards IPv6 multicast trac to the
appropriate interface
DATA SHEET
ARUBA 3810 SWITCH SERIES
- IPv6 ACL/QoS supports ACL and QoS for IPv6 trac
- IPv6 routing supports static, RIPng, OSPFv3 routing
protocols
- 6in4 tunneling supports encapsulation of IPv6 trac in
IPv4 packets
- Security provides RA guard, DHCPv6 protection, dynamic
IPv6 lockdown, and ND snooping
Performance
• Selectable queue congurations allows for increased
performance by selecting the number of queues
and associated memory buering that best meet the
requirements of the network applications
• Energy-ecient design
- 80 PLUS Silver Certied Power Supply increases power
eciency and savings
- Energy-ecient Ethernet (EEE) support reduces power
consumption in accordance with IEEE 802.3az
• Meshed stacking technology
- High-performance stacking provides up to 336 Gbps of
stacking throughput; each 4-port stacking module can
support up to 42 Gbps in each direction per stacking port
- Ring, chain, and mesh topologies support up to a
10-member ring or chain and 5-member fully meshed
stacks; meshed topologies oer increased resiliency vs. a
standard ring
- Virtualized switching provides simplied management as
the switches appear as a single chassis when stacked
• Aruba Provision ASIC architecture is designed with the
latest ProVision ASIC, providing very low latency, increased
packet buering, and adaptive power consumption
• Dual hot-swappable power supplies
- Increased resiliency provides secondary power supply
to enable complete switch power redundancy in case of
power line or supply failure
- Increased PoE+ power provides the secondary power
supply to increase the total available PoE+ power
• Distributed trunking enables loop-free and redundant
network topology without using Spanning Tree Protocol;
allows a server or switch to connect to two switches using
one logical trunk for redundancy and load sharing
• SmartLink provides easy-to-congure link redundancy of
active and standby links
Layer 2 switching
• IEEE 802.1ad QinQ increases the scalability of an Ethernet
network by providing a hierarchical structure; connects
multiple LANs on a high-speed campus or metro network
• VLAN support and tagging supports the IEEE 802.1Q
standard and 4096 VLANs simultaneously
• IEEE 802.1v protocol VLANs isolate select non-IPv4
protocols automatically into their own VLANs
• MAC-based VLAN provides granular control and security;
uses RADIUS to map a MAC address/user to specic VLANs
• Rapid Per-VLAN Spanning Tree (RPVST+) allows each
VLAN to build a separate spanning tree to improve link
bandwidth usage; is compatible with PVST+
• Aruba 3810 switch meshing dynamically load balances
across multiple active redundant links to increase available
aggregate bandwidth; allows concurrent Layer 3 routing
• GVRP and MVRP allows automatic learning and dynamic
assignment of VLANs
Resiliency and high availability
• Virtual Router Redundancy Protocol (VRRP) allows groups of
two routers to back each other up dynamically to create highly
available routed environments in IPv4 and IPv6 networks
• Nonstop switching and routing improves network
availability to better support critical applications, such as
unied communication and mobility; trac will continue to
be forwarded during failovers, when the backup member
of the stack becomes the commander
• IEEE 802.3ad Link Aggregation Protocol (LACP) and Hewlett
Packard Enterprise port trunking support up to 144 trunks,
each with up to 8 links (ports) per trunk
• IEEE 802.1s Multiple Spanning Tree provides high link
availability in multiple VLAN environments by allowing
multiple spanning trees; provides legacy support for IEEE
802.1d and IEEE 802.1w
Layer 3 services
• Loopback interface address denes an address in Routing
Information Protocol (RIP) and Open Shortest Path First
(OSPF), improving diagnostic capability
• Route maps provide more control during route
redistribution; allow ltering and altering of route metrics
• User datagram protocol (UDP) helper function allows
UDP broadcasts to be directed across router interfaces to
specic IP unicast or subnet broadcast addresses; and helps
prevent server spoong for UDP services such as DHCP
• DHCP server centralizes and reduces the cost of IPv4
address management
• Bidirectional Forwarding Detection (BFD) enables link
connectivity monitoring and reduces network convergence
time for static route, OSPFv2, and VRRP
DATA SHEET
ARUBA 3810 SWITCH SERIES
Layer 3 routing
• Static IP routing provides manually congured routing for
both IPv4 and IPv6 networks
• OSPF provides OSPFv2 for IPv4 routing and OSPFv3 for
IPv6 routing
• Policy-based routing makes routing decisions based on
policies set by the network administrator
• Border Gateway Protocol (BGP) provides IPv4 Border Gateway
Protocol routing, which is scalable, robust, and exible
• Routing Information Protocol (RIP) provides RIPv1, RIPv2,
and RIPng
Security
• Control Plane Policing sets rate limit on control protocols
to protect CPU overload from DOS attacks
• Source-port ltering allows only specied ports to
communicate with each other
• RADIUS/TACACS+ eases switch management security
administration by using a password authentication server
• Secure shell encrypts all transmitted data for secure
remote CLI access over IP networks
• Secure Sockets Layer (SSL) encrypts all HTTP trac,
allowing secure access to the browser-based management
GUI in the switch
• Port security allows access only to specied MAC addresses,
which can be learned or specied by the administrator
• MAC address lockout prevents particular congured MAC
addresses from connecting to the network
• Detection of malicious attacks monitors 10 types of
network trac and sends a warning when an anomaly that
potentially can be caused by malicious attacks is detected
• Secure FTP allows secure le transfer to and from the
switch; protects against unwanted le downloads or
unauthorized copying of a switch conguration le
• Switch management logon security helps secure switch CLI
logon by optionally requiring either RADIUS or TACACS+
authentication
• Secure management access delivers secure encryption of
all access methods (CLI, GUI, or MIB) through SSHv2, SSL,
and/or SNMPv3
• ICMP throttling defeats ICMP denial-of-service attacks
by enabling any switch port to automatically throttle
ICMP trac automatically
• Identity-driven ACL enables implementation of a highly
granular and exible access security policy and VLAN
assignment specic to each authenticated network user
• STP BPDU port protection blocks Bridge Protocol Data
Units (BPDUs) on ports that do not require BPDUs,
preventing forged BPDU attacks
• Dynamic IP lockdown works with DHCP protection to block
trac from unauthorized hosts, preventing IP source
address spoong
• DHCP protection blocks DHCP packets from unauthorized
DHCP servers, preventing denial-of-service attacks
• Dynamic ARP protection blocks ARP broadcasts from
unauthorized hosts, preventing eavesdropping or theft of
network data
• STP root guard protects the root bridge from malicious
attacks or conguration mistakes
• Management Interface Wizard helps secure management
interfaces such as SNMP, telnet, SSH, SSL, Web, and USB at
the desired level
• Security banner displays a customized security policy when
users log in to the switch
• Switch CPU protection provides automatic protection against
malicious network trac trying to shut down the switch
• ACLs provide ltering based on the IP eld, source/
destination IP address/subnet and source/destination
TCP/UDP port number on a per-VLAN or per-port basis
• Multiple authentication methods
- IEEE 802.1X authenticates multiple IEEE 802.1X users per
port; prevents a user from “piggybacking” on another
user’s authentication
- Web-based authentication authenticates from Web
browser for clients that do not support 802.1X supplicant
- MAC-based authentication authenticates client with the
RADIUS server based on client’s MAC address
- Concurrent authentication modes enables a switch port
to accept up to 32 sessions of 802.1X, Web, and MAC
authentication
• Private VLAN provides network security by restricting peer-
to-peer communication to prevent a variety of malicious
attacks; typically a switch port can only communicate with
other ports in the same community and/or an uplink port,
regardless of VLAN ID or destination MAC address
• IEEE 802.1AE MACsec provides security on a link between
two switch ports (1Gbps or 10Gbps) using standard
encryption and authentication
• Open Authentication Role simplies rst-time deployment
of AAA in browneld deployments by allowing full network
access for failed clients and provides instant connectivity
as soon as a client is plugged-in
DATA SHEET
ARUBA 3810 SWITCH SERIES
• Critical Authentication Role ensures that important
infrastructure devices such as IP phones are allowed
network access even in the absence of a RADIUS server
• MAC Pinning allows non-chatty legacy devices to stay
authenticated by pinning client MAC addresses to the port
until the clients logo or get disconnected
Convergence
• IP multicast snooping (data-driven IGMP) prevents ooding
of IP multicast trac
• LLDP-MED (Media Endpoint Discovery) denes a standard
extension of LLDP that stores values for parameters such
as QoS and VLAN to congure network devices such as IP
phones automatically
• PoE allocations supports multiple methods (automatic,
IEEE 802.3af class, LLDP-MED, or user-specied) to allocate
PoE power for more ecient energy savings
• Protocol Independent Multicast for IPv6 supports one-to-
many and many-to-many media casting use cases such as
IPTV over IPv6 networks
• IP multicast routing includes PIM sparse and dense modes
to route IP multicast trac
• Auto VLAN conguration for voice
- RADIUS VLAN uses a standard RADIUS attribute
and LLDP-MED to congure a VLAN automatically for
IP phones
- CDPv2 uses CDPv2 to congure legacy IP phones
• Local MAC Authentication assigns attributes such as VLAN
and QoS using locally congured prole that can be a list
of MAC prexes
Warranty and support
• Limited Lifetime Warranty
See www.hpe.com/networking/warrantysummary for
warranty and support information included with your
product purchase.
• Software releases to nd software for your product, refer
to www.hpe.com/networking/support; for details on the
software releases available with your product purchase,
refer to www.hpe.com/networking/warrantysummary
SPECIFICATIONS
Included accessories
I/O ports and slots
Additional ports and slots
Aruba 3810M 24G 1-slot Switch
(JL071A)
1 Aruba 3810 Switch Fan Tray
(JL088A)
24 RJ-45 autosensing 10/100/1000
ports (IEEE 802.3 Type 10BASE-T,
IEEE 802.3u Type 100BASE-TX, IEEE
802.3ab Type 1000BASE-T); Duplex:
10BASE-T/100BASE-TX: half or full;
1000BASE-T: full only; Ports 1 – 24
support MACSec
1 open module slot
Supports a maximum of 4 SFP+
ports or 1 40GbE ports, with optional
module or 4 Smart Rate ports
1 stacking module slot
1 RJ-45 serial console port
1 RJ-45 out-of-band management
port
1 dual-personality (RJ-45 or USB
micro-B)
Aruba 3810M 48G 1-slot Switch
(JL072A)
1 Aruba 3810 Switch Fan Tray
(JL088A)
48 RJ-45 autosensing 10/100/1000
ports (IEEE 802.3 Type 10BASE-T,
IEEE 802.3u Type 100BASE-TX, IEEE
802.3ab Type 1000BASE-T); Duplex:
10BASE-T/100BASE-TX: half or full;
1000BASE-T: full only; Ports 1 – 48
support MACSec
1 open module slot
Supports a maximum of 4 SFP+
ports or 2 40GbE ports, with optional
module or 4 Smart Rate ports
1 stacking module slot
1 RJ-45 serial console port
1 RJ-45 out-of-band management
port
1 dual-personality (RJ-45 or USB
micro-B)
Aruba 3810M 24G PoE+ 1-slot
Switch (JL073A)
1 Aruba 3810 Switch Fan Tray
(JL088A)
24 RJ-45 autosensing 10/100/1000
PoE+ ports (IEEE 802.3 Type
10BASE-T, IEEE 802.3u Type
100BASE-TX, IEEE 802.3ab Type
1000BASE-T, IEEE 802.3at PoE+);
Duplex: 10BASE-T/100BASE-TX: half
or full; 1000BASE-T: full only; Ports
1 – 24 support MACSec
1 open module slot
Supports a maximum of 4 SFP+
ports or 1 40GbE ports, with optional
module or 4 Smart Rate ports
1 stacking module slot
1 RJ-45 serial console port
1 RJ-45 out-of-band management
port
1 dual-personality (RJ-45 or USB
micro-B)
SPECIFICATIONS
DATA SHEET
ARUBA 3810 SWITCH SERIES
Aruba 3810M 24G 1-slot Switch
(JL071A)
Aruba 3810M 48G 1-slot Switch
(JL072A)
Aruba 3810M 24G PoE+ 1-slot
Switch (JL073A)
Power supplies
2 power supply slots
1 minimum power supply
required (ordered separately)
2 power supply slots
1 minimum power supply
required (ordered separately)
2 power supply slots
1 minimum power supply
required (ordered separately)
Fan tray
Includes:
1 x JL088A
1 fan tray slot
Switch ships with 1 JL088A fan tray
installed. Spares ordered separately.
Includes:
1 x JL088A
1 fan tray slot
Switch ships with 1 JL088A fan tray
installed. Spares ordered separately.
Includes:
1 x JL088A
1 fan tray slot
Switch ships with 1 JL088A fan tray
installed. Spares ordered separately.
Physical characteristics
Dimensions 17.42(w) x 16.98(d) x 1.73(h) in
(44.25 x 43.13 x 4.39 cm)
(1U height)
17.42(w) x 16.98(d) x 1.73(h) in
(44.25 x 43.13 x 4.39 cm)
(1U height)
17.42(w) x 16.98(d) x 1.73(h) in
(44.25 x 43.13 x 4.39 cm)
(1U height)
Weight 12.76 lb (5.79 kg) 13.20 lb (5.99 kg) 13.02 lb (5.91 kg)
Memory and processor
P2020 Dual Core @ 1.2 GHz, 4 GB
DDR3 SDRAM, 1 GB SD Card
Dual ARM
®
Coretex A9 @ 1 GHz,
2 GB DDR3 SDRAM; Packet buer
size: 13.5 MB Internal
P2020 Dual Core @ 1.2 GHz, 4 GB
DDR3 SDRAM, 1 GB SD Card
Dual ARM® Coretex A9 @ 1 GHz,
2 GB DDR3 SDRAM; Packet buer
size: 13.5 MB Internal
P2020 Dual Core @ 1.2 GHz, 4 GB
DDR3 SDRAM, 1 GB SD Card
Dual ARM® Coretex A9 @ 1 GHz,
2 GB DDR3 SDRAM; Packet buer
size: 13.5 MB Internal
Mounting and enclosure
Mounts in an EIA-standard 19 in.
telco rack or equipment cabinet
(hardware included); Horizontal
surface mounting only
Mounts in an EIA-standard 19 in.
telco rack or equipment cabinet
(hardware included); Horizontal
surface mounting only
Mounts in an EIA-standard 19 in.
telco rack or equipment cabinet
(hardware included); Horizontal
surface mounting only
Performance
IPv6 Ready Certied IPv6 Ready Certied IPv6 Ready Certied
1000 Mb Latency < 2.8 µs (FIFO 64-byte packets) < 2.8 µs (FIFO 64-byte packets) < 2.8 µs (FIFO 64-byte packets)
10 Gbps Latency < 1.8 µs (FIFO 64-byte packets) < 1.8 µs (FIFO 64-byte packets) < 1.8 µs (FIFO 64-byte packets)
40 Gbps Latency < 1.5 µs (FIFO 64-byte packets) < 1.5 µs (FIFO 64-byte packets) < 1.5 µs (FIFO 64-byte packets)
Throughput up to 95.2 Mpps (64-byte packets) up to 190.5 Mpps (64-byte packets) up to 95.2 Mpps (64-byte packets)
Routing/Switching capacity 160 Gbps 320 Gbps 160 Gbps
Switch fabric speed 169 Gbps 338 Gbps 169 Gbps
Routing table size 10000 entries (IPv4),
5000 entries (IPv6)
10000 entries (IPv4),
5000 entries (IPv6)
10000 entries (IPv4),
5000 entries (IPv6)
MAC address table size 64000 entries 64000 entries 64000 entries