Cloud-managed L2 switching, PoE and non-PoE
HyperSwitch
HyperSwitch is a cloud-managed access switching platform for campus and edge networks. It runs an open, disaggregated switch operating system on white-box hardware, so you get enterprise L2 features, PoE++ for Wi-Fi 6E and 7 access points, and zero-touch rollout without a per-port licence or a single-vendor lock-in.
Enterprises, campuses, managed service providers and LAN-as-a-Service operators deploying wiring-closet switching alongside wireless.
- 90W
- PoE++ per port, 802.3bt
- 4094
- VLANs per switch
- Open
- white-box hardware
The wiring closet is the last place still buying proprietary.
Wireless went cloud-managed and multi-vendor years ago. The switches underneath it did not. They still arrive with a per-port licence, a management console that does not talk to the Wi-Fi controller, and a hardware line you cannot leave without re-cabling your assumptions.
The switch powers the access point. Manage them from one place, or explain to the customer why you cannot.
What it costs you today
- Per-port and per-feature licences that renew forever
- A separate console from the one managing the access points
- A truck roll to configure every new wiring closet
- Wi-Fi 6E and 7 access points that need more power than the switch can give
How HyperSwitch works
The decisions that shape the platform, and why they were made that way.
Open switch OS, white-box hardware
The platform runs a community-developed, Linux-based network operating system on merchant-silicon hardware from several manufacturers. Hardware and management become separable decisions: refresh the switches without re-platforming, or add a second supplier without adding a second console.
One console for wired and wireless
Switches and access points are managed together. The port that powers an AP, the VLAN that carries its SSIDs and the RF settings on the AP itself are all configured and troubleshot in one place, rather than correlated by hand across two products.
Power the access points you actually deployed
Wi-Fi 6E and Wi-Fi 7 radios draw more than older PoE budgets allow. PoE++ models deliver up to 90W per port under 802.3bt, with per-port budgeting, priority ordering when the budget is tight, and scheduled power cycling to reboot a hung device without a site visit.
Rack it and walk away
A new switch authenticates to the provisioning service, is pointed at your controller, pulls its image and its configuration based on where it sits, and comes up in service. Rolling out a floor or a branch does not require a console cable or an engineer on site.
What you get
- Cloud-managed from the same console as your wireless estate
- Zero-touch provisioning: rack it, power it, it configures itself
- PoE and PoE++ models with per-port budgeting, priority and scheduling
- Full L2 feature set: VLANs, trunking, LAG/LACP, RSTP, MSTP and PVST
- 802.1X and MAC authentication with dynamic VLAN assignment
- Storm control, DHCP snooping, dynamic ARP inspection and port security
- QoS with DSCP and 802.1p mapping, queue scheduling and rate limiting
- Streaming telemetry, sFlow, SNMP and syslog to your monitoring stack
- Open network operating system on white-box hardware from multiple ODMs
- Config templates, scheduled firmware and rollback across the estate
Capabilities in full
Everything the platform does, grouped by the team that uses it.
Layer 2 switching
- Up to 4094 VLANs with access and trunk modes
- Link aggregation, static and LACP with min-links and fallback
- RSTP, MSTP and PVST spanning tree
- Large MAC table with dynamic learning, static entries and ageing
- LLDP and LLDP-MED neighbour discovery
- Jumbo frames and per-port MTU control
- Port mirroring, local and remote
- IGMP snooping for multicast control
Power over Ethernet
- 802.3af, 802.3at and 802.3bt on PoE models
- Up to 90W per port, PoE++ class 8
- Per-port and system-wide power budgeting
- Port priority when the budget is oversubscribed
- Scheduled power cycling to reboot remote devices
- Per-port consumption reporting and history
- Legacy device detection for older endpoints
- Non-PoE models for aggregation and uplink roles
Security and access control
- 802.1X port-based authentication
- MAC authentication bypass for devices without a supplicant
- Dynamic VLAN assignment from RADIUS
- Guest and restricted VLAN fallback
- Port security with MAC limiting
- DHCP snooping and dynamic ARP inspection
- Broadcast, multicast and unknown-unicast storm control
- Access control lists on ports and VLANs
Operations and visibility
- Zero-touch provisioning with secure onboarding
- Streaming telemetry to the cloud controller
- sFlow sampling for traffic and top-talker analysis
- SNMP v2c and v3, plus syslog export
- Per-port counters, errors and utilisation history
- Configuration templates applied by site and role
- Scheduled firmware upgrade with rollback
- Full CLI and REST API for automation
Where it gets deployed
Campus wiring closets
Access switching for floors and buildings, powering Wi-Fi 6E and 7 access points and authenticating every port with 802.1X.
Branch and retail
One compact PoE switch per site, provisioned from a template, carrying POS, cameras, phones and guest traffic on separate VLANs.
LAN-as-a-Service
Multi-tenant management with delegated administration, so a service provider runs switching for many customers from one console.
Wired and wireless convergence
Deployed with OMNIFI, the access point and the port that powers it are configured, monitored and fixed from a single interface.
The rest of the platform
Standards-based management across eight platforms. Useful alone, better together.
JustiFi ACS
Carrier-grade TR-069 and TR-369 device management
ExploreJustiFi Home
Subscriber-side Wi-Fi diagnostics, on the device that has the problem
ExploreHyperNMS
Multi-vendor network monitoring and fault management
ExploreHyperRecursor
Carrier-grade DNS resolution for ISPs and large enterprises
ExploreHyperWAN
SD-WAN for always-on connectivity at the edge
ExploreOMNIFI
Cloud-managed Wi-Fi for enterprises and growing businesses
ExploreCommon questions
What hardware does HyperSwitch run on?
White-box switches built on merchant silicon from several manufacturers, in PoE and non-PoE variants and in the port counts a wiring closet actually needs — typically 8, 24 and 48 access ports with 10G or 25G uplinks. Because the operating system is open rather than tied to one vendor, you can change supplier at refresh without changing platform.
Is this a data centre switch?
No. The same open operating system family is widely used in data centres, but HyperSwitch is packaged for campus and edge: access-layer L2 features, PoE for access points and cameras, 802.1X for port security, and a cloud controller rather than a fabric manager.
What happens if the cloud controller is unreachable?
The switch keeps forwarding traffic and enforcing its configuration. The controller manages and observes; it is not in the data path, so a management outage does not become a network outage.
Can it manage our access points too?
Yes, when deployed alongside OMNIFI. That is the main reason to run both: the port, the power budget, the VLAN and the SSID are one workflow instead of two consoles and a spreadsheet.
Do we need a per-port or per-feature licence?
No. The L2 feature set, PoE management, 802.1X and telemetry are part of the platform rather than licence-gated tiers, which is usually where the cost comparison against proprietary campus switching is decided.
Put HyperSwitch in front of your own network
Bring your CPE models, your protocol mix and your integration constraints. A solutions engineer will show you what the platform does with them — no slides.