QuickSpecs
HPE Networking EX5200 Switch Series QuickSpecs
Table of Contents
Powering secure, scalable, and AI-driven campus connectivity.
The HPE Networking EX5200 Switch Series is a premium, high‑performance access switching platform designed for enterprise campus and branch networks that require high-density multigigabit connectivity, advanced security, resilient stacking, and cloud-native operations.
As part of the underlying infrastructure for HPE Mist Wired Assurance, the EX5200 is purpose‑built for, and managed by, the cloud. The switch leverages HPE Mist AI to simplify operations and provide better visibility into the experience of connected devices, delivering a refreshing, user experience-first approach to access layer switching.
Overview
Built for the AI era, the EX5200 combines 100 M/1 G/2.5 G/5 G/10 GbE access ports, IEEE 802.3bt PoE++ power, end‑to-end Media Access Control Security (MACsec) AES-256 encryption, standards-based EVPN-VXLAN campus fabrics, and AI-driven operations through HPE Mist Wired Assurance.
The platform is well suited for Wi-Fi 7 access points, smart buildings, dense Internet of Things (IoT) environments, and large enterprise campuses. Its high routing, ARP/ND, MAC, VRF, and policy scale also make it suitable for demanding cloud access and service provider metro edge use cases.
Key Features
- – Cloud-ready, driven by HPE Mist AI with HPE Mist Wired Assurance and Marvis AI Assistant, provides zero-touch onboarding, template‑driven provisioning, service-level insights, anomaly detection, and guided remediation.
- – End-to-end encryption using MACsec AES256 encryption helps protect switch-to-switch and switch-to-host traffic while preserving network visibility and policy enforcement.
- – High-density 10GbE multi-gig access with 24 and 48-port models provides 100 M/1 G/2.5 G/5 G/10 GbE access for high-performance Wi-Fi, IP communications, smart buildings, and IoT endpoints.
- – Wi-Fi 7-ready switches with PoE models that support IEEE 802.3bt Class 8 up to 90W per port and up to 3400W aggregate PoE budget on the 48-port model.
- – EVPN-VXLAN enables scalable Layer 2 and Layer 3 overlays with standards-based Group-Based Policy for macro-and microsegmentation.
- – Large forwarding and policy tables support demanding enterprise, cloud access, and service provider edge environments.
- – Redundant hot-swappable power supplies and fans, fast PoE, perpetual PoE, nonstop bridging, active routing, and graceful failover help maintain uptime
- – Up to 10 switches can operate as a single logical system with 400 Gbps full-duplex Virtual Chassis bandwidth using dedicated 100GbE stacking ports.
The EX5200 family includes four 1U access switch models for PoE and non‑PoE deployments. All models provide 10GbE-capable multigigabit copper access ports, modular uplink choices, and dedicated high-speed Virtual Chassis/uplink ports.
Cloud management with HPE Mist Wired Assurance, driven by HPE Mist AI EX5200 switches can be quickly and easily onboarded (day 0), provisioned (day 1), and managed (day 2+) from the cloud with HPE Mist Wired Assurance, which brings AI-powered automation and insights that optimize experiences for end users and connected devices. EX5200 is designed for cloud-first operations with HPE Mist Wired Assurance. It provides telemetry and automation for campus access networks and helps operations teams simplify deployment, improve visibility, shorter mean time to repair (MTTR), and streamline troubleshooting. For more information, read the HPE Mist Wired Assurance data sheet.
In addition to HPE Mist Wired Assurance, Marvis AI—a key part of the self-driving network—makes the HPE Mist AI engine interactive. A digital extension of the IT team, Marvis offers automatic fixes or recommended actions, allowing IT teams to streamline how they troubleshoot and manage their network operations.
- – Day 0 operations: Claim and activate switches with zero-touch onboarding and activation workflows.
- – Day 1 operations: Use templates to standardize standalone, Virtual Chassis, and campus fabric deployments while retaining site-level flexibility.
- – Day 2+ operations: Monitor switch health, successful connects, throughput, bandwidth, and client experience using service-level insights.
- – AI-assisted troubleshooting: Marvis Actions can identify issues such as missing VLANs, DHCP failures, authentication issues, bad cables, port negotiation mismatches, and L2 loops.
- – Remote troubleshooting: Secure packet capture and cloud-based workflows simplify escalation and issue isolation.
EVPN-VXLAN campus fabric
An EVPN-VXLAN fabric is a simple, programmable, highly scalable architecture built on open standards. This technology can be applied in both data centers and campuses for architectural consistency. A campus EVPN-VXLAN architecture uses a Layer 3 IP-based underlay network and an EVPN-VXLAN overlay network. A flexible overlay network based on a VXLAN overlay with an EVPN control plane efficiently provides Layer 2 and/or Layer 3 connectivity throughout the network.
EX5200 supports standards-based EVPN-VXLAN campus fabric architectures that decouple logical network services from physical topology. This enables flexible segmentation, resilient scale-out, and simpler network expansion.
- – EVPN multihoming for collapsed core or distribution designs.
- – Campus fabric core distribution for incremental fabric adoption across core and distribution layers.
- – Campus fabric IP Clos for end-to-end fabric designs that extend VXLAN termination and policy enforcement to the access layer.
- – Group-based policy for consistent macro- and microsegmentation across wired and wireless environments.
The main advantages of EVPN-VXLAN in campus networks are:
- – Flexibility of consistent VLANs across the network: Endpoints can be placed anywhere in the network and remain connected to the same logical L2 network, enabling a virtual topology to be decoupled from the physical topology.
- – Microsegmentation using group-based policy: Group-based policies (GBP) with EVPN-VXLAN‑based architecture lets you deploy a common set of policies and services across campuses with support for L2 and L3VPNs.
- – Scalability: With an EVPN control plane, enterprises can scale out easily by adding more core, aggregation, and access layer devices as the business grows without having to redesign the network or perform a forklift upgrade. Using an L3 IP-based underlay coupled with an EVPN-VXLAN overlay, campus network operators can deploy much larger and more resilient networks than would otherwise be possible with traditional L2 Ethernet‑based architectures.
Virtual Chassis Technology
Virtual Chassis technology from HPE allows multiple interconnected switches to operate as a single, logical unit, enabling users to manage all platforms as one virtual device.
Up to 10 EX5200 switches can be interconnected as a Virtual Chassis switch to operate as a single logical device, simplifying management while delivering resilient, scalable access-layer designs.
- – Fast 10-member Virtual Chassis support.
- – 400 Gbps full-duplex stacking bandwidth per switch using two dedicated 100GbE ports.
- – Single management plane with one configuration and one operational view for the stack.
- – Graceful routing engine switchover, nonstop bridging, and nonstop active routing for high availability.
- – Dedicated 100GbE ports can be used for Virtual Chassis or high-speed uplink connectivity, where supported.
Standard Features
Simplified operations with HPE Mist Wired Assurance
The EX5200 is fully cloud onboarded, provisioned, and managed by HPE Mist Wired Assurance. The EX5200 is designed from the ground up to deliver the rich telemetry that enables AI for IT operations (AIOps) with simplified operations from day 0 to day 2 and beyond. HPE Mist Wired Assurance provides detailed switch insights for easier troubleshooting and improved time to resolution by offering the following features:
- – Day 0 operations: Onboard switches seamlessly by claiming a greenfield switch or all purchased switches with a single activation code for true plug and-play simplicity. You may also onboard brownfield switches with the adopt switch process.
- – Day 1 operations: Implement a template-based configuration model for bulk rollouts of traditional and campus fabric deployments while retaining the flexibility and control required to apply custom site or switch-specific attributes. Automate provisioning of ports via Dynamic Port Profiles.
- – Day 2 operations: Leverage the AI in HPE Mist Wired Assurance to meet service-level expectations such as throughput, successful connects, switch health, and switch bandwidth with key pre-and post-connection metrics. Add the self-driving capabilities in Marvis Actions to detect needle in the haystack issues such as missing VLANs, DHCP failure scopes, wired authentication failures, bad cables, port negotiation mismatches, persistently failing clients, detection of L2 loops, misconfigured ports, and traffic loops. Perform software upgrades easily through HPE Mist cloud.
MACsec AES256 encryption
The EX5200 supports IEEE 802.1AE MACsec with AES‑256 encryption to protect Layer 2 traffic on user‑facing and uplink interfaces. MACsec helps protect against passive wiretapping, replay, and man‑in‑the‑middle attacks while enabling the switch to apply policy, quality of service, and telemetry internally.
PoE++ Power, fast PoE, and perpetual PoE
EX5200 PoE models support IEEE 802.3bt PoE++ with up to 90W per port for Wi-Fi 7 access points, smart lighting, IP cameras, building automation systems, and other high-power endpoints.
- – Fast PoE helps deliver power to connected endpoints shortly after switch power is applied.
- – Perpetual PoE helps maintain endpoint power through switch software restarts or upgrades.
Telemetry, security, and operations
Flow-based telemetry
The EX5200 supports hardware-accelerated flow‑based telemetry for visibility into traffic behavior and anomaly detection. Flow telemetry helps identify security threats, policy violations, and abnormal traffic patterns without placing unnecessary load on the CPU.
- – Monitor up to 256K concurrent flows.
- – Export IPFIX flow records and alerts to external collectors.
- – Enable operations teams to automate investigation or quarantine workflows for affected endpoints.
High availability
- – Redundant hot-swappable power supplies and field‑replaceable fan module.
- – Graceful routing engine switchover for Virtual Chassis resiliency.
- – Nonstop bridging and nonstop active routing. Fast PoE and perpetual PoE on PoE models.
- – Link aggregation, VRRP, BFD, ERPS, and other resiliency features for campus access designs.
Security and access control
- – 802.1X, MAC authentication, and captive portal workflows for wired access control.
- – Dynamic policy assignment with standards-based VLANs and group-based policy. Role-based administrator access, secure management, syslog, SNMPv3, and secure application programming interfaces (APIs).
- – IPv4 and IPv6 ACLs for policy enforcement.
- – DHCP snooping, dynamic ARP inspection, IP source guard, and IPv6 neighbour discovery protections.
- – MACsec AES-256 for encrypted Layer 2 connectivity.
EVPN-VXLAN for campus core, distribution, and access
HPE offers complete flexibility in choosing any of the following validated EVPN-VXLAN campus fabrics that cater to networks of different sizes, scales, and segmentation requirements:
- – EVPN multihoming (collapsed core or distribution): A collapsed core architecture combines the core and distribution layers into a single switch, turning the traditional three-tier hierarchical network into a two-tier network. EVPN multihoming on a collapsed core eliminates the need for Spanning Tree Protocol (STP) across campus networks by providing link aggregation capabilities from the access layer to the core layer. This topology is best suited for small to medium-sized distributed enterprise networks and allows for consistent VLANs across the network. This topology uses (Ethernet Segment Identifier) ESI (Link Aggregation) LAG and is a standards-based protocol.
- – Campus fabric core distribution: When EVPN-VXLAN is configured across core and distribution layers, it becomes a campus fabric core distribution architecture that can be configured in two modes: centrally or edge-routed bridging overlay. This architecture provides an opportunity for an administrator to move toward campus-fabric IP Clos without a forklift upgrade of all access switches in the existing network while bringing in the advantages of moving to a campus fabric and providing an easy way to scale out the network.
- – Campus fabric IP Clos: When EVPN VXLAN is configured on all layers, including access, it is called the campus fabric IP Clos architecture. This model is also referred to as end-to-end, given that VXLAN tunnels are terminated at the access layer. The availability of VXLAN at access layer provides the opportunity to bring policy enforcement and microsegmentation to the access layer (closest to the source) using standards-based GBP to segment traffic even within a VLAN. GBP tags are assigned dynamically to clients as part of a RADIUS transaction by HPE Mist Access Assurance (NAC). This topology works for small, medium, and large campus architectures that need macro and microsegmentation.
In all these EVPN-VXLAN deployment modes, EX5200 switches can be used in standalone or Virtual Chassis configurations. All three topologies are standards‑based and interoperable with third-party vendors.
Managing AI-driven Campus Fabric with the HPE Mist platform cloud
HPE Mist Wired Assurance brings cloud management and HPE Mist AI to campus fabrics. It sets a new standard that moves away from traditional network management toward AI-Native operations, while delivering better experiences to connected devices. The HPE Mist cloud streamlines deployment and management of campus fabric architectures by allowing:
- – Automated deployment and zero-touch deployment (ZTD)
- – Anomaly detection
- – Root cause analysis
Deployment scenarios
- – Premium campus access for large sites, headquarters, and higher-education environments.
- – Wi-Fi 7 access switching with 10GbE multigigabit ports and high-power PoE++.
- – Smart buildings with PoE-powered lighting, sensors, cameras, and building automation devices.
- – Branch consolidation where compact, resilient, AI managed access switching is required.
- – Cloud access and service provider edge deployments that need high forwarding scale in a 1U platform.
JunOS Operating System
The EX5200 switches run Junos OS, HPE’s powerful and robust network operating system that powers all HPE Juniper Networking switches, routers, and firewalls. By utilizing a common operating system, HPE delivers a consistent implementation and operation of control plane features across all products.
To maintain that consistency, Junos OS adheres to a highly disciplined development process that uses a single source code and employs a highly available modular architecture that prevents isolated failures from bringing down an entire system. Junos OS supports automation, telemetry, consistent command line interface (CLI) and API workflows, and a broad set of Layer 2 and Layer 3 services.
These attributes are fundamental to the core value of the software, enabling all Junos OS powered products to be updated simultaneously with the same software release. All features are fully regression tested, making each new release a true superset of the previous version. Customers can deploy the software with complete confidence that all existing capabilities are maintained and operate in the same way.
Flex licensing
HPE Juniper Flex licensing offers a common, simple, and flexible licensing model for EX series access switches, enabling customers to purchase features based on their network and business needs.
Flex licensing is offered in standard, advanced, and premium tiers. Standard tier features are available with the Junos OS image that ships with HPE Networking EX Series Switches. Additional features can be accessed with the purchase of a Flex Advanced or Flex Premium license.
The Flex and Premium licenses for the EX series platforms are class-based, determined by the number of access ports on the switch. Class 1 (C1) switches have 12 ports, class 2 (C2) switches have 24 ports, and class 3 (C3) switches have 32 or 48 ports.
The EX5200 switches support both subscription and perpetual Flex licenses. Subscription licenses are offered for three-and five-year terms. In addition to Junos OS features, the Flex Advanced and Premium subscription licenses include HPE Mist Wired Assurance. Flex Advanced and Premium subscription licenses also allow portability across the same tier and class of switches, providing investment protection for the customer.
For a complete list of features supported by the Flex Standard, Advanced, and Premium tiers, or to learn about HPE Networking EX Switch Series licenses, visit Software Licenses for EX Series Switches.
Warranty, services, and support
The EX5200 switches are designed for enterprise-grade supportability with field-replaceable components, redundant power and cooling, and operational workflows integrated with HPE Mist and Junos OS. Customers can select support options aligned to deployment criticality, sparing strategy, and required replacement service levels.
EX5200 switches include an enhanced limited lifetime hardware warranty that provides return-to‑factory switch replacement for as long as the original purchaser owns the product. The warranty includes lifetime software updates, advanced shipping of spares within one business day, and 24x7 Juniper Technical Assistance Center support for 90 days after the purchase date. Power supplies and fan trays are covered for a period of five years.
For complete details, visit Product Warranty Policy.
Quality of Service (QoS)
- – Eight hardware queues for traffic prioritization
- – Classification and marking based on Layer 2, Layer 3, and Layer 4 fields
- – Strict priority and weighted scheduling options
- – Ingress and egress rate limiting and shaping
- – Jumbo frames up to 9216 bytes
Configuration Information
| EX5200 Campus Access Switches | |
| Description | SKU |
| HPE Networking EX5200 48x100M/1G/2.5G/5G/10G MACsec AES-256 CL8 2x100G AFO 3x Fan AC Campus Switch | EX5200-48MP |
| HPE Networking EX5200 24x100M/1G/2.5G/5G/10G MACsec AES-256 CL8 2x100G AFO 2x Fan AC Campus Switch | EX5200-24MP |
| HPE Networking EX5200 48x100M/1G/2.5G/5G/10G MACsec AES-256 2x100G AFO 2xFan AC Campus Access Switch | EX5200-48T |
| HPE Networking EX5200 24x100M/1G/2.5G/5G/10G MACsec AES-256 2x100G AFO 2xFan AC Campus Access Switch | EX5200-24T |
| EX5200 Modules | |
| HPE Networking EX5200 2x100GbE MACsec AES-256 Campus Extension Module | EX5200-EM-2C |
| HPE Networking EX5200 8x25GbE MACsec AES-256 Campus Extension Module | EX5200-EM-8Y |
| HPE Networking EX5200 Air Flow Out Fan Module | EX5200-FAN |
| EX5200 Power Supplies | |
| HPE Networking EX5200 2000W Air Flow Out 110-240V AC Power Supply | JPSU-2000-AC-AFO |
| HPE Networking EX5200 1600W Air Flow Out 110-240V AC Power Supply | JPSU-1600-AC-AFO |
| HPE Networking EX5200 550W Air Flow Out 110-240V AC Power Supply | JPSU-550-AC-AFO |
Technical Specifications
| EX5200 Line of Ethernet Switches | |||||
|---|---|---|---|---|---|
| Model/ Product SKU | EX5200-48T | EX5200-24T | EX5200-48MP | EX5200-24MP | |
| Access/Revenue Port Configuration | 48-port 100M/1/2.5/5/10GbE | 24-port 100M/1/2.5/5/10GbE | 48-port 100M/1/2.5/5/10GbE | 24-port 100M/1/2.5/5/10GbE | |
| PoE++ Ports | 0 | 0 | 48 | 24 | |
| PoE++ Budget 1 PSU/2 PSU | 220V | N/A | N/A | | |
| 110V | N/A | N/A | | | |
| 10GbE Ports (max. with module) | 48 (56) | 24 (32) | 48 (56) | 24 (32) | |
| 25GbE Ports (max. with module) | 0(8) | 0(8) | 0(8) | 0(8) | |
| 100GbE/40GbE Ports (max with module) | 2(4) | 2(4) | 2(4) | 2(4) | |
| Power Supply Rating | 550 W AC | 550 W AC | 2000 W AC | 1600 W AC | |
| Cooling | AFO (front-to-back airflow) | AFO (front-to-back airflow) | AFO (front-to-back airflow) | AFO (front-to-back airflow) | |
The EX5200 also offers spare chassis options without power supplies or fans, providing customers with the flexibility to stock SKUs (see Table 2). See the Ordering Information section for additional details.
| EX5200 Spare Chassis SKUs | ||||
|---|---|---|---|---|
| Spare Chassis SKU | EX5200-48T | EX5200-24T | EX5200-48MP | EX5200-24MP |
| Description | Spare chassis, 48x100M/ 1/2.5/5/10GbE ports | Spare chassis, 24x100M/ 1/2.5/5/10GbE ports | Spare chassis, 48x100M/ 1/2.5/5/10GbE ports | Spare chassis, 24x100M/ 1/2.5/5/10GbE ports |
| JPSU-550-AC- AFO + EX5200- FAN | Y | Y | X | X |
| JPSU-1600- AC-AFO + EX5200-FAN | X | X | X | Y |
| JPSU- 2000- AC- AFO + EX5200- FAN | X | X | X | Y |
| Notes: Y = supported; X = not supported | ||||
EX5200 Line Specifications
Physical specifications Backplane
- – 400 Gbps Virtual Chassis interconnect to combine up to 10 units as a single logical device
Extension module options
- – EX5200-EM-8Y, 8 port SFP28
- – EX5200-EM-2C, 2 port QSFP28
Power options
- – Power supplies: Autosensing; 100-120V/200-240V; 550 W, 1600 W and 2000 W AC AFO dual load sharing hot-swappable power supplies
- – Maximum current inrush: 30 amps
- – Minimum number of PSUs required for fully loaded chassis: 1 per switch
Dimensions (W x H x D)
- – Height: 1 U
System weight
- – 1550 W AC power supply: 1.76 lb (0.8 kg)
- – 1600 W AC power supply: 2.0 lb (0.91 kg)
- – 2000 W AC power supply: 2.05 lb (0.93 kg)
Environmental ranges
- – Operating temperature: 32° to 113° F (0° to 45°C)
- – Storage temperature: –40° to 158° F (-40° to 70°C)
- – Operating altitude: up to 6000 ft at 40°C (1828.8 m)
- – Nonoperating altitude: up to 16,000 ft (4,877 m)
- – Relative humidity operating: 5% to 90% (noncondensing)
- – Relative humidity non-operating: 0% to 90% (noncondensing)
Cooling
- – Field-replaceable fans: 2
Hardware specifications Switching engine mode
- – Store and forward
Memory
- – DRAM: 8 GB with Error Correcting Code (ECC) on all models
- – Storage: 80 GB on all models
CPU
- – All models: 2.3 GHz Quad-Core Intel® x86 CPU
Physical layer
- – Time domain reflectometry (TDR) for detecting cable breaks and shorts: EX5200-24T/MP and EX5200-48T/MP
- – Auto medium-dependent interface/medium-dependent interface crossover (MDI/MDIX) support: EX5200-24T/MP and EX5200-48T/MP
- – Port speed downshift/setting maximum advertised speed on 10/100/1000BASE-T ports: EX5200-24MP/T and EX5200-48MP/T only
- – Digital optical monitoring for optical ports
Packet switching capacities (maximum with 64 Byte Packets)
- – EX5200-24MP/24T: 640 Gbps (unidirectional)/ 1280 Gbps (bidirectional)
- – EX5200-48MP/48T: 880 Gbps (unidirectional)/ 1760 Gbps (bidirectional)
Software specifications
Layer 2/Layer 3 throughput (Mpps) (maximum with 64 Byte Packets)
- – EX5200-24MP/T 952.38Mpps
- – EX5200-48MP/T 1309.52 Mpps
Security
- – MAC limiting (per port and per VLAN)
- – Allowed MAC addresses: 112,000
- – Dynamic Address Resolution Protocol (ARP) inspection (DAI)
- – IP source guard
- – Local proxy ARP
- – Static ARP support
- – Dynamic Host Configuration Protocol (DHCP) snooping
- – Captive portal
- – Persistent MAC address configurations
- – Distributed denial of service (DDoS) protection (CPU control path flooding protection)
- – Simple Certificate Enrollment Protocol (SCEP)
Layer 2 switching
- – Maximum MAC addresses per system:
- – Jumbo frames: 9216 Bytes
- – Number of VLANs supported: 4093
- – Range of possible VLAN IDs: 1 to 4094
- – Virtual Spanning Tree (VST) instances: 510
- – Port-based VLAN
- – Voice VLAN
- – Physical port redundancy: Redundant trunk group (RTG)
- – Compatible with Per-VLAN Spanning Tree Plus (PVST+)
- – Routed VLAN interface (RVI)
- – Uplink failure detection (UFD)
- – ITU-T G.8032: Ethernet Ring Protection Switching
- – IEEE 802.1AB: Link Layer Discovery Protocol (LLDP)
- – LLDP-MED with VoIP integration
- – Default VLAN and multiple VLAN range support
- – MAC learning deactivate
- – Persistent MAC learning (sticky MAC)
- – MAC notification
- – Private VLANs (PVLANs)
- – Explicit congestion notification (ECN)
- – Layer 2 protocol tunneling (L2PT)
- – IEEE 802.1ak: Multiple VLAN Registration Protocol (MVRP)
- – IEEE 802.1p: CoS prioritization
- – IEEE 802.1Q: VLAN tagging
- – IEEE 802.1X: Port Access Control
- – IEEE 802.1ak: Multiple Registration Protocol
- – IEEE 802.3: 10BASE-T
- – IEEE 802.3u: 100BASE-T
- – IEEE 802.3ab: 1000BASE-T
- – IEEE 802.3z: 1000BASE-X
- – IEEE 802.3bz: 2.5GBASE-T and 5GBASE-T
- – IEEE 802.3ae: 10-Gigabit Ethernet
- – IEEE 802.3by: 25-Gigabit Ethernet
- – IEEE 802.3af: Power over Ethernet
- – IEEE 802.3at: Power over Ethernet Plus
- – IEEE 802.3bt: 90 W Power over Ethernet
- – IEEE 802.3x: Pause Frames/Flow Control
- – IEEE 802.3ah: Ethernet in the First Mile
Spanning Tree
- – IEEE 802.1D: Spanning Tree Protocol
- – IEEE 802.1s: Multiple instances of Spanning Tree Protocol (MSTP)
- – IEEE 802.1w: Rapid reconfiguration of Spanning Tree Protocol
Link Aggregation
- – IEEE 802.3ad: Link Aggregation Control Protocol
- – 802.3ad (LACP) support:
- – LAG load-sharing algorithm bridged or routed (unicast or multicast) traffic:
- IP: S/D IP
- TCP/UDP: S/D IP, S/D Port
- Non-IP: S/D MAC
- – Tagged ports support in LAG
Layer 3 features: IPv4
- – Routing protocols: RIPv1/v2, OSPF, BGP, IS-IS
- – Static routing
- – Routing policy
- – Bidirectional Forwarding Detection (BFD)
- – L3 redundancy: Virtual Router Redundancy Protocol (VRRP)
Layer 3 features: IPv6
- – Routing protocols: RIPng, OSPFv3, IPv6, IS-IS
- – Static routing
Access Control Lists (ACLs) (Junos OS Firewall Filters)
- – ACL counter for denied packets
- – ACL counter for permitted packets
- – Ability to add/remove/change ACL entries in middle of list (ACL editing)
- – L2-L4 ACL
Access security
- – 802.1X port-based
- – 802.1X multiple supplicants
- – 802.1X with VLAN assignment
- – 802.1X with authentication bypass access (based on host MAC address)
- – 802.1X with VoIP VLAN support
- – 802.1X dynamic ACL based on RADIUS attributes
- – 802.1X Supported Extensible Authentication Protocol (EAP) types: Message Digest 5 (MD5), Transport Layer Security (TLS), Tunneled TLS (TTLS), Protected Extensible Authenticated Protocol (PEAP)
- – MAC authentication (RADIUS)
- – Control plane DoS protection
- – RADIUS functionality over IPv6 for authentication, authorization, and accounting (AAA)
- – DHCPv6 snooping
- – IPv6 neighbor discovery
- – IPv6 source guard
- – IPv6 RA guard
- – IPv6 Neighbor Discovery Inspection
- – MACsec
High availability
- – Redundant, hot-swappable power supplies
- – Redundant, field-replaceable, hot-swappable fans
- – GRES for Layer 2 hitless forwarding and Layer 3 protocols on RE failover
- – Graceful protocol restart (OSPF, BGP)
- – Layer 2 hitless forwarding on RE failover
- – Nonstop bridging: LACP, xSTP
- – Nonstop routing: PIM, OSPF v2 and v3, RIP v2, RIPng, BGP, BGPv6, ISIS, IGMP v1, v2, v3
- – Online insertion and removal (OIR) uplink module
Quality of service
- – L2 QoS
- – L3 QoS
- – Ingress policing: 1 rate 2 color
- – Hardware queues per port: 12 (8 unicast + 4 multicast)
- – Scheduling methods (egress): Strict priority (SP), weighted deficit round-robin (WDRR)
- – 802.1p, DiffServ code point (DSCP)/IP precedence trust and marking
- – L2-L4 classification criteria: Interface, MAC address, Ethertype, 802.1p, VLAN, IP address, DSCP/IP precedence, TCP/UDP port numbers, and more
- – Congestion avoidance capabilities: Tail drop, weighted random early detection (WRED)
Multicast
- – IGMP: v1, v2, v3
- – IGMP snooping
- – Multicast Listener Discovery (MLD) snooping
- – Protocol Independent Multicast-Sparse Mode (PIM-SM), PIM Source-Specific Mode (PIM-SSM), PIM Dense Mode (PIM-DM)
Management and analytics platforms
- – Juniper Mist Wired Assurance for Campus
Device management and operations
- – Junos OS CLI
- – Out-of-band management: Serial; 10/100/1000BASE-T Ethernet
- – Rescue configuration
- – Configuration rollback
- – Image rollback
- – RMON (RFC2819) groups 1, 2, 3, 9
- – Remote performance monitoring
- – SNMP: v1, v2c, v3
- – Network Time Protocol (NTP)
- – DHCP server
- – DHCP client and DHCP proxy
- – DHCP relay and helper
- – DHCP local server support
- – RADIUS
- – TACACS+
- – SSHv2
- – Secure copy
- – HTTP/HTTPS
- – Domain Name System (DNS) resolver
- – System logging
- – Temperature sensor
- – Configuration backup via FTP/secure copy
Supported RFCs
- – RFC 768 UDP
- – RFC 783 TFTP
- – RFC 791 IP
- – RFC 792 ICMP
- – RFC 793 TCP
- – RFC 826 ARP
- – RFC 854 Telnet client and server
- – RFC 894 IP over Ethernet
- – RFC 903 RARP
- – RFC 906 TFTP Bootstrap
- – RFC 951, 1542 BOOTP
- – RFC 1027 Proxy ARP
- – RFC 1058 RIP v1
- – RFC 1112 IGMP v1
- – RFC 1122 Host Requirements
- – RFC 1195 Use of OSI IS-IS for Routing in TCP/IP and Dual Environments (TCP/IP transport only)
- – RFC 1256 IPv4 ICMP Router Discovery (IRDP)
- – RFC 1492 TACACS+ RFC 1519 CIDR
- – RFC 1587 OSPF NSSA Option
- – RFC 1591 DNS
- – RFC 1812 Requirements for IP Version 4 Routers
- – RFC 1981 Path MTU Discovery for IPv6
- – RFC 2030 SNTP, Simple Network Time Protocol
- – RFC 2068 HTTP server
- – RFC 2080 RIPng for IPv6
- – RFC 2131 BOOTP/DHCP relay agent and DHCP server
- – RFC 2154 OSPF w/Digital Signatures (password, MD-5)
- – RFC 2236 IGMP v2
- – RFC 2267 Network Ingress Filtering
- – RFC 2328 OSPF v2 (edge-mode)
- – RFC 2338 VRRP
- – RFC 2362 PIM-SM (edge-mode)
- – RFC 2370 OSPF Opaque LSA Option
- – RFC 2453 RIP v2
- – RFC 2460 Internet Protocol, Version 6 (IPv6) Specification
- – RFC 2461 Neighbor Discovery for IP Version 6 (IPv6)
- – RFC 2463 Internet Control Message Protocol (ICMPv6) for the Internet Protocol Version 6 (IPv6) Specification
- – RFC 2464 Transmission of IPv6 Packets over Ethernet Networks
- – RFC 2474 DiffServ Precedence, including 12 queues/port
- – RFC 2475 DiffServ Core and Edge Router Functions
- – RFC 2526 Reserved IPv6 Subnet Anycast Addresses
- – RFC 2597 DiffServ Assured Forwarding (AF)
- – RFC 2598 DiffServ Expedited Forwarding (EF)
- – RFC 2740 OSPF for IPv6
- – RFC 2868: RADIUS Attributes for Tunnel Protocol Support
- – RFC 2925 MIB for Remote Ping, Trace
- – RFC 3176 sFlow®
- – RFC 3376 IGMP v3
- – RFC 3484 Default Address Selection for Internet Protocol Version 6 (IPv6)
- – RFC 3513 Internet Protocol Version 6 (IPv6) Addressing Architecture
- – RFC 3569 draft-ietf-ssm-arch-06.txt PIM-SSM PIM Source Specific Multicast
- – RFC 3579 RADIUS EAP support for 802.1x
- – RFC 3618 Multicast Source Discovery Protocol (MSDP)
- – RFC 3623 OSPF Graceful Restart
- – RFC 4213 Basic Transition Mechanisms for IPv6 Hosts and Routers
- – RFC 2011 SNMPv2 for Internet Protocol using SMIv2
- – RFC 4291 IPv6 Addressing Architecture
- – RFC 4443 ICMPv6 for the IPv6 Specification
- – RFC 4541 IBMP and MLD snooping services
- – RFC 4552 OSPFv3 Authentication
- – RFC 4861 Neighbor Discovery for IPv6
- – RFC 4862 IPv6 Stateless Address Autoconfiguration
- – RFC 4915 MT-OSPF
- – RFC 5095 Deprecation of Type 0 Routing Headers
- – RFC 5176 Dynamic Authorization Extensions to RADIUS
- – RFC 5798 VRRPv3 for IPv6
- – Draft-ietf-bfd-base-05.txt Bidirectional Forwarding Detection
- – Draft-ietf-idr-restart-10.txt Graceful Restart Mechanism
- – Draft-ietf-isis-restart-02 Restart Signaling for IS-IS
- – Draft-ietf-isis-wg-multi-topology-11 Multi Topology (MT) Routing in IS-IS for BGP
- – Internet draft-ietf-isis-ipv6-06.txt, Routing IPv6 with IS-IS
- – LLDP Media Endpoint Discovery (LLDP-MED), ANSI/ TIA-1057, draft 08
- – PIM-DM Draft IETF PIM Dense Mode draft-ietf-idmr- pimdm-05.txt, draft-ietf-pim-dm-new-v2-04.txt
Supported MIBs
- – RFC 1155 SMI
- – RFC 1157 SNMPv1
- – RFC 1212, RFC 1213, RFC 1215 MIB-II, Ethernet-Like MIB and TRAPs
- – RFC 1493 Bridge MIB
- – RFC 1643 Ethernet MIB
- – RFC 1657 BGP-4 MIB
- – RFC 1724 RIPv2 MIB
- – RFC 1850 OSPFv2 MIB
- – RFC 1905 RFC 1907 SNMP v2c, SMIv2 and Revised MIB-II
- – RFC 2012 SNMPv2 for transmission control protocol using SMIv2
- – RFC 2013 SNMPv2 for User Datagram Protocol using SMIv2
- – RFC 2096 IPv4 Forwarding Table MIB
- – RFC 2287 System Application Packages MIB
- – RFC 2570–2575 SNMPv3, user based security, encryption, and authentication
- – RFC 2576 Coexistence between SNMP Version 1, Version 2, and Version 3
- – RFC 2578 SNMP Structure of Management Information MIB
- – RFC 2579 SNMP Textual Conventions for SMIv2
- – RFC 2665 Ethernet-like interface MIB
- – RFC 2787 VRRP MIB
- – RFC 2819 RMON MIB
- – RFC 2863 Interface Group MIB
- – RFC 2863 Interface MIB
- – RFC 2922 LLDP MIB
- – RFC 2925 Ping/Traceroute MIB
- – RFC 2932 IPv4 Multicast MIB
- – RFC 3413 SNMP Application MIB
- – RFC 3414 User-based Security model for SNMPv3
- – RFC 3415 View-based Access Control Model for SNMP
- – RFC 3621 PoE-MIB (PoE switches only)
- – RFC 4188 STP and Extensions MIB
- – RFC 4363 Definitions of Managed Objects for Bridges with Traffic Classes, Multicast Filtering, and VLAN extensions
- – RFC 5643 OSPF v3 MIB support
- – RFC 6614 RadSec
- – Draft – blumenthal – aes – usm - 08
- – Draft – reeder - snmpv3 – usm - 3desede -00
- – Draft-ietf-bfd-mib-02.txt
- – Draft-ietf-idmr-igmp-mib-13
- – Draft-ietf-idmr-pim-mib-09
- – Draft-ietf-idr-bgp4-mibv2-02.txt – Enhanced BGP-4 MIB
- – Draft-ietf-isis-wg-mib-07
Troubleshooting
- – Debugging: CLI via console, Telnet, or SSH
- – Diagnostics: Show and debug command, statistics
- – Traffic mirroring (port)
- – Traffic mirroring (VLAN)
- – IP tools: Extended ping and trace
- – Juniper Networks commit and rollback
Traffic monitoring
- – ACL-based mirroring
- – Mirroring destination ports per system: 4
- LAG port monitoring
- Multiple destination ports monitored to 1 mirror (N:1)
- – Maximum number of mirroring sessions: 4
- – Mirroring to remote destination (over L2): 1 destination VLAN
Safety and Compliance
Electromagnetic Compatibility (EMC) requirements
- – FCC 47 CFR
- – ICES-003 / ICES-GEN
- – BS EN 55032
- – BS EN 55035
- – EN 300 386 V1.6.1
- – EN 300 386 V2.2.1
- – BS EN 300 386
- – EN 55032
- – CISPR 32
- – EN 55035
- – CISPR 35
- – IEC/EN 61000-3-2
- – IEC/EN 61000-3-3
- – AS/NZS CISPR 32
- – VCCI-CISPR 32
- – BSMI CNS 15936
- – KS C 9835
- – KS C 9832
- – KS C 9610
Safety requirements Chassis and optics:
- – IEC 62368-1:2014 (All country deviations): 2nd Edition: CB Scheme
- – IEC 62368-1:2018 (All country deviations): 3rd Edition: CB Scheme
- – IEC 62368-1:2023 (All country deviations): 4th Edition CB Scheme
- – EN 62368-1:2014+A11:2017, EN IEC 62368-1:2020+A11:2020
- – EN 62368-1:2024/A11:2024
- – BS EN 62368-1:2014+A11:2017, BS EN IEC 62368-1:2020+A11:2020
- – BS EN 62368-1:2024/A11:2024.
- – UL 62368-1:2025 (4th Edition)
- – CSA C22.2 No. 62368-1:2025 (4th Edition)
- – UL 60950-1:2007
- – CAN/CSA C22.2 No. 60950-1-07+ A1:2011+A2:2014
- – CFR, Title 21, Chapter 1, Subchapter J, Part 1040
- – REDR c 1370 OR CAN/CSA-E 60825-1- Part 1
- – IEC 60825-1
- – IEC 60825-2
- – IEC/UL/CSA 62368-1
Energy efficiency
- – AT&T TEER (ATIS-06000015.03.2013)
- – ECR 3.0.1
- – ETSI ES 203 136 V.1.1.1
- – Verizon TEEER (VZ.TPR.9205
Environmental
- – RoHS II Directive 2011/65/EU + Amd1 2015/863
- – REACH, SCIP and WEEE
- – EU PPWR Directive 2025/40
- – China RoHS
- – Taiwan RoHS
- – TSCA
- – PFAs
- – POPs
- – California Proposition 65
Telco
- – CLEI code
Noise specifications
Noise measurements based on operational tests taken from bystander position (front) and performed at 23°C in compliance with ISO 7779.
| EX5200 power supply ratings and acoustic in dBA | ||||||||
|---|---|---|---|---|---|---|---|---|
| Spare Chassis SKU | EX5200-48T | EX5200-24T | EX5200-48MP | EX5200-24MP | ||||
| PSU 1 | ON | ON | ON | ON | ON | ON | ON | ON |
| PSU 2 | ON | OFF | ON | OFF | ON | OFF | ON | OFF |
| Acoustic Sound Pressure Level | 38.48 dbA | 38 dbA | 39.9 dbA | 40.2 dbA | 43.5 dbA | 42.7 dbA | 42.5 dbA | 41.9 dbA |
Summary of Changes
| Date | Version History | Action | Description of Change |
|---|---|---|---|
| 08-Sep-2026 | New | New QuickSpecs |
© Copyright 2026 Hewlett Packard Enterprise Development LP. The information contained herein is subject to change without notice. The only warranties for Hewlett Packard Enterprise products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. Hewlett Packard Enterprise shall not be liable for technical or editorial errors or omissions contained herein.
To learn more, visit: http://www.hpe.com/networking
a50014660enw, 17423 - Worldwide - V1 - 08-September-2026