Zyxel CX4800-56f review: 100G Switch with high redundancy

The Zyxel CX4800-56F is a high-density L3 aggregation optical switch in which the company pioneered the use of 100G ports: 8 QSFP28 100GbE uplinks complement 48 SFP+/SFP28 slots with 10/25gbe support, forming a single 56-port stack for traffic aggregation in campus and datacenter factories. With a pass-through switching matrix of up to 4 Tbit/s and forwarding speeds of up to 2 billion packets per second, this switch confidently closes scenarios of highly loaded highways, where not only bandwidth, but also delays are critical.

Hardware acceleration of IPv4/IPv6 routing and impressive L3/L2 tables (up to 12,000 IPv4 records) allow it to be used as the core of an average campus or an aggregation node for provider pops. Nebula cloud management support combined with traditional Web/CLI/SNMP modes allows the CX4800-56F to integrate as part of a unified managed infrastructure where centralized policies, telemetry, and automatic management are important, both through proprietary tools and through the vendor cloud.

Exterior

The Zyxel CX4800-56F is made in a classic 1U form factor for the aggregation level. The case has a depth of 489 mm, so the device takes up full space even in deep server cabinets. The weight of the switchboard is 8.6 Kg, so skids are used for mounting into the rack.

Zyxel CX4800 56F

The entire switching part is located on the front panel, and the service and power parts are located on the rear. There are 48 SFP+/SFP28 optical slots and 8 QSFP28 slots on the front, grouped into a single port unit without any "extra" copper interfaces ‑ everything is focused on pure fiber-optic aggregation.

Zyxel CX4800 56F - вид сзади

On the back side there is an RJ‑45 Out-of-Band control port, a console RJ‑45 and a pair of USB Type‑A for working with firmware images and logs, which allows you to service the device without getting into production traffic.

The cooling system is based on 4 hot-swappable fan modules installed on the rear side. These are twin fans from Delta (model GFC0412DS-SM06), a company that needs no introduction, and each of them has a power of up to 27.24 watts, a speed of up to 23,000 RPM and an air flow of up to 37.6 watts. The maximum noise level is up to 69 dB, so installing the switch in the same room with people is out of the question.

The power supply is implemented through two hot-swappable power supplies. When ordering, it is possible to choose between AC and DC versions for AC and DC power supply, respectively. The AC version that came to us for testing uses power supplies manufactured by the same company Delta Electronics, model DPS-650AB-18 A with a power of 650 watts each. These power supplies are 80 Plus Gold certified, and achieve maximum efficiency just somewhere around 330 watts, that is, at the maximum documented power of the switch itself.

There is no doubt that Zyxel did the right thing for power supply and cooling by choosing Delta, the best manufacturer of fans and power supplies. However, this does not mean that he will forgive you for being sloppy in the server rack: the ambient temperature ranges for operation are relatively narrow – from 0 to 40 degrees Celsius, and the incoming voltage is 200-240 V / 100-127 V. That is, if we are used to Zyxel switches operating under any conditions from any voltage and on any cable line, then in this case we change our habits and make sure that the CX4800-56F is installed in a server cabinet in an air-conditioned room and connected with two "legs" to the UPS.

Interior

According to the internal layout, the CX4800-56F looks like a typical high-density 1U aggregator: almost the entire area of the printed circuit board is occupied by a powerful switching ASIC under a large radiator. The entire power part is separated along the edges of the board so as not to interfere with direct air flow and simplify maintenance: the connectors of the ventilation modules and the PSU are placed on separate boards, accessible without disassembling the main "sandwich" of radiators.

The photo shows that the switch's RAM is represented by one 8 GB SO-DIMM memory module, while the second connector for the same memory module remains free.

The firmware is embedded on a 32 GB M2 SSD drive manufactured by Innodisk (model 3ME4), a leader in industrial and embedded disks of all stripes. And although all switches of this level can boot from different firmware versions, the system SSD itself is not duplicated here.

Interestingly, SFP slots 1 through 16 do not have radiators on top, so it is better to install any hot transceivers in odd slots 17 through 47.

Software

The CX4800-56F has a huge set of functions in its firmware, but four blocks look particularly interesting: specialized Networked AV Mode, L2 protocol tunneling, an advanced set of L2/L3 security tools, and a fairly powerful QoS/Voice mechanism based on the classifier/policy engine. Below we will briefly analyze each of these possibilities.

Networked AV Mode is essentially a separate "operation profile" where the web interface gathers into one section only those subsystems that are critical for AV‑over‑IP installations: system parameters, IP routing, SNMP, ports, aggregation, DiffServ, mirroring and multicast. This mode has its own menu tree, MONITOR/SYSTEM/PORT/SWITCHING/SECURITY/MAINTENANCE, which allows the integrator to configure IGMP‑snooping, link aggregation, prioritization, and remote control without "digging" into the overall L3 functionality of the switch.

Complex L2/L3‑security

The Network Security section describes in detail a rather aggressive set of protections: port security with a limited number of MACS per port, static MAC filter, Anti‑ARP Scan with thresholds and switching the port to err‑disable, as well as DHCP snooping and IP Source Guard with IP/MAC/VLAN binding in the binding table. This is complemented by 802.1X and MAC authentication via RADIUS, Guest VLAN for "failed" users, ACLs with actions like drop/mirror/rate‑limit and ARP inspection, which together turns the CX4800‑56F into a rather evil filter switch on the border of trusted and guest segments.

Flexible QoS and Voice/AV‑functions

QoS is based not only on classic 802.1p/DSCP markup, but also on a combination of classifier → policy rule: classifier describes the flow of L2/L3 fields, and policy can either change the quality of service or do bandwidth metering with an out‑of‑profile drop, actually implementing per‑flow policing directly on a switch.

For voice and AV, on top of this, there is a Voice VLAN with automatic VLAN assignment and priority according to the OUI of phones and LLDP‑MED, as well as a DiffServ module with a configurable DSCP→802.1p matrix and detailed queue configuration, which allows you to very tightly separate voice, video and "normal" data even in highly converged scenarios.

DHCP

The DHCP in the CX4800-56F is implemented as a full-fledged server with support for pools at the VLAN level, where address ranges, mask, gateway and DNS are set for each subnet, with automatic consideration of relay agents for inter-segment distribution.

Interestingly, the switch allows you to combine static IP interfaces with dynamic pools, automatically excluding the switch address from the distributed range, and also supports MAC redundancy options and setting T1/T2 timeouts for stateless DHCPv6 on top of the IPv4 infrastructure. This approach makes it convenient for scenarios where there is no separate DHCP server, but traffic needs to be routed between VLANs with a dynamic IP destination, for example, in branches or test networks where hosts migrate between subnets.

MVR

MVR (Multicast VLAN Registration) allows you to efficiently distribute multicast IPTV or AV stream traffic over a shared VLAN without clogging up client subnets: the multicast source sits on the provider VLAN, and MVR ports at the access level transparently copy streams to local VLANs upon IGMP requests.

The CX4800-56F supports static and dynamic MVR with a querier on the switch, which simplifies topologies where a single multicast channel is needed in dozens of isolated segments - traffic is replicated only on the right ports, rather than flooding everywhere, saving bandwidth on highways and reducing the load on host processors.

VRRP

VRRP on the CX4800-56F provides gateway fault tolerance without a single point of failure: two switches synchronize virtual IP through a VRRP group, where master actively routes VLAN traffic, and backup instantly picks up the role in case of failure by rewriting the ARP tables of neighbors. Multiple routing interfaces are supported in a single VRRP group with priority based on interface tracking or IP, plus integration with Zyxel HA clustering, where the VRRP state migrates with sessions without causing connection disconnections for user applications.

Stacking

Stacking in the CX4800-56F is implemented via high-speed 100G uplinks, combining up to two devices into a single logical stack with centralized management: one master switch manages the entire configuration, synchronizes the firmware and presents the stack as a single IP for Telnet/SSH/Web/SNMP. Physically, the stack ports form a full-mesh topology with MRR (multi-chassis redundancy ring), where traffic is automatically rebalanced when the module fails, and the master's hitless failover ensures continuity of L3 routing - connected devices will not have any interruptions of ARP or BGP sessions even with a complete reboot of the leader.

MLAG configuration in Zyxel takes place through a single master stack configuration: QSFP28 stacking uplinks are assigned, fault-tolerant interconnects are activated, and access-level ports are grouped into LAG with distribution over src-dst-ip or src-dst-mac - no separate ISC (inter-switch connection) or peer-link configurations, everything is controlled from a single Web GUI or CLI wizard. At the same time, VRRP for the L3 gateway lives on top of MLAG, ensuring smooth migration of virtual IP between the chassis, and state synchronization (including ARP cache and session tables) proceeds via a stacking channel with a heartbeat check every 200ms. If the master does not respond for 1.2seconds, backup seamlessly migrates all services without packet loss.

Conclusions

The Zyxel CX4800-56F impresses as the company's first mass-market 100G switch, where high port density (48×25G SFP28 plus 8×100G QSFP28 in 1U) is combined with thoughtful engineering implementation: from server cooling with hot-swap fans and duplicated PSUs to stacking, providing fault tolerance without a single point of failure. The software stack is pleased with the maturity of the L3 router - VRRP with tracking, a DHCP server over VLANs, MVR for multicast, and an aggressive security suite with Anti-ARP/DHCP snooping. At the same time, the flexibility of standalone/NebulaFlex allows it to be integrated into both local campuses and cloud-managed provider factories.

Michael Degtyarev (aka LIKE OFF)
02/02.2026


Read also:

The model range of Zyxel Wi-Fi 7 access points

The right access point today is chosen not by the maximum "speed on the box", but by a set of quite mundane parameters: how many bands are actually used, is there 6GHz, how many spatial streams does the radio frequency give, whi...

Review of the Zyxel IAP500BE Secure Access Point

The Zyxel IAP500BE is a Wi‑Fi 7 industrial access point that focuses not so much on a typical office scenario as on working in a technically complex environment where stability, fault tolerance, and predictable hardware behavior...

Setting up Tailscale on the Zyxel USG Flex 500H gateway

Tailscale can now be centrally deployed on the security gateway. We'll tell you how to deploy Tailscale and Headscale on the Zyxel USG Flex500, cross internal networks, organize an exit node, and use unique features, from publi...