This is an old revision of the document!


TP-Link T1600G-52PS

The TP-Link T1600G-52PS v4 48 + 4-port Gigabit L2 switch with PoE+.

  • Winbond 25Q256JVFQ (32MB flash)
  • SEC K4B2G1646 BYMA (256MB RAM)
  • PoE daughter board:
    • TI 9BAJJ6T ISO7741 digital isolator
    • 12× TI TPS23861PW PSE controller

4 Uplink ports are SFP cages which support 1000 Base-X mini GBIC modules.

Power is supplied via a 230 volt mains connector, with an internal power supply for 12 Volt and PoE+.

The board does not have a console connector, but there is an unpopulated header at the left side (front-facing). The Pinout is either TX-RX-GND-VCC or RX-TX-GND-VCC, this needs to be checked again. The connection parameters are 38400 8N1.

There is 1 main PCB and a small PCB with 13 shift register logic chips to control the LEDs (74HC164).

Board Pictures
Overview; the main CPU is beneath the biggest heat sink, the ribbon cable connects to the LED panel. There are three fans, the speed of the two near the power supply can be controlled.
CPU area; the chip markings are SEC 010 K4B2G16 46F (RAM), WINBOND 25Q256JVFQ (Flash) and LVC245A XH38702 TXD947F (Octal Bus Transceiver)
Fan area; there is one FET marked P3056LS 1951
External PHY area; there is a RTL8214QF PHY for the SFP slots
PoE daughter board detail t1600-52p-poe-detail.jpg

There are no ICs on the bottom side of the PCB.

It ships with a bootloader based on Realtek's SDK for RTL83xx SoCs and Linux 2.6.32 based on Realtek's second generation SDK. It has a web interface for all management functions.

OpenWrt support is currently WiP. There is serial access to the bootloader and the stock firmware image has been successfully decrypted. However, a new U-Boot is required for development.

It might be possible to have upgrades from the stock web interface, but this depends on whether the RSA signature is actually verified or not - the relevant code is commented in the bootloader source code.

  • t1600g-52ps.1604939523.txt.gz
  • Last modified: 2020/11/09 16:32
  • by svanheule