Release Date:
August 13, 2026
This firmware supports the M4350 series models.
Enhancements:
- Support for up to four PTP domains with an updated PTP command format. Multiple PTP domains are available through CLI and the device UI only. The AV UI continues to support a single PTP domain.
- The PTP command structure and architecture are changed to a domain-based format. Existing PTP configurations are migrated automatically when you upgrade the firmware. However, we recommend backing up the switch configuration before you upgrade the firmware.
- Support for 2 new models: M4350-16M4V (MSM4320) and M4350-16C (CSM4316).
- Support for MLAG (Multi-chassis Link Aggregation Group). The following models support peer links, and both peer switches must be the same model.
- MSM4328F
- XSM4328FV
- XSM4340V
- XSM4340FV
- VSM4320C
- XSM4344FC
- CSM4316
- Upgrade on the underlying SDK and kernel versions, resulting in changes to the following features:
- End of support for 50G speed and related commands.
- Removal of DSA keys from SSH for security reasons.
- The command format “aaa ias-user username <username>” is changed to “aaa ias-user username <username> dot1x”.
- The unused slot power command is removed.
- Support for configurable RSTP Hello timer [CE-7584]
- Support for the AJA AV Network profile.
- Support for the Audio Video AVB MILAN profile.
- Support for the Audio Video AVB MILAN with Dante PTPv1 PTPv2 or AES67 profile.
- Support for the AUDAC Audio and Control Network profile.
- Support for the BluOS AV profile.
- Support for the Shure Converged Profile on M4350 switches.
- Support for the color palettes to the profile color picker.
- Updated the Nice Home Management profile with auto provision features.
- Updated the Audio Video SMPTE profile description to supported new M4350 switch models.
Bug Fixes:
- Fixes the issue where only five Auto-LAGs were created even when more than five devices were connected using multiple links per device. [MS-5200]
- Fixes the issue where continuous DHCPv6 packets cause the switch to reboot unexpectedly. [CE-7265]
- Fixes the issue where the switch operates as dot1AS Grand Master sent Announce messages with a UTC Offset value of 0. [MS-5416]
- Fixes the issue where OUI-based VLAN assignments stopped functioning after extended operation. [CE-7316]
- Fixes an issue where the VLAN 1 routing interface could not be removed through the Main UI. [CE-7321]
- Fixes the issue where PTP time jumped forward intermittently on the M4350-16V4C when operating as PTP Grand Master. [CE-7349]
- Fixes the issue where creating a Tagged VLAN Port in an AVB VLAN Profile incorrectly changes the MTU to 9198. [CE-7632]
- Fixes the issue where PTP TC is not enabled on a manual LAG interface when using Manual Trunk. [CE-7608]
- Fixes the issue where the Audio Dante profile auto-trunk port retains “no spanning tree port mode” configuration after connecting. [PV-6886]
- Fixes the issue where AVUI rejects subnet mask 255.255.255.254 with an incorrect subnet error. [CE-7650]
- Fixes the issue where the PoE++ (802.3bt) option is missing in Engage/ProAV UI for MSM4332, causing ports to be downgraded to PoE+. [CE-7686]
- Fixes the issue where NVX profile cannot be applied to ports 25-48 of the secondary switch in a stacked GSM4352PS configuration. [CE-7512]
- Fixes the issue where PVST is disabled on a VLAN after deleting and re-creating a DICENTIS Conference System profile on that VLAN. [CE-7469]
AV UI Known Issues:
- gPTP Clock Master Causes Time Drift with AVB MILAN Devices:
If the switch becomes the gPTP clock master, time drift issues may occur when AVB MILAN devices are in use.
Workaround: When creating an "Audio Video AVB MILAN" profile in AVUI, set the Local Clock Priority 1 and Priority 2 values to 255 to prevent the switch from acting as the clock master.
- Stale Spanning Tree Configuration After Firmware Upgrade from AVUI 2.2.13.29:
When upgrading firmware from AVUI 2.2.13.29 to the current release, access port configurations with no spanning-tree port mode may persist. If Dante devices are connected using redundancy ports, this can cause a network loop.
Workaround: Manually clear the stale configuration by setting the affected interfaces back to spanning-tree port mode.
- Kramer AV Single-VLAN Profile Cannot Be Modified When Using VLAN 1:
If a Kramer AV profile is created with a single VLAN and that VLAN is VLAN 1, the profile cannot be modified to another single-VLAN profile.
Workaround: Use a VLAN ID other than VLAN 1 when creating a single-VLAN Kramer AV profile.
Known Firmware Issues:
- The boot code might not update automatically when upgrading to this firmware because the firmware size has increased.
Workaround: Update the boot code manually, or upgrade to the same firmware version again.
- It is not possible to import a backup configuration into this firmware if it contains:
- Legacy PTP commands used in firmware version 14.0.6.x
- Configuration settings related to the removed 50G speed support
Workaround: Back up the configuration before upgrading to firmware version 14.0.9.x. To restore the backup configuration, downgrade to firmware version 14.0.6.x first.
- Multiple PTP Domains limitations:
- Support for only one global PTP source IP address. The PTP source IP address is selected according to the following priority:
- Configured global PTP source IP address
- Management VLAN IP address
- Multiple PTP domains do not support a mix of one-step and two-step modes. All PTP domains must use either one-step mode or two-step mode. All PTP domains must use the same mode. Configuring different modes across the domains might result in unexpected behavior.
- All ports within the same PTP domain must use the same VLAN. Configuring different VLANs for ports within the same PTP domain is not supported.
- The PTP command format is updated to support multiple PTP domains. Existing PTP commands are migrated to the new command format during the upgrade. We do not recommend downgrading from firmware version 14.0.9.x to 14.0.6.x or earlier due to incompatible PTP command formats.
Workaround: Back up configuration before upgrading to 14.0.9.x. Import the backup configuration with firmware 14.0.6.x
- MLAG limitations:
- Auto-MLAG is not supported.
Workaround: Configure an MLAG manually through the CLI or device UI.
- Communication between orphan ports is not supported. Clients cannot connect to only one MLAG switch.
Workaround: Connect partner switches and clients redundantly to both MLAG switches.
- The peer link creation might fail if MLAG is enabled and disabled repeatedly within a short period.
Workaround: Ensure there is a 3 to 5 second delay between disabling MLAG and re-enabling MLAG. If the issue persists, disable it for 10 seconds, then enable it again.
- The IGMP querier IP address must be identical on both MLAG switches. To provide redundancy and ensure that both switches can act as IGMP queriers, configure the same querier IP address on both switches.
- MLAG does not support PTP boundary clock mode. Only transparent clock mode is supported.
- Anti-Configuration Error can be done in AVUI in Engage.
- Auto-LAG Global PTP mode in main UI configures PTP boundary clock on the newly formed Auto-LAG interface when it is enabled on the switch models that support PTP boundary clock mode.
Workaround: Do not enable Auto-LAG Global PTP mode from main UI if you do not use the PTP boundary clock mode of operation and configure it manually on the newly formed Auto-LAG interface.
- G&D Control Center IP devices fail to link up with the switch.
Workaround: Manually set the switch port speed to 1G to establish the link.
- This firmware includes a configuration migration process that transitions the default web browser protocol from HTTP to HTTPS. When you upgrade to this firmware and import an older configuration with HTTPS disabled, HTTPS becomes enabled.
Workaround: Reconfigure the web browser protocol settings manually after you perform a firmware upgrade or import an older configuration.
- During your initial login, you must set up a password to access the switch. However, if you access the main UI before you set up a password and simultaneously set the password in the AV UI, the switch console might lock for up to 15 minutes.
Workaround: Configure a password in either the main UI or the AV UI to avoid this lock up issue.
- If you upload only the private key or the certificate before you enable HTTPS, the system enables the HTTPS service but it fails to operate correctly because the configuration is incomplete. A factory reset does not fix this issue.
Workaround: Ensure both the private key and certificate are fully uploaded before you enable HTTPS. If the issue still occurs, remove the incomplete HTTPS-related private key or certificate, and disable HTTPS before reconfiguring.
- The four 25G ports of models M4350-44M4X4V, M4350-24X4V, and M4350-24F4V can operate at either 10G or 25G speed but not simultaneously at 10G and 25G speed.
- A stacking link works only at the highest speed that the port supports. For example, if you configure a 25G port in stack mode, the port can operate only at 25G and not at 10G. Therefore, you cannot establish a stacking link if a 10G port and a 25G port are interconnected.
Warnings:
Read and follow these warnings before updating your firmware:
- HTTPS is set to default web browser protocol from firmware version 14.0.6.10 and newer versions. The default certificate is self-signed, so a browser warning might display when you log in. To avoid this warning, you can download your own certificate that is issued by a trusted Certificate Authority (CA).
General Information:
- The boot code remains at the existing version 1.0.0.15 in this switch firmware.
- The process of upgrading the firmware and boot code takes about three minutes. Apply the “update bootcode” command from the command line interface. Do not switch off or restart the device during the upgrade process.
- This switch firmware upgrades AppMgr to version 1.0.6.16.
- Insight and Engage/AV UI are mutually exclusive. This means you can only use one of these options to configure and manage the switch, not both.
- If the encrypted password in the configuration file does not adhere to the NETGEAR password policy, when the configuration file is loaded on the firmware version 14.0.6.9 or later, you must create a new password during the initial login.
Download Link: https://www.downloads.netgear.com/files/GDC/M4350/M4350_V14.0.9.10.zip
Firmware Update Instructions:
To update your product’s firmware, follow the instructions in your product’s user manual. To find your user manual, visit https://www.netgear.com/support/, enter your model number in the search box, and click the Documentation button on the product page.