TP-Link

Prepare TP-Link devices for QUARK Config Backup.

This guide covers TP-Link managed switches (JetStream and Omada lines), DeltaStream GPON OLTs, and the legacy TL-SL5428 and TL-SL3428 switches.

This applies to JetStream and Omada managed switches with a full CLI.

Create a backup account. In the web UI under System > User Management, add a user named netwatch-backup. TP-Link switches offer several access levels (Admin, Operator, Power User, User); only the Admin level can display the complete running configuration, so assign Admin. QUARK only runs show commands and never changes the switch.

Enable SSH access. Enable the SSH server in the web UI under Security > Access Security > SSH Config (you can do the same from the CLI). To restrict management sources, use Security > Access Security > Access Control and limit access to the Netwatch collector's IP address.

Notes. If the switch prompts for a separate enable/privileged password when entering privileged mode from the CLI, record it in QUARK along with the account credentials.

DeltaStream GPON OLT

This applies to TP-Link DeltaStream GPON OLT chassis.

Create a backup account. Create a dedicated account with administrator rights through the OLT's CLI user management or web interface — displaying the full running configuration, including ONU provisioning, requires administrative privilege on this platform.

Enable SSH access. Enable the SSH server in the management settings where your firmware supports it; older firmware may only offer Telnet. Restrict management access to the Netwatch collector's IP using the OLT's management ACL if available, or an upstream ACL otherwise.

Notes. The configuration includes ONU/ONT provisioning, which makes the backup useful for full service restoration.

TL-SL5428

This applies to the legacy TL-SL5428 switch family.

Create a backup account. Account management is limited on this generation — create an admin-level login in the web UI if your firmware supports multiple users; otherwise set a strong password on the built-in admin account and store those credentials in QUARK.

Enable management access. Enable SSH in the access security settings if your firmware revision offers it; many units of this generation only support Telnet, which QUARK can use instead. Restrict management to the collector's IP with the switch's access control settings where present, or an upstream ACL.

Notes. Firmware on this model is no longer updated; treat Telnet-only units as candidates for an isolated management VLAN.

TL-SL3428

This applies to the legacy TL-SL3428 switch family.

Create a backup account. As with the TL-SL5428, create an admin-level login where the firmware supports it, or use the built-in admin account with a strong password. Administrative access is required to retrieve the full configuration.

Enable management access. Use SSH if your firmware provides it; otherwise enable Telnet management. Limit management sources to the Netwatch collector's IP via the switch's access control settings or an upstream ACL.

Notes. Verify configuration retrieval manually once after adding the device — legacy firmware revisions vary in CLI behavior.

Enable backup in Netwatch

Once the device is prepared, open its host in Netwatch (Data collection > Hosts) and add the Config Backup macros — the supported status flag, the model code for this platform, and the credentials you created. See Getting started for the full macro list and values.

On this page