Created on
04-15-2025
11:57 PM
Edited on
04-17-2025
06:51 AM
By
Stephen_G
| Description | This article describes how to disable LLDP on individual ports of a FortiSwitch when managed by a FortiGate acting as a Switch Controller. |
| Scope | All FortiSwitches when managed by a FortiGate Firewall. |
| Solution |
LLDP (Link Layer Discovery Protocol) is a layer 2 neighbour discovery protocol and is used to advertise device capability to directly connected peers.
Disabling LLDP can significantly impact several network functions, including the inability to discover or map neighbouring devices, which hampers network topology management.
Additionally, it may disrupt functionality for network management tools that depend on LLDP for visualisation and interoperability with other devices, particularly regarding voice VLAN configuration and PoE settings.
Therefore, it is crucial to assess the implications of this decision in the context of overall network management and operational requirements before proceeding.
Generally, it is best practice to enable it; however, upon occasion, it is necessary to override the default behaviour and completely disable LLDP on a particular switch port.
Disable LLDP in scenarios where strict security protocols are in place that disallow the sharing of network device information, to minimize any potential overhead from unnecessary network communications, or to prevent devices from automatically exchanging configuration details, thereby ensuring greater control over network behaviour.
On a FortiGate-managed FortiSwitch, Disabling LLDP on an individual port can only be done via the CLI, as follows: config switch-controller managed-switch edit <switch_name> config port edit <port> set lldp-status disable next end end end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.