FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
markdr_FTNT
Staff
Staff
Article Id 387808
Description This article describes how to disable LLDP on individual ports of a FortiSwitch when managed by a FortiGate acting as a Switch Controller.
Scope All FortiSwitches when managed by a FortiGate Firewall.
Solution

LLDP (Link Layer Discovery Protocol) is a layer 2 neighbour discovery protocol and is used to advertise device capability to directly connected peers.

 

Disabling LLDP can significantly impact several network functions, including the inability to discover or map neighbouring devices, which hampers network topology management.

 

Additionally, it may disrupt functionality for network management tools that depend on LLDP for visualisation and interoperability with other devices, particularly regarding voice VLAN configuration and PoE settings.

 

Therefore, it is crucial to assess the implications of this decision in the context of overall network management and operational requirements before proceeding.

 

Generally, it is best practice to enable it; however, upon occasion, it is necessary to override the default behaviour and completely disable LLDP on a particular switch port.

 

Disable LLDP in scenarios where strict security protocols are in place that disallow the sharing of network device information, to minimize any potential overhead from unnecessary network communications, or to prevent devices from automatically exchanging configuration details, thereby ensuring greater control over network behaviour.

 

On a FortiGate-managed FortiSwitch, Disabling LLDP on an individual port can only be done via the CLI, as follows:

config switch-controller managed-switch

    edit <switch_name>

        config port

            edit <port>

                set lldp-status disable

            next

        end

    end

end