| Description |
This article describes that in certain industrial environments, devices using Profinet communication—specifically PTCP (Precision Time Control Protocol) may send packets using the multicast MAC address 01:80:c2:00:00:0e. PTCP leverages LLDP-like behavior but uses a different ethertype (0x8892 instead of 0x88cc).
While in some setups this traffic remains local, in others, it traverses the LAN via FortiSwitch. Certain FortiSwitch models are unable to correctly handle these Profinet packets and enter CPU exhaustion due to the unexpected ethertype. This leads to FortiLink flapping and overall instability.
Important Note: One of the parameters to build FortiLink is LLDP. Refer to Technical Tip: Management Protocols for FortiSwitch discovery on FortiGate. |
| Scope | FortiSwitch v7.4, v7.6. |
| Solution |
Validation:
Solution 1: Block Profinet Traffic with ACL (if traffic is not required on FortiSwitch): If Profinet traffic is not expected on the FortiSwitch, configure an ACL to drop it. The example below demonstrates how to drop traffic destined for 01:80:c2:00:00:0e on VLAN 100 from port1:
FortiSwitch versions v7.4.5 and v7.6.1 introduce a new setting to control Profinet traffic forwarding via LLDP configuration:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.