I would like to disable CDP and have noticed it is referenced in certain CLI commands in the CLI reference. However, I have been unable to find how it might be disabled globally. Is there a command to achieve this?
You said "config switch-controller", then it is for FortiSwitch.
HI @jefazo92
if you want to block CDP protocol traffic in Fortigate you can create a local in policy and block the communication.
refer to the below link for the creation of the local_in policy and modify it based on the protocol number of CDP.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-the-IGMP-protocol-using-a-loc...
Thank you @sbabu but the list of protocols (https://docs.fortinet.com/document/fortigate/6.0.0/handbook/451530/protocol-number) which can be configured as a firewall custom service do not include CDP.
User | Count |
---|---|
2131 | |
1187 | |
770 | |
451 | |
345 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.