Hi!
I've enabled receive/transmit LLDP globally and confirmed on adjacent (Cisco) switches that this works for all Fortigate interfaces.
However, on Fortigate, "diagnose lldprx port neighbor" shows expected information, except that it excludes the interface (mgmt1) I provisioned as a Reserved HA Management interface.
How to show LLDP neighbor for ha-mgmt-interfaces?
Thanks!
Hi AlexFerenX,
When you enable HA reserved management, FortiGate configures that interface as out‑of‑band management and removes it from the regular routing/VDOM so it won't function like a normal data interface.
FortiGate creates a hidden VDOM named vsys_hamgmt for reserved management interfaces. These interfaces are isolated—they don't participate in normal traffic flows or routing in the root VDOM
LLDP neighbor detection on FortiGate runs within the main forwarding/routing (root VDOM) not within vsys_hamgmt—the interface mgmt1 is excluded from LLDP discovery and isn't shown by CLI command: diagnose lldprx port neighbor
You can use a regular interface (not HA reserved) for LLDP visibility.
Regards,
Aman
Hi @kaman
thanks for writing a lot, but none of it answers the question - again: “How to show LLDP neighbor [information] for ha-mgmt-interfaces?”
Do you know the answer?
Thanks!
User | Count |
---|---|
2593 | |
1381 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.