Networking · Concept · 10 min read

What LLDP Is, and Why It Answers the Port Question

It replaces the wiring closet and the tone probe, it lets an IP phone find its own voice VLAN, and it hands the switch model and management address to anything plugged into a transmitting port.

Written by Marko Ristic, Editor Updated Sep 17, 2026
3Mandatory fields, and everything else is optional
120 sHow long a neighbor that has been unplugged keeps being listed
0x88CCThe ethertype, on an address bridges are told not to forward
2Separate settings, transmit and receive, on nearly every platform
Short answer

LLDP is the Link Layer Discovery Protocol, standardized as IEEE 802.1AB, and it is how a network device announces what it is and which port it is speaking from.

Every 30 seconds a switch, phone, access point or server sends a small frame out each port carrying its identity, its port name and how long to believe that. The result is that any device can be asked which switch and which port it is connected to, which is the most tedious question in an office network.

  • Devices tell each other what they are and which port they are on
  • Answers where a device is plugged in without walking to the closet
  • LLDP-MED lets an IP phone learn its voice VLAN and its power budget
  • It is a disclosure protocol, so it does not belong on a lobby port
  • Vendor neutral, unlike CDP, and usually disabled until enabled
On this page

The frameWhat LLDP actually sends

What is LLDP on the wire? One small Ethernet frame, and its shape explains the Link Layer Discovery Protocol as IEEE 802.1AB defines it.

An LLDP frame goes to a multicast destination address that an 802.1D bridge is required not to forward, so the information reaches the device on the other end of the cable and stops there. That single design choice is why the LLDP protocol describes a link rather than a network.

Inside the Ethernet frame is a sequence of TLVs, short for type, length, value. Each LLDP TLV declares its own type and length, so a receiving device can skip one it does not understand. Three TLVs are mandatory and the rest are optional, which is how the discovery protocol has been extended for twenty years without breaking anything.

TLVRequiredWhat it carries
Chassis IDYesWhich device this is, usually a MAC address
Port IDYesWhich port it left from, by name
Time to LiveYesHow long to keep the entry, typically 120 s
Port descriptionNoThe interface description configured on it
System nameNoThe device hostname
System capabilitiesNoBridge, router, telephone, access point
Management addressNoThe IP address to manage this device on
Organizationally specificNoVendor and standards body extensions

Note what is not in the list of TLVs: any request. LLDP is one way. A device announces, its neighbor records the information, and nothing ever asks a question. A missing neighbor therefore means either the far end is not sending or the near end is not listening, and on most equipment those are two separate settings.

The time to live TLV is worth understanding rather than skipping. A neighbor entry is not deleted when a cable is pulled; it ages out when the hold time expires.

With a 30 second interval and a 120 second hold, a device that has gone will still be listed for up to two minutes, which is exactly long enough to mislead somebody troubleshooting in real time.

The payoffThe question it answers

Ask any network team what the most tedious recurring question is and it is a version of this: something is misbehaving, and nobody knows which switch port it is on.

Without LLDP the procedure is to look up a MAC address, search the MAC address table on each switch, follow the port to a patch panel, and hope the labeling is current. With LLDP the device itself can be asked.

On the switch. A neighbor listing shows every device that has announced itself, with its own name and its own port name, per switch port. That is a live map of one hop in every direction.

On Cisco IOS the command is show lldp neighbors, once lldp run has enabled the protocol in the global configuration, and most other vendors use a close variant.

On the endpoint. A laptop, a server or an access point running an LLDP listener can report the switch name and port it is connected to. On a Windows or Linux machine that is a small utility; on a server or a hypervisor the protocol support is usually built in.

In the management system. Each device keeps the information it sends in a local MIB and the information it hears in a remote MIB, and both can be read over SNMP. That is how a network management system collects LLDP neighbors from every switch without logging in to any of them.

Two things follow that make this worth more than convenience. The first is that the answer comes from the network rather than from documentation, so it cannot be out of date the way a spreadsheet can.

The second is that the same information is what makes automatic topology maps in monitoring tools work at all: those maps are LLDP neighbor tables joined together, which is why a tool draws a beautiful diagram of the network devices that speak the protocol and nothing of the devices that do not.

VoiceLLDP-MED, and why an IP phone finds its own VLAN

LLDP-MED is the extension for endpoint devices, published as ANSI/TIA-1057 in 2006, and it is the reason desk phones are as close to plug and play as they are.

A phone plugs into an ordinary access port. The switch announces, through the MED TLVs, which VLAN the phone should tag its voice traffic with and what quality of service marking to use.

The phone reconfigures itself accordingly, and the PC plugged into the back of the phone continues to use the untagged data VLAN. Nobody configures the phone and nobody configures a second cable.

Power is negotiated the same way, through another TLV. The phone advertises how much power it needs, the switch advertises how much it is prepared to allocate, and the two devices settle on a number finer grained than the class based negotiation in the Ethernet hardware alone.

This is also why the same phone model works on one switch and not on another. If the LLDP-MED protocol extension is not enabled, or the network policy TLV is not configured, the phone never learns the voice VLAN, lands untagged on the data VLAN, and appears to be a phone problem.

DisclosureWhat LLDP tells anybody who plugs in

Here is the part the enable it everywhere advice usually leaves out.

LLDP is an announcement, and the frame leaves a port without knowing or caring what is on the other end. A device plugged into a port with LLDP transmitting learns, without authenticating and without sending anything, the switch model and system name, the exact port it is connected to, the interface description somebody wrote, the management IP address, and often the software version.

All of that information arrives in optional TLVs that were enabled for a good reason on a different kind of port.

For a reconnaissance step that is a substantial free gift, and it arrives within 30 seconds of plugging a laptop into a socket in a meeting room.

The resolution is not to disable LLDP. It is to notice that transmit and receive are separate settings on nearly every platform, and to configure them per port rather than globally.

The policy is short enough to write down.

Port facesTransmitReceiveWhy
Another switch or routerYesYesThe map of the network is the whole point
An access point or serverYesYesBoth ends belong in the topology
An IP phoneYes, with MEDYesThe phone needs the network policy TLV
A desk in a staffed areaYesYesUseful, and the risk is an internal one
A meeting room or lobbyNoYesYou still learn what plugged in
A guest or untrusted VLANNoNoNeither device should describe itself

The neighbor map keeps its value and the lobby stops narrating the network to visitors.

PitfallsWhere people go wrong

Leaving the protocol off and rebuilding the map by hand. The information is free and continuously correct. A spreadsheet is neither.

Enabling transmit on public ports. LLDP is a disclosure protocol on any port a stranger can reach. Transmit and receive are separate settings, and per port configuration is the answer.

Trusting a neighbor entry in real time. The hold time is typically 120 seconds, so a device that has just been unplugged is still listed. Check the timestamp before drawing a conclusion.

Expecting the frame to cross a switch. The destination address is one that bridges do not forward. LLDP describes one hop of the network, and a device two switches away will never appear.

Assuming a phone problem when the voice VLAN is missing. If LLDP-MED is not configured on the port, the phone cannot learn the VLAN and behaves exactly like a broken phone.

Enabling only CDP in a mixed estate. The LLDP vs CDP choice is simple when vendors are mixed: run the standard one. With CDP alone, every non Cisco device is invisible to the map, and it is usually the access points and the phones.

WHAT THE FRAME CARRIES, AND WHAT IT GIVES AWAYOne announcement, sent every 30 seconds, to whatever is on the other end.01:80:C2:00:00:0Edestinationsource MACthe sender0x88CCethertypeLLDPDUthe payload, expanded belowChassis IDmandatoryPort IDmandatoryTTLmandatorySystem nameoptionalPort descroptionalMgmt addressoptionalEndmandatorywhat a device on the port learnswithout authenticating, without sending anythingThe three mandatory fields are what makes the neighbor map work.The optional tail is why transmit and receive belong configured per port.
The same optional fields that make a topology map worth having are the ones worth switching off where a stranger can plug in.

ComparisonLLDP, CDP and the proprietary alternatives, side by side

CriterionLLDPCDPFDP, EDP and others
StandardIEEE 802.1ABCisco proprietaryVendor proprietary
Works between vendorsYesOnly with CiscoNo
Ethertype0x88CCSNAP, 0x2000Vendor specific
Voice extensionLLDP-MEDBuilt into CDPVaries
Typical interval30 s60 sVaries
Enabled by defaultOften notOn Cisco, usually yesVaries
Use it whenAlways, per portA Cisco only estateLegacy equipment

The row that decides it is the second. A mixed estate, which is nearly every estate an MSP inherits, gets a complete map only from the protocol every vendor implements. Running both is normal and costs nothing; running only the proprietary one leaves holes exactly where the equipment came from a different supplier.

FAQFrequently asked questions

What is LLDP?

The Link Layer Discovery Protocol, a link layer discovery protocol standardized as IEEE 802.1AB. Network devices use it to announce their identity, their port and their capabilities to whatever is on the other end of the cable.

What does LLDP stand for?

Link Layer Discovery Protocol. Link layer because it works between two directly connected devices, and discovery because the whole purpose is finding out what is there.

What is LLDP used for?

Answering which switch and which port a device is connected to, feeding automatic topology maps, and letting IP phones learn their voice VLAN and power budget through LLDP-MED.

How does LLDP work?

Each device periodically sends an Ethernet frame out every enabled port containing its chassis ID, port ID and a time to live, plus optional TLVs. The neighbor stores the information and ages it out when the time to live expires.

What is the difference between LLDP and CDP?

CDP is the Cisco Discovery Protocol and works only between Cisco devices. LLDP is the IEEE standard and works between every vendor that implements it, which is why a mixed estate needs it.

How often does LLDP send updates?

Every 30 seconds on most equipment, with a hold time of 120 seconds, so a neighbor that disappears stays in the table for up to two minutes.

What is LLDP-MED?

The media endpoint extension, published as ANSI/TIA-1057 in 2006. It carries the network policy and power TLVs that let an IP phone configure its own voice VLAN and negotiate power.

Is LLDP a security risk?

It is a disclosure risk. A device plugged into a transmitting port learns the switch name, the port, the interface description and often the management IP without authenticating, which is why user facing and public ports should not transmit.

Does LLDP cross switches?

No. It is sent to a multicast address that compliant bridges do not forward, so it describes one link. Neighbors more than one hop away never appear.

What TLVs are mandatory in LLDP?

Chassis ID, Port ID and Time to Live, in that order, followed by any optional TLVs and an end of LLDPDU marker. Every other TLV, including the system name and the management address, is optional.

What ethertype does LLDP use?

The Ethernet type is 0x88CC. The destination is a reserved multicast address, normally 01:80:C2:00:00:0E, chosen because bridges are required not to forward the frame.

Is LLDP enabled by default?

Often not. Many platforms ship with it globally disabled, and on some it is enabled to receive but not to transmit, which is why one side of a link can see the other and not the reverse.

Can a server or a laptop use LLDP?

Yes. Hypervisors and many server operating systems can listen and report the switch and port they are connected to, and there are small utilities for ordinary desktops.

Does LLDP replace network documentation?

It replaces the part that goes stale, which is which device is on which port. It does not tell you why a link exists or what depends on it, and that is what a CMDB is for.

Is LLDP a network discovery protocol?

Yes. LLDP is the vendor neutral network discovery protocol defined in IEEE 802.1AB. Each device announces its name, port, capabilities and management address to its direct neighbors. Monitoring tools read those tables to draw the topology. CDP is Cisco's proprietary equivalent.

Read next · Operations What a CMDB Is, and the Question That Justifies One What LLDP cannot tell you, which is why a link exists and what breaks if it goes away. Open this next10 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.