LLDP is the Link Layer Discovery Protocol, standardized as IEEE 802.1AB, and it is how a network device announces what it is and which port it is speaking from.
Every 30 seconds a switch, phone, access point or server sends a small frame out each port carrying its identity, its port name and how long to believe that. The result is that any device can be asked which switch and which port it is connected to, which is the most tedious question in an office network.
- Devices tell each other what they are and which port they are on
- Answers where a device is plugged in without walking to the closet
- LLDP-MED lets an IP phone learn its voice VLAN and its power budget
- It is a disclosure protocol, so it does not belong on a lobby port
- Vendor neutral, unlike CDP, and usually disabled until enabled
On this page
The frameWhat LLDP actually sends
What is LLDP on the wire? One small Ethernet frame, and its shape explains the Link Layer Discovery Protocol as IEEE 802.1AB defines it.
An LLDP frame goes to a multicast destination address that an 802.1D bridge is required not to forward, so the information reaches the device on the other end of the cable and stops there. That single design choice is why the LLDP protocol describes a link rather than a network.
Inside the Ethernet frame is a sequence of TLVs, short for type, length, value. Each LLDP TLV declares its own type and length, so a receiving device can skip one it does not understand. Three TLVs are mandatory and the rest are optional, which is how the discovery protocol has been extended for twenty years without breaking anything.
| TLV | Required | What it carries |
|---|---|---|
| Chassis ID | Yes | Which device this is, usually a MAC address |
| Port ID | Yes | Which port it left from, by name |
| Time to Live | Yes | How long to keep the entry, typically 120 s |
| Port description | No | The interface description configured on it |
| System name | No | The device hostname |
| System capabilities | No | Bridge, router, telephone, access point |
| Management address | No | The IP address to manage this device on |
| Organizationally specific | No | Vendor and standards body extensions |
Note what is not in the list of TLVs: any request. LLDP is one way. A device announces, its neighbor records the information, and nothing ever asks a question. A missing neighbor therefore means either the far end is not sending or the near end is not listening, and on most equipment those are two separate settings.
The time to live TLV is worth understanding rather than skipping. A neighbor entry is not deleted when a cable is pulled; it ages out when the hold time expires.
With a 30 second interval and a 120 second hold, a device that has gone will still be listed for up to two minutes, which is exactly long enough to mislead somebody troubleshooting in real time.
The payoffThe question it answers
Ask any network team what the most tedious recurring question is and it is a version of this: something is misbehaving, and nobody knows which switch port it is on.
Without LLDP the procedure is to look up a MAC address, search the MAC address table on each switch, follow the port to a patch panel, and hope the labeling is current. With LLDP the device itself can be asked.
On the switch. A neighbor listing shows every device that has announced itself, with its own name and its own port name, per switch port. That is a live map of one hop in every direction.
On Cisco IOS the command is show lldp neighbors, once lldp run has enabled the protocol in the global configuration, and most other vendors use a close variant.
On the endpoint. A laptop, a server or an access point running an LLDP listener can report the switch name and port it is connected to. On a Windows or Linux machine that is a small utility; on a server or a hypervisor the protocol support is usually built in.
In the management system. Each device keeps the information it sends in a local MIB and the information it hears in a remote MIB, and both can be read over SNMP. That is how a network management system collects LLDP neighbors from every switch without logging in to any of them.
Two things follow that make this worth more than convenience. The first is that the answer comes from the network rather than from documentation, so it cannot be out of date the way a spreadsheet can.
The second is that the same information is what makes automatic topology maps in monitoring tools work at all: those maps are LLDP neighbor tables joined together, which is why a tool draws a beautiful diagram of the network devices that speak the protocol and nothing of the devices that do not.
VoiceLLDP-MED, and why an IP phone finds its own VLAN
LLDP-MED is the extension for endpoint devices, published as ANSI/TIA-1057 in 2006, and it is the reason desk phones are as close to plug and play as they are.
A phone plugs into an ordinary access port. The switch announces, through the MED TLVs, which VLAN the phone should tag its voice traffic with and what quality of service marking to use.
The phone reconfigures itself accordingly, and the PC plugged into the back of the phone continues to use the untagged data VLAN. Nobody configures the phone and nobody configures a second cable.
Power is negotiated the same way, through another TLV. The phone advertises how much power it needs, the switch advertises how much it is prepared to allocate, and the two devices settle on a number finer grained than the class based negotiation in the Ethernet hardware alone.
This is also why the same phone model works on one switch and not on another. If the LLDP-MED protocol extension is not enabled, or the network policy TLV is not configured, the phone never learns the voice VLAN, lands untagged on the data VLAN, and appears to be a phone problem.
DisclosureWhat LLDP tells anybody who plugs in
Here is the part the enable it everywhere advice usually leaves out.
LLDP is an announcement, and the frame leaves a port without knowing or caring what is on the other end. A device plugged into a port with LLDP transmitting learns, without authenticating and without sending anything, the switch model and system name, the exact port it is connected to, the interface description somebody wrote, the management IP address, and often the software version.
All of that information arrives in optional TLVs that were enabled for a good reason on a different kind of port.
For a reconnaissance step that is a substantial free gift, and it arrives within 30 seconds of plugging a laptop into a socket in a meeting room.
The resolution is not to disable LLDP. It is to notice that transmit and receive are separate settings on nearly every platform, and to configure them per port rather than globally.
The policy is short enough to write down.
| Port faces | Transmit | Receive | Why |
|---|---|---|---|
| Another switch or router | Yes | Yes | The map of the network is the whole point |
| An access point or server | Yes | Yes | Both ends belong in the topology |
| An IP phone | Yes, with MED | Yes | The phone needs the network policy TLV |
| A desk in a staffed area | Yes | Yes | Useful, and the risk is an internal one |
| A meeting room or lobby | No | Yes | You still learn what plugged in |
| A guest or untrusted VLAN | No | No | Neither device should describe itself |
The neighbor map keeps its value and the lobby stops narrating the network to visitors.
PitfallsWhere people go wrong
Leaving the protocol off and rebuilding the map by hand. The information is free and continuously correct. A spreadsheet is neither.
Enabling transmit on public ports. LLDP is a disclosure protocol on any port a stranger can reach. Transmit and receive are separate settings, and per port configuration is the answer.
Trusting a neighbor entry in real time. The hold time is typically 120 seconds, so a device that has just been unplugged is still listed. Check the timestamp before drawing a conclusion.
Expecting the frame to cross a switch. The destination address is one that bridges do not forward. LLDP describes one hop of the network, and a device two switches away will never appear.
Assuming a phone problem when the voice VLAN is missing. If LLDP-MED is not configured on the port, the phone cannot learn the VLAN and behaves exactly like a broken phone.
Enabling only CDP in a mixed estate. The LLDP vs CDP choice is simple when vendors are mixed: run the standard one. With CDP alone, every non Cisco device is invisible to the map, and it is usually the access points and the phones.
ComparisonLLDP, CDP and the proprietary alternatives, side by side
| Criterion | LLDP | CDP | FDP, EDP and others |
|---|---|---|---|
| Standard | IEEE 802.1AB | Cisco proprietary | Vendor proprietary |
| Works between vendors | Yes | Only with Cisco | No |
| Ethertype | 0x88CC | SNAP, 0x2000 | Vendor specific |
| Voice extension | LLDP-MED | Built into CDP | Varies |
| Typical interval | 30 s | 60 s | Varies |
| Enabled by default | Often not | On Cisco, usually yes | Varies |
| Use it when | Always, per port | A Cisco only estate | Legacy equipment |
The row that decides it is the second. A mixed estate, which is nearly every estate an MSP inherits, gets a complete map only from the protocol every vendor implements. Running both is normal and costs nothing; running only the proprietary one leaves holes exactly where the equipment came from a different supplier.
FAQFrequently asked questions
What is LLDP?
The Link Layer Discovery Protocol, a link layer discovery protocol standardized as IEEE 802.1AB. Network devices use it to announce their identity, their port and their capabilities to whatever is on the other end of the cable.
What does LLDP stand for?
Link Layer Discovery Protocol. Link layer because it works between two directly connected devices, and discovery because the whole purpose is finding out what is there.
What is LLDP used for?
Answering which switch and which port a device is connected to, feeding automatic topology maps, and letting IP phones learn their voice VLAN and power budget through LLDP-MED.
How does LLDP work?
Each device periodically sends an Ethernet frame out every enabled port containing its chassis ID, port ID and a time to live, plus optional TLVs. The neighbor stores the information and ages it out when the time to live expires.
What is the difference between LLDP and CDP?
CDP is the Cisco Discovery Protocol and works only between Cisco devices. LLDP is the IEEE standard and works between every vendor that implements it, which is why a mixed estate needs it.
How often does LLDP send updates?
Every 30 seconds on most equipment, with a hold time of 120 seconds, so a neighbor that disappears stays in the table for up to two minutes.
What is LLDP-MED?
The media endpoint extension, published as ANSI/TIA-1057 in 2006. It carries the network policy and power TLVs that let an IP phone configure its own voice VLAN and negotiate power.
Is LLDP a security risk?
It is a disclosure risk. A device plugged into a transmitting port learns the switch name, the port, the interface description and often the management IP without authenticating, which is why user facing and public ports should not transmit.
Does LLDP cross switches?
No. It is sent to a multicast address that compliant bridges do not forward, so it describes one link. Neighbors more than one hop away never appear.
What TLVs are mandatory in LLDP?
Chassis ID, Port ID and Time to Live, in that order, followed by any optional TLVs and an end of LLDPDU marker. Every other TLV, including the system name and the management address, is optional.
What ethertype does LLDP use?
The Ethernet type is 0x88CC. The destination is a reserved multicast address, normally 01:80:C2:00:00:0E, chosen because bridges are required not to forward the frame.
Is LLDP enabled by default?
Often not. Many platforms ship with it globally disabled, and on some it is enabled to receive but not to transmit, which is why one side of a link can see the other and not the reverse.
Can a server or a laptop use LLDP?
Yes. Hypervisors and many server operating systems can listen and report the switch and port they are connected to, and there are small utilities for ordinary desktops.
Does LLDP replace network documentation?
It replaces the part that goes stale, which is which device is on which port. It does not tell you why a link exists or what depends on it, and that is what a CMDB is for.
Is LLDP a network discovery protocol?
Yes. LLDP is the vendor neutral network discovery protocol defined in IEEE 802.1AB. Each device announces its name, port, capabilities and management address to its direct neighbors. Monitoring tools read those tables to draw the topology. CDP is Cisco's proprietary equivalent.
Keep readingRelated concepts
Read next · Operations What a CMDB Is, and the Question That Justifies One What LLDP cannot tell you, which is why a link exists and what breaks if it goes away. Open this next10 min- Switching · 14 min What Is a VLAN? The voice and data separation that LLDP-MED configures for a phone automatically, and what happens when the phone never learns it.
- Switching · 9 min The MAC Address Table, and How to Find Which Port a Device Is On The slower way to answer the same question, by looking up an address on every switch and following the port to a patch panel.
- Tools · 11 min Network Management Software, and the Three Questions It Has to Answer What draws the map in the console.