skip to content

Which three TLVs open every LLDP frame, and how does the Time To Live TLV let a neighbour forget a device that disappeared?

level: middleimportance: should knowfreq 16%

answer

  1. identity first, then a lifetime
  2. no acknowledgements, so expiry
  3. interval times hold multiplier
  4. a zero lifetime means delete now

basics

~20 s

Every LLDPDU opens with Chassis ID, Port ID and Time To Live. The TTL says how many seconds to keep the sender's information: without a fresh advertisement the entry ages out, and a TTL of 0 deletes it at once.

solid answer

~40 s

An LLDPDU starts with three mandatory TLVs in fixed order: `Chassis ID` and `Port ID`, which together identify the sending port, and `Time To Live`, a 16-bit count of seconds. Because LLDP is one-way, the receiver has no other way to learn a neighbour is gone: each fresh advertisement restarts its timer, and if the timer runs out the entry is deleted. The sender derives the TTL from its transmit interval times a hold multiplier — IEEE 802.1AB's defaults of 30 seconds and 4 give roughly 120 seconds, so several advertisements can be lost before the neighbour vanishes. When a port is administratively shut or LLDP is turned off, the agent sends a shutdown LLDPDU with TTL 0, and the receiver removes the entry immediately rather than waiting.

go deeper

for a junior

Recall the three mandatory TLVs, Chassis ID, Port ID and Time To Live, and that the TTL is a hold time in seconds.

for a middle

Explain why a one-way protocol needs a hold time, how interval times multiplier sets it, and what a TTL of 0 does on the receiver.

for a senior

Reason about stale neighbours after crashes versus clean shutdowns, and how interval and multiplier choices trade detection speed against frame load and loss tolerance.

for a principal

Judge whether topology tooling built on LLDP should trust a neighbour list that can lag reality by a full TTL, and what it should cross-check.

## The frame An **LLDP data unit (LLDPDU)** is carried directly in an Ethernet frame with **EtherType `0x88CC`**, sent to a reserved link-local multicast MAC address that standard bridges do not forward. Its body is nothing but a sequence of **type-length-value fields (TLVs)**. Each TLV header packs a **7-bit type** and a **9-bit length** into two bytes — the layout RFC 8520 reproduces when it defines its own LLDP extension — so a single TLV can carry at most 511 bytes of value. ## The mandatory three, and the optional rest IEEE 802.1AB requires the first three TLVs, in this order, in every LLDPDU. The type numbers below are the standard's. | Type | TLV | Mandatory? | Content | |---|---|---|---| | 1 | `Chassis ID` | yes | identifies the sending device, for example by a MAC address, network address, interface name or locally assigned string, marked by a subtype | | 2 | `Port ID` | yes | identifies the sending port, for example by an interface name, MAC address or locally assigned string | | 3 | `Time To Live` | yes | seconds the receiver may keep this information, 0 to 65,535 | | 4 | `Port Description` | no | administrator's text for the port | | 5 | `System Name` | no | configured hostname | | 6 | `System Description` | no | free text, often model and software release | | 7 | `System Capabilities` | no | what the device can be and what is enabled, such as bridge, router or telephone | | 8 | `Management Address` | no | an address and interface for management access | | 127 | Organizationally specific | no | an OUI and subtype, then the owner's own data | **Chassis ID plus Port ID** is the key a receiver files the advertisement under: one entry per sending port, per local port. If either value changes, the receiver sees a new neighbour rather than an update. ## Why LLDP needs a lifetime at all LLDP is **one-way**: RFC 8520 points out that LLDPDUs are not exchanged as requests and responses, and receivers do not acknowledge them. A receiver therefore never learns that a neighbour is gone by being told — the cable may be unplugged, the device may crash, a transceiver may die. The only signal is **silence**, and the TTL turns silence into a decision: 1. An LLDPDU arrives with TTL *t*; the receiver stores its TLVs and starts a timer of *t* seconds. 2. Each later LLDPDU from the same Chassis ID and Port ID replaces the stored data and restarts the timer. 3. If the timer expires with no fresh advertisement, the receiver deletes the entry. 4. If an LLDPDU arrives with **TTL 0**, the receiver deletes the entry immediately. ## Choosing the value: interval times multiplier The sender, not the receiver, chooses the TTL. It is based on two settings: - **Transmit interval** — how often an unchanged port re-advertises. IEEE 802.1AB's default is **30 seconds**. - **Hold multiplier** — how many intervals the information should outlive. The standard's default is **4**. With those defaults the TTL is about **120 seconds**, so the neighbour survives roughly three consecutive lost advertisements. These numbers are the IEEE standard's defaults, not an RFC rule, and implementations let operators change both. A shorter interval detects disappearance faster at the cost of more frames; a larger multiplier tolerates loss but keeps a dead neighbour visible longer. ## Shutdown and changes - **Shutdown LLDPDU.** When an administrator disables LLDP or shuts the port, the agent sends a final LLDPDU with TTL 0, carrying its Chassis ID and Port ID so the receiver knows which entry to drop. A crash or a pulled cable sends nothing, so the neighbour lingers until its TTL runs out. - **Change-triggered sends.** When local information changes — a renamed port, a new management address — the agent transmits early instead of waiting out the interval, limited so a flapping value cannot flood the link. ## Extending the format Type 127, the **organizationally specific TLV**, carries a three-byte OUI and a one-byte subtype before its data. That is how IEEE 802.1 adds VLAN information, IEEE 802.3 adds link and power details, TIA's LLDP-MED adds voice policy and inventory, and the IETF adds a Manufacturer Usage Description URL under IANA's OUI `00-00-5E`, subtype 1 (RFC 8520, registry rules in RFC 9542). A receiver that does not recognise an OUI skips the TLV by its length.

  • A switch loses power. How long can its neighbours keep listing it, and why not longer?
    Until the TTL from its last advertisement runs out — about 120 seconds with IEEE 802.1AB's defaults of a 30-second interval and a multiplier of 4. A crash sends no shutdown LLDPDU, so expiry is the only way out. The 16-bit TTL field caps any hold time at 65,535 seconds.
  • Why does LLDP put Chassis ID and Port ID together at the front rather than relying on the frame's source MAC address?
    Because the pair is the stable identity a receiver files the advertisement under. A source MAC address is just an interface address chosen by the sender's hardware; Chassis ID groups all of a device's ports under one identity, and Port ID names the port in terms people use, such as its interface name.

saying these in an interview costs you the question

  • The 30-second LLDP interval is fixed by an RFC
  • A Time To Live of 0 means the information never expires
  • The receiver sends keepalives to refresh the neighbour entry
  • System Name is mandatory in every LLDP frame
  • LLDP's TTL counts hops, like the IPv4 TTL field