skip to content

How does LLDP-MED let an IP phone on an access switch port learn its voice VLAN and negotiate its PoE power?

level: middleimportance: nice to knowfreq 12%

answer

  1. a TIA extension inside LLDP
  2. organizationally specific TLVs
  3. network policy: VLAN, priority, DSCP
  4. exact watts beyond the class

basics

~20 s

LLDP-MED, a TIA extension carried in ordinary LLDP frames, has the switch advertise a Network Policy TLV giving the voice VLAN ID, priority and DSCP, and lets phone and switch exchange Extended Power-via-MDI TLVs to agree an exact power draw.

solid answer

~40 s

LLDP-MED (Media Endpoint Discovery) is a TIA standard, ANSI/TIA-1057, that adds organizationally specific TLVs under TIA's OUI to normal LLDP frames. When the switch hears a MED-capable phone, it advertises a **Network Policy** TLV for the voice application: the VLAN ID, whether to tag, the 802.1p priority and the DSCP value. When the policy says tagged, the phone sends its voice frames 802.1Q-tagged with that VLAN and priority, while the PC behind it stays untagged in the data VLAN. For power, PoE's electrical classification at link-up only gives a coarse class; the **Extended Power-via-MDI** TLV lets the phone state the power it actually needs, with a priority, so the switch can budget that figure instead of the class maximum. MED also carries inventory and an emergency-call location.

go deeper

for a junior

Recall that LLDP-MED tells an IP phone its voice VLAN and helps settle how much PoE power it gets.

for a middle

Explain the Network Policy TLV's VLAN, priority and DSCP, the tagged-voice and untagged-PC split, and why LLDP power TLVs refine PoE classification.

for a senior

Discuss what happens when MED is missing or spoofed, how fast start shortens phone boot, and how power priority decides which ports lose power first.

for a principal

Weigh switch-owned voice policy against per-device configuration, and decide how much endpoint trust a voice VLAN grants without port authentication.

## What LLDP-MED adds Plain LLDP lets devices describe themselves. **LLDP-MED** (Media Endpoint Discovery), published by the Telecommunications Industry Association as **ANSI/TIA-1057**, turns that description channel into a light configuration channel for endpoints such as IP phones. It defines no new protocol: its data rides in ordinary LLDP frames as **organizationally specific TLVs** — LLDP TLV type 127, followed by TIA's OUI and a subtype — so it inherits LLDP's properties. It is one-hop, one-way and unacknowledged, and it needs no IP address, which is exactly why it works before the phone has one. MED distinguishes **network connectivity devices** (the switch) from **endpoints**, which come in classes: Class I generic endpoints, Class II media endpoints, and Class III communication devices such as IP phones. ## The TLVs that matter | LLDP-MED TLV | Who sends it | Purpose | |---|---|---| | `LLDP-MED Capabilities` | both | announces MED support and the device type or endpoint class | | `Network Policy` | switch, and the endpoint echoing what it uses | per application (voice, voice signalling, video): VLAN ID, tagged flag, layer 2 priority, DSCP | | `Extended Power-via-MDI` | both | power type, source, priority and a power value in 0.1 W units | | `Location Identification` | switch | coordinates, a civic address or an emergency number identifier for emergency calls | | `Inventory` | endpoint | hardware, firmware and software revisions, serial number, manufacturer, model, asset ID | ## How a phone finds its voice VLAN 1. The phone powers up and links. Its first LLDPDUs include the `LLDP-MED Capabilities` TLV, declaring it a communication device. 2. A switch port that supports MED typically starts adding its own MED TLVs once it has heard a MED endpoint, sending a few LLDPDUs in quick succession ("fast start") so the phone is not left waiting a full interval. 3. The switch's `Network Policy` TLV for the voice application says, for example: VLAN 110, tagged, priority 5, DSCP 46. 4. The phone sends voice traffic in 802.1Q-tagged frames carrying VLAN 110 and priority 5, and marks the IP packets with DSCP 46 (the DSCP field itself is defined in RFC 2474). 5. The phone requests its IP address with DHCP inside the voice VLAN. 6. A PC plugged into the phone's pass-through port keeps sending untagged frames, which the switch puts in the port's ordinary data VLAN. If the policy's tagged flag is clear, the phone sends voice untagged and shares the port's own VLAN with the PC; the tagged case above is the usual design because it keeps voice and data apart on one cable. The point of the design is that the switch, not each phone's local settings, owns the voice VLAN number: change it once on the switch and every phone follows at its next advertisement. ## How power is negotiated PoE first powers a device after detecting and **classifying** it electrically at link-up. Classification yields only a coarse power class, and a switch that budgets by class typically reserves that class's maximum even if the phone draws far less. LLDP refines it: - The phone advertises, in `Extended Power-via-MDI`, the power it actually requires and its priority (critical, high or low). - The switch advertises its own power information in return and can budget the port at the requested figure rather than the class maximum. - If the switch's power supply runs short, the priority tells it which ports to keep powered. IEEE 802.3 defines its own `Power via MDI` organizationally specific TLV for the same negotiation; which of the two a given phone and switch use is a matter of what each implements. ## Limits worth stating - **No authentication.** Any device on the port can claim to be a phone and will receive the voice policy; securing that needs port authentication, not LLDP. - **One hop only.** MED configures the device on the other end of the cable, nothing further. - **Alternatives exist.** Before MED, phones commonly learned their voice VLAN from a proprietary discovery protocol (CDP is the best-known) or a vendor-specific DHCP option; in a mixed network MED is the vendor-neutral choice. The interview answer is the sequence: MED rides in LLDP, the switch's network policy hands over the voice VLAN and markings, the phone tags accordingly, and an exact power figure replaces the coarse class.

  • What does the phone do with the priority and DSCP values in the LLDP-MED Network Policy TLV?
    It writes the layer 2 priority into the 802.1Q tag of its voice frames and the DSCP value into the IP header of its voice packets. Switches use the frame priority to queue voice ahead of bulk traffic on the link, and routers use DSCP once the frames are stripped, so the markings stay consistent across the network.
  • Why negotiate power over LLDP when PoE classification already happens at link-up?
    Because classification gives only a coarse class, and a switch budgeting by class reserves that class's maximum. An LLDP power TLV states the real requirement and a priority, so the switch can power more phones from the same supply and knows which ports to shed first if it runs short.

saying these in an interview costs you the question

  • LLDP-MED is one vendor's proprietary protocol
  • LLDP-MED replaces DHCP for the phone's IP address
  • PoE power can only come from link-up classification
  • LLDP-MED runs on its own EtherType separate from LLDP
  • The phone learns its voice VLAN by sending the switch a request