Description

This article provides information about the support extended by branch SRX and J-series devices for the Link Layer Discovery Protocol (LLDP).
 

Symptoms

If you have configured the LLDP protocol for a VLAN tagged interface or Reth interface on a SRX branch device:
 

  • Peers for LLDP are able to ping each other.
  • But, you are not able to see the peer in the output of the show lldp neighbor command on SRX.

Solution

This is a limitation on SRX branch devices - SRX100, SRX210, SRX220, SRX240, SRX650, and all J-series devices for VLAN tagged routed interfaces and Reth interfaces. LLDP is not supported.

Verification on SRX :

root@JuniperSRX220H# set protocols lldp interface ge-0/0/0.0 
[edit]
root@210-hm1-oncall# commit                                   //Work on ge-0/0/0.0 Interface
[edit]
root@SRX# set protocols lldp interface ge-0/0/0.1   
[edit]
root@SRX# commit 
[edit protocols]
  'lldp'
    Invalid interface name. LLDP operates only on physical interfaces
error: configuration check-out failed



Below consolidated Supportability of LLDP In SRX-Branch in Junos 12.1X44/12.1X45/12.1X46/12.1X47/12.3X48/15.1X49:


12.1X44/12.1X45/12.1X46
Extracted from Known Behaviour Section in Release note of 12.1X44-D60 / 12.1X45-D30 / 12.1X46-D55 .
  • On all SRX Series devices, the Link Layer Discovery Protocol (LLDP) is not supported on reth interfaces.
  • On all J Series devices, Link Layer Discovery Protocol (LLDP) is not supported on routed ports.
  • On SRX100, SRX210, SRX220, SRX240, SRX650, and all J Series devices, on VLAN-tagged routed interfaces, LLDP is not supported.


Note: From release of 12.1X44-D60
  • On SRX650 devices, Link Layer Discovery Protocol (LLDP) is not supported on the base ports of the device and on the 2-Port 10 Gigabit Ethernet XPIM.

12.1X47
Extracted from Knwon Behaviour Section  in Release note of 12.1X47-D40
  • On all SRX Series devices, the Link Layer Discovery Protocol (LLDP) is not supported on reth interfaces.

Extracted from Concept and example URL below:
https://www.juniper.net/techpubs/en_US/junos12.1x47/topics/concept/layer-2-ethernet-port-switching-security-overview.html
  • On SRX100, SRX210, SRX220, SRX240, and SRX650 devices, on VLAN-tagged routed interfaces, LLDP is not supported.


12.3X48
Extracted from Concept and example URL below:
https://www.juniper.net/techpubs/en_US/junos12.3x48/topics/concept/layer-2-ethernet-port-switching-security-overview.html
  • On SRX100, SRX210, SRX220, SRX240, and SRX650 devices, on VLAN-tagged routed interfaces, LLDP is not supported.
  • On all SRX Series devices, the Link Layer Discovery Protocol (LLDP) is not supported on reth interfaces.

15.1X49
Extracted from Release Notes of 15.1X49-D60
  • On SRX300, SRX320, SRX340, and SRX345 devices, on VLAN-tagged routed interfaces, LLDP is not supported.
  • LLDP and LLDP-MED for SRX300, SRX320, SRX340, SRX345, SRX550M and SRX1500 devices—Starting with Junos OS Release 15.1X49-D60, Link Layer Discovery Protocol (LLDP) and LLDP-Media Endpoint Discovery (MFD) are supported on Layer 3 interfaces for SRX300, SRX320, SRX340, SRX345, SRX550M and SRX1500 devices.