A real-life situation
You inherit a network with no diagram. You are logged in to R1 and need to know what is plugged into each port and which port on the other device the cable lands in. Walking to the wiring closet and tracing cables takes an afternoon. A neighbour discovery protocol answers the question in one command.
What CDP and LLDP are
A neighbour discovery protocol lets a device send a short "this is me" message out of each of its interfaces. Devices on the other end store what they hear in a neighbour table. There are two you need to know:
- CDP (Cisco Discovery Protocol): Cisco's own protocol. Enabled by default on Cisco routers, switches, IP phones and access points.
- LLDP (Link Layer Discovery Protocol): the open IEEE 802.1AB standard, used by every vendor. Supported on Cisco devices but disabled by default on most IOS and IOS XE platforms. A variant called LLDP-MED adds features for phones and other endpoints.
Both share information such as:
- the neighbour's name (the Device ID, usually its hostname),
- the neighbour's own interface the cable is plugged into (the Port ID),
- its capabilities (router, switch, phone, access point),
- its model (platform) and software version,
- a management IP address, and on switches the native VLAN and duplex.
- 1. SW1 and SW2 advertise to R1. Each switch sends a CDP message out of every port; R1 records both, with the port at each end.
- 2. R1 advertises back. Discovery runs in both directions, so each switch also lists R1.
- 3. The third-party AP speaks only LLDP. SW1 sees AP-FLOOR1 only if LLDP is enabled on SW1. CDP alone would miss it.
- 4. CDP toward the ISP is a leak. R1 would advertise its model and IOS version to a network you don't control. Turn CDP off on Gi0/0.
- 5. Only one hop. SW1 does not pass the AP's or anyone else's messages on. R1 never learns about AP-FLOOR1 or PC1.
Why it works that way
CDP and LLDP run at Layer 2. Each message is an Ethernet frame sent to a reserved multicast MAC address (CDP uses 01:00:0C:CC:CC:CC, LLDP uses 01:80:C2:00:00:0E). Because no IP is involved, discovery works even before addresses are configured or when IP is misconfigured. That is exactly when you need it most.
A device that understands the protocol keeps the frame and does not forward it. That is deliberate: the table should describe the cable you are standing at, not a device three switches away. A Cisco switch therefore never lists a device it isn't directly cabled to.
How it works step by step
Each message carries a holdtime: how long the receiver should keep the entry if it hears nothing more. The sender repeats its message on a timer well inside that holdtime, so a healthy neighbour never expires.
LLDP behaves the same way with different defaults: every 30 seconds, holdtime 120 seconds.
| CDP | LLDP | |
|---|---|---|
| Standard | Cisco proprietary | IEEE 802.1AB (open) |
| Default on Cisco IOS | Enabled | Disabled |
| Advertisement timer | 60 s | 30 s |
| Holdtime | 180 s | 120 s |
| Turn on/off globally | cdp run / no cdp run | lldp run / no lldp run |
| Per interface | cdp enable / no cdp enable | lldp transmit and lldp receive (separately) |
How to configure it on Cisco IOS
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device.
CDP
cdp run
interface GigabitEthernet0/0
no cdp enablecdp run is the default, shown for completeness. Turn CDP off on the interface that faces the ISP. no cdp run would turn it off on every interface at once.
cdp timer 30
cdp holdtime 90Optional: change how often CDP is sent and how long neighbours keep the entry. Keep the holdtime longer than the timer (three times is the usual ratio).
LLDP
lldp run
interface GigabitEthernet1/0/20
lldp transmit
lldp receiveOn SW1: enable LLDP globally. Once it runs, every interface sends and receives by default; the interface lines are only needed if they were turned off before.
interface range GigabitEthernet1/0/2 - 19
no lldp transmit
no cdp enableOn user-facing access ports where no network device or phone connects, stop advertising. You can keep receiving with lldp receive if you want to see what users plug in.
lldp timer 30
lldp holdtime 120
lldp reinit 2The defaults: advertise every 30 s, hold for 120 s, and wait 2 s before restarting LLDP on an interface after it is re-enabled.
A full example: R1
! Keep CDP for the internal links, drop it toward the ISP
cdp run
lldp run
interface GigabitEthernet0/0
description WAN to ISP
no cdp enable
no lldp transmit
no lldp receiveDiscovery on the LAN side, silence on the internet side.
How to verify it
R1#show cdp neighbors Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone Device ID Local Intrfce Holdtme Capability Platform Port ID SW1 Gig 0/1 152 S I C9200L-24 Gig 1/0/24 SW2 Gig 0/2 147 S I C9200L-24 Gig 1/0/24 Total cdp entries displayed : 2
R1#show cdp neighbors detail ------------------------- Device ID: SW1 Entry address(es): IP address: 192.168.10.2 Platform: cisco C9200L-24T-4G, Capabilities: Switch IGMP Interface: GigabitEthernet0/1, Port ID (outgoing port): GigabitEthernet1/0/24 Holdtime : 138 sec Version : Cisco IOS Software [Cupertino], Catalyst L3 Switch Software (CAT9K_LITE_IOSXE), Version 17.9.4, RELEASE SOFTWARE (fc5) advertisement version: 2 Native VLAN: 1 Duplex: full Management address(es): IP address: 192.168.10.2 ------------------------- ...
show cdp entry SW1 shows the same for one neighbour.R1#show cdp Global CDP information: Sending CDP packets every 60 seconds Sending a holdtime value of 180 seconds Sending CDPv2 advertisements is enabled
show cdp interface lists which interfaces are running CDP; Gi0/0 should be missing from that list after no cdp enable.SW1#show lldp neighbors Capability codes: (R) Router, (B) Bridge, (T) Telephone, (C) DOCSIS Cable Device (W) WLAN Access Point, (P) Repeater, (S) Station, (O) Other Device ID Local Intf Hold-time Capability Port ID R1 Gi1/0/24 120 R Gi0/1 AP-FLOOR1 Gi1/0/20 120 W eth0 Total entries displayed: 2
eth0 or a MAC address.SW1#show lldp Global LLDP Information: Status: ACTIVE LLDP advertisements are sent every 30 seconds LLDP hold time advertised is 120 seconds LLDP interface reinitialisation delay is 2 seconds
% LLDP is not enabled instead. Use show lldp neighbors detail for addresses and versions, and show lldp interface for per-port settings.What goes wrong and how to troubleshoot it
- A neighbour you expect is missing. Check the link is up/up with
show ip interface brief; discovery needs a working Layer 2 link. Then check the protocol is running on both ends (show cdp interface,show lldp interface). Wait up to a full timer interval after a change. - A non-Cisco device never appears. It doesn't speak CDP. Enable LLDP with
lldp run. - An old neighbour is still listed after recabling. Its entry stays until the holdtime runs out. Clear it with
clear cdp tableorclear lldp table. - IP phones lose their voice VLAN. Cisco phones learn the voice VLAN from CDP (other phones from LLDP-MED). Disabling CDP on a phone port breaks that.
- The table shows a device you didn't expect, several hops away. A device between you that doesn't understand CDP (an unmanaged switch or a hub) floods the multicast frame on, so two Cisco devices look directly connected when they aren't.
Common mistakes
- Reading Port ID as your own port. It is the neighbour's.
- Expecting
show cdp neighborsto show IP addresses. Usedetailorshow cdp entry. - Assuming LLDP is on because CDP is. On Cisco IOS it must be enabled with
lldp run. - Using
cdp enableas a global command orcdp runon an interface.runis global,enableis per interface. - Leaving CDP on internet-facing interfaces and announcing your model and IOS version to the world.
💡 Exam tip: expect exhibits of show cdp neighbors where you must say which local port connects to which remote port, or which device is a router or switch from the capability codes. Memorise the defaults: CDP on, 60 s / 180 s; LLDP off, 30 s / 120 s; reinit 2 s. Know the commands: global [no] cdp run and [no] lldp run, per interface [no] cdp enable and [no] lldp transmit / receive. The blueprint lists both protocols under Layer 2 discovery.
Key takeaways
- CDP (Cisco) and LLDP (IEEE 802.1AB) advertise a device to its directly connected neighbours only.
- They run at Layer 2 to a multicast MAC, so they work without IP.
- CDP is on by default (60/180 s); LLDP is off by default on Cisco (30/120 s).
- Use
show cdp neighbors [detail]andshow lldp neighbors [detail]to map a network hop by hop. - Turn discovery off on interfaces facing untrusted networks; it reveals model, version and addresses.
For the other everyday verification commands, see Cisco show commands.
Check yourself
On R1, show cdp neighbors shows 'SW2 Gig 0/2 147 S I C9200L-24 Gig 1/0/24'. Which port on SW2 is the cable plugged into?
SW1 connects to a non-Cisco access point. show cdp neighbors on SW1 doesn't list it. What is the most likely fix?
R1 is connected to SW1, and SW1 to SW2. Both switches are Cisco with CDP on. Does show cdp neighbors on R1 list SW2?
You want to stop CDP only on R1's internet-facing Gi0/0 and keep it everywhere else. Which command do you use?
What are the default LLDP advertisement timer and holdtime?