Routelearn.net
Course menu

Course 1: Cisco IOSLesson 1.4 (4 of 5 in this course)4 of 91 in the CCNA series

Discovering neighbours with CDP and LLDP

Using CDP and LLDP to map a network, and when to turn them off.

Intermediate · 9 min read

CDP (Cisco Discovery Protocol) and LLDP (Link Layer Discovery Protocol) are Layer 2 neighbour discovery protocols: each device periodically advertises its identity, platform, port and addresses out of its interfaces, and directly connected devices store what they receive in a neighbour table. CDP is Cisco proprietary; LLDP is the vendor-neutral IEEE 802.1AB standard.

In simple terms: They let a device tell the device at the other end of the cable “this is who I am and which port you're plugged into.” That makes it easy to draw a map of the network without walking around tracing cables.

A real-life situation

You inherit a network with no diagram. You are logged in to R1 and need to know what is plugged into each port and which port on the other device the cable lands in. Walking to the wiring closet and tracing cables takes an afternoon. A neighbour discovery protocol answers the question in one command.

What CDP and LLDP are

A neighbour discovery protocol lets a device send a short "this is me" message out of each of its interfaces. Devices on the other end store what they hear in a neighbour table. There are two you need to know:

  • CDP (Cisco Discovery Protocol): Cisco's own protocol. Enabled by default on Cisco routers, switches, IP phones and access points.
  • LLDP (Link Layer Discovery Protocol): the open IEEE 802.1AB standard, used by every vendor. Supported on Cisco devices but disabled by default on most IOS and IOS XE platforms. A variant called LLDP-MED adds features for phones and other endpoints.

Both share information such as:

  • the neighbour's name (the Device ID, usually its hostname),
  • the neighbour's own interface the cable is plugged into (the Port ID),
  • its capabilities (router, switch, phone, access point),
  • its model (platform) and software version,
  • a management IP address, and on switches the native VLAN and duplex.
Gi0/1Gi1/0/24Gi0/2Gi1/0/24Gi0/0Gi1/0/20Gi1/0/1R1CISCO2911SW1C9200LSW2C9200LAP-FLOOR1third-party APPC1192.168.10.10ISP
  1. 1. SW1 and SW2 advertise to R1. Each switch sends a CDP message out of every port; R1 records both, with the port at each end.
  2. 2. R1 advertises back. Discovery runs in both directions, so each switch also lists R1.
  3. 3. The third-party AP speaks only LLDP. SW1 sees AP-FLOOR1 only if LLDP is enabled on SW1. CDP alone would miss it.
  4. 4. CDP toward the ISP is a leak. R1 would advertise its model and IOS version to a network you don't control. Turn CDP off on Gi0/0.
  5. 5. Only one hop. SW1 does not pass the AP's or anyone else's messages on. R1 never learns about AP-FLOOR1 or PC1.

Why it works that way

CDP and LLDP run at Layer 2. Each message is an Ethernet frame sent to a reserved multicast MAC address (CDP uses 01:00:0C:CC:CC:CC, LLDP uses 01:80:C2:00:00:0E). Because no IP is involved, discovery works even before addresses are configured or when IP is misconfigured. That is exactly when you need it most.

A device that understands the protocol keeps the frame and does not forward it. That is deliberate: the table should describe the cable you are standing at, not a device three switches away. A Cisco switch therefore never lists a device it isn't directly cabled to.

How it works step by step

Each message carries a holdtime: how long the receiver should keep the entry if it hears nothing more. The sender repeats its message on a timer well inside that holdtime, so a healthy neighbour never expires.

Step 1 of 4 · CDP advertisement
SW1
Gi1/0/24
One Ethernet link
Layer 2 only, no IP needed
R1
Gi0/1

LLDP behaves the same way with different defaults: every 30 seconds, holdtime 120 seconds.

CDPLLDP
StandardCisco proprietaryIEEE 802.1AB (open)
Default on Cisco IOSEnabledDisabled
Advertisement timer60 s30 s
Holdtime180 s120 s
Turn on/off globallycdp run / no cdp runlldp run / no lldp run
Per interfacecdp enable / no cdp enablelldp transmit and lldp receive (separately)

How to configure it on Cisco IOS

⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device.

CDP

cdp run interface GigabitEthernet0/0 no cdp enable

cdp run is the default, shown for completeness. Turn CDP off on the interface that faces the ISP. no cdp run would turn it off on every interface at once.

cdp timer 30 cdp holdtime 90

Optional: change how often CDP is sent and how long neighbours keep the entry. Keep the holdtime longer than the timer (three times is the usual ratio).

LLDP

lldp run interface GigabitEthernet1/0/20 lldp transmit lldp receive

On SW1: enable LLDP globally. Once it runs, every interface sends and receives by default; the interface lines are only needed if they were turned off before.

interface range GigabitEthernet1/0/2 - 19 no lldp transmit no cdp enable

On user-facing access ports where no network device or phone connects, stop advertising. You can keep receiving with lldp receive if you want to see what users plug in.

lldp timer 30 lldp holdtime 120 lldp reinit 2

The defaults: advertise every 30 s, hold for 120 s, and wait 2 s before restarting LLDP on an interface after it is re-enabled.

A full example: R1

! Keep CDP for the internal links, drop it toward the ISP cdp run lldp run interface GigabitEthernet0/0 description WAN to ISP no cdp enable no lldp transmit no lldp receive

Discovery on the LAN side, silence on the internet side.

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
                  S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone

Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID
SW1              Gig 0/1           152             S I    C9200L-24 Gig 1/0/24
SW2              Gig 0/2           147             S I    C9200L-24 Gig 1/0/24

Total cdp entries displayed : 2
Local Intrfce is R1's port; Port ID is the neighbour's port. Read each line as "my Gi0/1 connects to SW1's Gi1/0/24". Holdtme counts down and jumps back up with each new message. There is no IP address here; you need the detail view for that.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show cdp neighbors detail
-------------------------
Device ID: SW1
Entry address(es):
  IP address: 192.168.10.2
Platform: cisco C9200L-24T-4G,  Capabilities: Switch IGMP
Interface: GigabitEthernet0/1,  Port ID (outgoing port): GigabitEthernet1/0/24
Holdtime : 138 sec

Version :
Cisco IOS Software [Cupertino], Catalyst L3 Switch Software (CAT9K_LITE_IOSXE), Version 17.9.4, RELEASE SOFTWARE (fc5)

advertisement version: 2
Native VLAN: 1
Duplex: full
Management address(es):
  IP address: 192.168.10.2
-------------------------
...
The detail view adds the neighbour's IP address (so you can SSH to it next) and its exact software version. That version line is precisely what an attacker would want to see. show cdp entry SW1 shows the same for one neighbour.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show cdp
Global CDP information:
        Sending CDP packets every 60 seconds
        Sending a holdtime value of 180 seconds
        Sending CDPv2 advertisements is  enabled
The global timers. show cdp interface lists which interfaces are running CDP; Gi0/0 should be missing from that list after no cdp enable.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show lldp neighbors
Capability codes:
    (R) Router, (B) Bridge, (T) Telephone, (C) DOCSIS Cable Device
    (W) WLAN Access Point, (P) Repeater, (S) Station, (O) Other

Device ID           Local Intf     Hold-time  Capability      Port ID
R1                  Gi1/0/24       120        R               Gi0/1
AP-FLOOR1           Gi1/0/20       120        W               eth0

Total entries displayed: 2
The same idea in LLDP's format. A switch shows up as B (bridge) in LLDP. The third-party access point appears here even though it doesn't speak CDP. Port IDs are whatever the neighbour reports, so a non-Cisco device may show a name like eth0 or a MAC address.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show lldp
Global LLDP Information:
    Status: ACTIVE
    LLDP advertisements are sent every 30 seconds
    LLDP hold time advertised is 120 seconds
    LLDP interface reinitialisation delay is 2 seconds
If LLDP is off you see % LLDP is not enabled instead. Use show lldp neighbors detail for addresses and versions, and show lldp interface for per-port settings.

What goes wrong and how to troubleshoot it

  • A neighbour you expect is missing. Check the link is up/up with show ip interface brief; discovery needs a working Layer 2 link. Then check the protocol is running on both ends (show cdp interface, show lldp interface). Wait up to a full timer interval after a change.
  • A non-Cisco device never appears. It doesn't speak CDP. Enable LLDP with lldp run.
  • An old neighbour is still listed after recabling. Its entry stays until the holdtime runs out. Clear it with clear cdp table or clear lldp table.
  • IP phones lose their voice VLAN. Cisco phones learn the voice VLAN from CDP (other phones from LLDP-MED). Disabling CDP on a phone port breaks that.
  • The table shows a device you didn't expect, several hops away. A device between you that doesn't understand CDP (an unmanaged switch or a hub) floods the multicast frame on, so two Cisco devices look directly connected when they aren't.

Common mistakes

  • Reading Port ID as your own port. It is the neighbour's.
  • Expecting show cdp neighbors to show IP addresses. Use detail or show cdp entry.
  • Assuming LLDP is on because CDP is. On Cisco IOS it must be enabled with lldp run.
  • Using cdp enable as a global command or cdp run on an interface. run is global, enable is per interface.
  • Leaving CDP on internet-facing interfaces and announcing your model and IOS version to the world.

💡 Exam tip: expect exhibits of show cdp neighbors where you must say which local port connects to which remote port, or which device is a router or switch from the capability codes. Memorise the defaults: CDP on, 60 s / 180 s; LLDP off, 30 s / 120 s; reinit 2 s. Know the commands: global [no] cdp run and [no] lldp run, per interface [no] cdp enable and [no] lldp transmit / receive. The blueprint lists both protocols under Layer 2 discovery.

Key takeaways

  • CDP (Cisco) and LLDP (IEEE 802.1AB) advertise a device to its directly connected neighbours only.
  • They run at Layer 2 to a multicast MAC, so they work without IP.
  • CDP is on by default (60/180 s); LLDP is off by default on Cisco (30/120 s).
  • Use show cdp neighbors [detail] and show lldp neighbors [detail] to map a network hop by hop.
  • Turn discovery off on interfaces facing untrusted networks; it reveals model, version and addresses.

For the other everyday verification commands, see Cisco show commands.

Check yourself

Predict · scenario 1

On R1, show cdp neighbors shows 'SW2 Gig 0/2 147 S I C9200L-24 Gig 1/0/24'. Which port on SW2 is the cable plugged into?

Predict · scenario 2

SW1 connects to a non-Cisco access point. show cdp neighbors on SW1 doesn't list it. What is the most likely fix?

Predict · scenario 3

R1 is connected to SW1, and SW1 to SW2. Both switches are Cisco with CDP on. Does show cdp neighbors on R1 list SW2?

Predict · scenario 4

You want to stop CDP only on R1's internet-facing Gi0/0 and keep it everywhere else. Which command do you use?

Predict · scenario 5

What are the default LLDP advertisement timer and holdtime?

FAQ

What is the difference between CDP and LLDP?
Both let a device tell its directly connected neighbours who it is. CDP (Cisco Discovery Protocol) is Cisco's own protocol and is enabled by default on Cisco devices. LLDP (Link Layer Discovery Protocol, IEEE 802.1AB) is the open standard that every vendor supports, but it is disabled by default on most Cisco IOS devices. CDP sends every 60 seconds with a 180-second holdtime; LLDP every 30 seconds with a 120-second holdtime.
Can CDP see devices two hops away?
No. A Cisco device receives CDP messages and does not forward them, so you only ever see devices on the other end of your own links. To map a bigger network you log in to each neighbour in turn and run show cdp neighbors there.
Do CDP and LLDP need IP addresses to work?
No. They are Layer 2 protocols sent in Ethernet frames to a multicast MAC address. They work as long as the link is up at Layer 2, which makes them useful for finding out what is connected before IP is configured, or when IP is broken.
Should I disable CDP?
Disable it on interfaces facing networks you don't control, such as an internet link or ports where untrusted users connect. It advertises the device name, model, software version and addresses, which is useful to an attacker. Keep it on internal links between your own devices, and on ports with Cisco IP phones that rely on it.