Skip to main content
PacketMentor logo
Open menu
← All topics
Network Access Foundational

CDP & LLDP: Neighbor Discovery

How devices discover directly connected neighbors. CDP is Cisco-proprietary, LLDP is the vendor-neutral standard, and both share identity, model, IOS and port.

Quick summary
  • CDP and LLDP are Layer-2 protocols where every device announces itself to its directly-connected neighbors.
  • CDP is Cisco-only. LLDP is the IEEE standard (802.1AB), multi-vendor.
  • Useful: instantly map who's connected where. Risk: leaks device model + IOS version to anyone on the LAN. Disable on user-facing ports.
CDP / LLDP · neighbors announce themselvesSW1Cat 9300 · 17.6R1ISR4331 · 17.9CDP ad every 60sCDP ad every 60sNeighbor info learned (each side):Device ID · IP · platform · IOS · port-id · capabilitiese.g. "R1, 10.0.0.2, ISR4331, 17.9, Gi0/0, Router"
Every directly-connected Cisco device shouts about itself periodically. Each neighbor records who's on every port, invaluable for troubleshooting.

Mental model

You walk into a new network. You SSH into one switch. You don’t know what’s connected to which port. CDP / LLDP solves that. Every neighbor introduces itself, periodically and unsolicited.

A Cisco switch broadcasts a multicast frame every 60 seconds saying “I’m SW1, a Catalyst 9300, IOS 17.6, my Gi0/24 is on this wire.” Every neighbor records it. You run show cdp neighbors and see a table of who’s on every port, model, IOS version, IP, peer’s port number.

That’s the entire concept. Different name (CDP / LLDP / FDP for Foundry / EDP for Extreme), same idea.

CDP vs LLDP

CDPLLDP
OriginCisco-proprietaryIEEE 802.1AB (industry standard)
Default state on CiscoEnabled globally + per interfaceDisabled globally; needs enabling
CarriesDevice ID, platform, capabilities, IP, IOS, native VLAN, port-ID, duplexSame kind of info
Hello interval60s (default)30s (default)
Hold time180s (3× hello)120s (4× hello)
Best whenPure Cisco environmentsMulti-vendor environments

Most production networks run both. CDP works between Cisco devices. LLDP fills in for non-Cisco gear (printers, IP cameras, Aruba APs, anything not made by Cisco).

Commands

CDP

SW1# show cdp neighbors                ! one-line per neighbor (most useful)
SW1# show cdp neighbors detail         ! verbose: IOS version, IP address
SW1# show cdp interface                ! which interfaces have CDP active
SW1# show cdp entry R1                 ! deep info about one specific neighbor

! Globally enable / disable
SW1(config)# cdp run                   ! default on Cisco: keep it
SW1(config)# no cdp run                ! turn off entirely

! Per-interface
SW1(config-if)# cdp enable
SW1(config-if)# no cdp enable          ! disable on this port only

LLDP

SW1# show lldp neighbors
SW1# show lldp neighbors detail
SW1# show lldp                          ! global status

! Enable globally (Cisco IOS default is OFF for LLDP)
SW1(config)# lldp run

! Per-interface: direction matters!
SW1(config-if)# lldp transmit          ! send LLDP
SW1(config-if)# lldp receive           ! accept incoming LLDP
SW1(config-if)# no lldp transmit       ! mute outbound

LLDP separates transmit and receive, useful for “listen but don’t reveal” scenarios.

Sample output: what you’ll see

SW1# show cdp neighbors
Device ID    Local Intrfce     Holdtme    Capability  Platform     Port ID
R1.corp      Gig 0/24          168        R           ISR4331      Gig 0/0
SW2.corp     Gig 0/23          151        S           WS-C2960-48  Gig 0/1
AP-12.corp   Gig 0/15          122        T           AIR-AP3802   Gig 0

In 5 seconds you know: R1 is a router on Gi0/24, SW2 is a switch on Gi0/23, and AP-12 is an access point on Gi0/15.

Security implications

CDP / LLDP leaks information. Any device on the LAN running tcpdump can read:

  • Device hostname → guess at naming convention
  • Platform → “Cisco 9300, IOS 17.6, what vulnerabilities affect that version?”
  • Native VLAN ID → VLAN hopping attack hint
  • Power consumption, duplex, port-ID: info that helps an attacker map the network

The fix: disable on user-facing ports. Keep enabled on inter-switch / inter-router trunks where you actually need it.

SW1(config)# interface range GigabitEthernet0/1 - 23      ! access ports
SW1(config-if-range)# no cdp enable
SW1(config-if-range)# no lldp transmit
SW1(config-if-range)# no lldp receive

Then leave it on for uplinks where adjacent devices need to discover each other.

Voice VLANs and CDP

A specific case where you can’t simply disable CDP: Cisco IP phones use CDP to learn their voice VLAN ID from the switch automatically.

SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10        ! data VLAN
SW1(config-if)# switchport voice vlan 100        ! voice VLAN
SW1(config-if)# cdp enable                        ! phone needs this

The phone sends CDP toward the switch, asking “what’s my voice VLAN?” The switch replies with VLAN 100. The phone tags voice traffic accordingly. Without CDP, manual phone config is needed.

LLDP-MED (Media Endpoint Discovery) is the multi-vendor equivalent, and modern IP phones support it. Polycom, Yealink, and modern Cisco phones use LLDP-MED.

Related reading: for a side by side of when to use each protocol, see CDP vs LLDP.

Checking your documentation with CDP and LLDP (CCNA v2.0 2.3)

Diagrams go stale: someone moves a cable or swaps a switch and the drawing never changes. CDP and LLDP let you audit it from the CLI, one link at a time.

Log in to one device, run show cdp neighbors, and check four columns for every row:

  • Device ID: the neighbor’s hostname. Compare it with the name on the diagram.
  • Local Intrfce: the port on the device you’re logged in to.
  • Port ID: the port on the neighbor, the remote end. Mixing up these two columns is the easiest way to “correct” a diagram into something wrong.
  • Platform: the neighbor’s model number. If it doesn’t match the diagram, hardware was swapped.

show cdp neighbors detail adds the neighbor’s IP address, software version, native VLAN and duplex. Use it to check the addressing on the diagram too.

For non-Cisco gear, run show lldp neighbors detail (LLDP is off by default on Catalyst, so lldp run first). The fields map across: Local Intf is your port, Port id is theirs, System Name is the hostname, and Management Addresses gives the IP.

CDP also compares the native VLAN on both ends of a link and logs a mismatch:

%CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on GigabitEthernet1/0/1 (1), with SW2 GigabitEthernet1/0/24 (99).

The number in parentheses is each side’s native VLAN: 1 locally, 99 on SW2.

Diagram vs reality

Diagram saysCDP saysWhat to fix
SW1 Gi1/0/1 to SW2 Gi1/0/1Local Gi1/0/1, Port ID Gi1/0/24The diagram: the remote port is Gi1/0/24
SW1 Gi1/0/2 to R1Device ID R2 on Gi1/0/2Confirm which router is really cabled, then fix the patching or the drawing
SW2 is a 2960Platform shows a Catalyst 9300 modelHardware label and inventory
Native VLAN 99 on both trunk endsNATIVE_VLAN_MISMATCH, 1 vs 99switchport trunk native vlan 99 on the side still using VLAN 1
Link to a non-Cisco switchNo entryNothing yet: check show lldp neighbors detail
Link drawn, protocol enabled on both endsNo entry in CDP or LLDPCheck that the link is up/up and the cable goes where you think

Know the limits

CDP and LLDP only show directly connected neighbors that run the same protocol. A device two hops away never appears; log in to the next device and repeat the walk. Non-Cisco devices don’t speak CDP, so they only show up through LLDP, and only when LLDP is enabled on both ends. An access port where you disabled CDP and LLDP for security (see above) shows nothing, which is expected and not a missing cable.

Common mistakes

  1. Leaving CDP on every port. Security risk on user-facing ports. Disable on access ports unless they connect to IP phones / APs / specific devices that need it.

  2. Disabling CDP everywhere. Now you’ve lost a key troubleshooting tool. Targeted disable, not global.

  3. Forgetting LLDP is off by default on Cisco. You add a third-party device, can’t see it in CDP. Solution: turn on LLDP globally.

  4. Trusting CDP/LLDP info as authoritative. It’s whatever the neighbor claims to be. Spoofable. Use as a hint, not a source of truth for ACLs / security policies.

  5. Voice VLAN doesn’t work after CDP disable. Forgot the phone uses CDP. Re-enable on phone ports.

  6. Confusing CDP frame multicast address. CDP uses 01:00:0c:cc:cc:cc. LLDP uses 01:80:c2:00:00:0e. Both reach all bridges that support the protocol on the segment.

Lab to try tonight

  1. Two Cisco devices connected by a single cable.
  2. Wait ~2 minutes after boot. Run show cdp neighbors on each side. Verify each shows the other.
  3. Run show cdp neighbors detail: note all the info disclosed (IOS, IP, native VLAN, etc.).
  4. Capture with Wireshark on a span port: filter cdp. See the periodic CDP frames every 60 seconds.
  5. Enable LLDP globally on both: lldp run. Re-verify with show lldp neighbors.
  6. Disable CDP on one interface: no cdp enable. Re-check after the 180s holdtime: the neighbor no longer lists this device, and this device no longer lists the neighbor on that port.
  7. Bonus: connect a third-party device (any non-Cisco router/switch). Try CDP: doesn’t work. Try LLDP: works.

Cheat strip

ConceptPlain English
CDPCisco-proprietary discovery. Default on.
LLDPIEEE 802.1AB. Vendor-neutral. Default off on Cisco.
Hello intervalCDP 60s, LLDP 30s
show cdp neighborsDaily-driver troubleshooting command
detailAdds IOS version, IP, native VLAN: more useful, more leakage
Security riskLeaks platform/version info: disable on user ports
Voice VLANCisco IP phones use CDP. Keep CDP on phone ports.
LLDP-MEDMulti-vendor voice equivalent
Multicast MACsCDP 01:00:0c:cc:cc:cc · LLDP 01:80:c2:00:00:0e

Frequently asked questions

Q: Should I disable CDP for security? A: On ports facing users or the internet: yes (no cdp enable on the interface). CDP announces device type, IOS version, IP addresses, and platform: great intel for an attacker. On switch-to-switch trunks: leave it on because it powers PoE negotiation, VoIP phone discovery, and network topology tooling. Best practice: no cdp run globally then re-enable per-interface where needed, or leave global on and disable per-interface for user ports.

Q: What’s the difference between CDP and LLDP? A: CDP is Cisco proprietary (also on some Cisco-aligned vendors like Meraki). LLDP (802.1AB) is the IEEE standard, works between Cisco, Juniper, Arista, HP, etc. Both send similar info (neighbor name, port, VLAN), but on different default timers: CDP every 60s, LLDP every 30s. In a mixed-vendor environment, enable both: CDP for Cisco-to-Cisco, LLDP for cross-vendor.

Q: What are the default CDP timers? A: Send every 60 seconds, hold time 180 seconds (3× the send interval). Change with cdp timer <seconds> and cdp holdtime <seconds>. In stable networks, defaults are fine. Only tune down for faster failure detection, and if you’re doing that for redundancy, you’d rather use a routing protocol’s own hellos.

Q: Why does LLDP-MED matter for VoIP phones? A: LLDP-MED (Media Endpoint Discovery) is the extension that lets a Cisco IP phone learn its voice VLAN, power budget (PoE class), and QoS settings automatically from the switch. Without it, you’d manually configure the phone. With it, plug the phone in and it comes up in the right VLAN with the right power, zero-touch deployment. Enable with lldp med-tlv-select on access ports.

Q: Where is CDP information stored? A: In the CDP neighbor table, refreshed by incoming CDP announcements. View with show cdp neighbors (brief) or show cdp neighbors detail (full, including IP addresses and IOS versions). Entries age out after the hold time (180s default). Empty output means either CDP is disabled, the neighbor isn’t Cisco, or the link is broken.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on CDP & LLDP: Neighbor Discovery. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where CDP & LLDP: Neighbor Discovery fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.