CDP & LLDP: Neighbor Discovery
How devices discover directly connected neighbors. CDP is Cisco-proprietary, LLDP is the vendor-neutral standard, and both share identity, model, IOS and port.
- CDP and LLDP are Layer-2 protocols where every device announces itself to its directly-connected neighbors.
- CDP is Cisco-only. LLDP is the IEEE standard (802.1AB), multi-vendor.
- Useful: instantly map who's connected where. Risk: leaks device model + IOS version to anyone on the LAN. Disable on user-facing ports.
Mental model
You walk into a new network. You SSH into one switch. You don’t know what’s connected to which port. CDP / LLDP solves that. Every neighbor introduces itself, periodically and unsolicited.
A Cisco switch broadcasts a multicast frame every 60 seconds saying “I’m SW1, a Catalyst 9300, IOS 17.6, my Gi0/24 is on this wire.” Every neighbor records it. You run show cdp neighbors and see a table of who’s on every port, model, IOS version, IP, peer’s port number.
That’s the entire concept. Different name (CDP / LLDP / FDP for Foundry / EDP for Extreme), same idea.
CDP vs LLDP
| CDP | LLDP | |
|---|---|---|
| Origin | Cisco-proprietary | IEEE 802.1AB (industry standard) |
| Default state on Cisco | Enabled globally + per interface | Disabled globally; needs enabling |
| Carries | Device ID, platform, capabilities, IP, IOS, native VLAN, port-ID, duplex | Same kind of info |
| Hello interval | 60s (default) | 30s (default) |
| Hold time | 180s (3× hello) | 120s (4× hello) |
| Best when | Pure Cisco environments | Multi-vendor environments |
Most production networks run both. CDP works between Cisco devices. LLDP fills in for non-Cisco gear (printers, IP cameras, Aruba APs, anything not made by Cisco).
Commands
CDP
SW1# show cdp neighbors ! one-line per neighbor (most useful)
SW1# show cdp neighbors detail ! verbose: IOS version, IP address
SW1# show cdp interface ! which interfaces have CDP active
SW1# show cdp entry R1 ! deep info about one specific neighbor
! Globally enable / disable
SW1(config)# cdp run ! default on Cisco: keep it
SW1(config)# no cdp run ! turn off entirely
! Per-interface
SW1(config-if)# cdp enable
SW1(config-if)# no cdp enable ! disable on this port only
LLDP
SW1# show lldp neighbors
SW1# show lldp neighbors detail
SW1# show lldp ! global status
! Enable globally (Cisco IOS default is OFF for LLDP)
SW1(config)# lldp run
! Per-interface: direction matters!
SW1(config-if)# lldp transmit ! send LLDP
SW1(config-if)# lldp receive ! accept incoming LLDP
SW1(config-if)# no lldp transmit ! mute outbound
LLDP separates transmit and receive, useful for “listen but don’t reveal” scenarios.
Sample output: what you’ll see
SW1# show cdp neighbors
Device ID Local Intrfce Holdtme Capability Platform Port ID
R1.corp Gig 0/24 168 R ISR4331 Gig 0/0
SW2.corp Gig 0/23 151 S WS-C2960-48 Gig 0/1
AP-12.corp Gig 0/15 122 T AIR-AP3802 Gig 0
In 5 seconds you know: R1 is a router on Gi0/24, SW2 is a switch on Gi0/23, and AP-12 is an access point on Gi0/15.
Security implications
CDP / LLDP leaks information. Any device on the LAN running tcpdump can read:
- Device hostname → guess at naming convention
- Platform → “Cisco 9300, IOS 17.6, what vulnerabilities affect that version?”
- Native VLAN ID → VLAN hopping attack hint
- Power consumption, duplex, port-ID: info that helps an attacker map the network
The fix: disable on user-facing ports. Keep enabled on inter-switch / inter-router trunks where you actually need it.
SW1(config)# interface range GigabitEthernet0/1 - 23 ! access ports
SW1(config-if-range)# no cdp enable
SW1(config-if-range)# no lldp transmit
SW1(config-if-range)# no lldp receive
Then leave it on for uplinks where adjacent devices need to discover each other.
Voice VLANs and CDP
A specific case where you can’t simply disable CDP: Cisco IP phones use CDP to learn their voice VLAN ID from the switch automatically.
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10 ! data VLAN
SW1(config-if)# switchport voice vlan 100 ! voice VLAN
SW1(config-if)# cdp enable ! phone needs this
The phone sends CDP toward the switch, asking “what’s my voice VLAN?” The switch replies with VLAN 100. The phone tags voice traffic accordingly. Without CDP, manual phone config is needed.
LLDP-MED (Media Endpoint Discovery) is the multi-vendor equivalent, and modern IP phones support it. Polycom, Yealink, and modern Cisco phones use LLDP-MED.
Related reading: for a side by side of when to use each protocol, see CDP vs LLDP.
Checking your documentation with CDP and LLDP (CCNA v2.0 2.3)
Diagrams go stale: someone moves a cable or swaps a switch and the drawing never changes. CDP and LLDP let you audit it from the CLI, one link at a time.
Walk the diagram link by link
Log in to one device, run show cdp neighbors, and check four columns for every row:
- Device ID: the neighbor’s hostname. Compare it with the name on the diagram.
- Local Intrfce: the port on the device you’re logged in to.
- Port ID: the port on the neighbor, the remote end. Mixing up these two columns is the easiest way to “correct” a diagram into something wrong.
- Platform: the neighbor’s model number. If it doesn’t match the diagram, hardware was swapped.
show cdp neighbors detail adds the neighbor’s IP address, software version, native VLAN and duplex. Use it to check the addressing on the diagram too.
For non-Cisco gear, run show lldp neighbors detail (LLDP is off by default on Catalyst, so lldp run first). The fields map across: Local Intf is your port, Port id is theirs, System Name is the hostname, and Management Addresses gives the IP.
CDP also compares the native VLAN on both ends of a link and logs a mismatch:
%CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on GigabitEthernet1/0/1 (1), with SW2 GigabitEthernet1/0/24 (99).
The number in parentheses is each side’s native VLAN: 1 locally, 99 on SW2.
Diagram vs reality
| Diagram says | CDP says | What to fix |
|---|---|---|
| SW1 Gi1/0/1 to SW2 Gi1/0/1 | Local Gi1/0/1, Port ID Gi1/0/24 | The diagram: the remote port is Gi1/0/24 |
| SW1 Gi1/0/2 to R1 | Device ID R2 on Gi1/0/2 | Confirm which router is really cabled, then fix the patching or the drawing |
| SW2 is a 2960 | Platform shows a Catalyst 9300 model | Hardware label and inventory |
| Native VLAN 99 on both trunk ends | NATIVE_VLAN_MISMATCH, 1 vs 99 | switchport trunk native vlan 99 on the side still using VLAN 1 |
| Link to a non-Cisco switch | No entry | Nothing yet: check show lldp neighbors detail |
| Link drawn, protocol enabled on both ends | No entry in CDP or LLDP | Check that the link is up/up and the cable goes where you think |
Know the limits
CDP and LLDP only show directly connected neighbors that run the same protocol. A device two hops away never appears; log in to the next device and repeat the walk. Non-Cisco devices don’t speak CDP, so they only show up through LLDP, and only when LLDP is enabled on both ends. An access port where you disabled CDP and LLDP for security (see above) shows nothing, which is expected and not a missing cable.
Common mistakes
Leaving CDP on every port. Security risk on user-facing ports. Disable on access ports unless they connect to IP phones / APs / specific devices that need it.
Disabling CDP everywhere. Now you’ve lost a key troubleshooting tool. Targeted disable, not global.
Forgetting LLDP is off by default on Cisco. You add a third-party device, can’t see it in CDP. Solution: turn on LLDP globally.
Trusting CDP/LLDP info as authoritative. It’s whatever the neighbor claims to be. Spoofable. Use as a hint, not a source of truth for ACLs / security policies.
Voice VLAN doesn’t work after CDP disable. Forgot the phone uses CDP. Re-enable on phone ports.
Confusing CDP frame multicast address. CDP uses
01:00:0c:cc:cc:cc. LLDP uses01:80:c2:00:00:0e. Both reach all bridges that support the protocol on the segment.
Lab to try tonight
- Two Cisco devices connected by a single cable.
- Wait ~2 minutes after boot. Run
show cdp neighborson each side. Verify each shows the other. - Run
show cdp neighbors detail: note all the info disclosed (IOS, IP, native VLAN, etc.). - Capture with Wireshark on a span port: filter
cdp. See the periodic CDP frames every 60 seconds. - Enable LLDP globally on both:
lldp run. Re-verify withshow lldp neighbors. - Disable CDP on one interface:
no cdp enable. Re-check after the 180s holdtime: the neighbor no longer lists this device, and this device no longer lists the neighbor on that port. - Bonus: connect a third-party device (any non-Cisco router/switch). Try CDP: doesn’t work. Try LLDP: works.
Cheat strip
| Concept | Plain English |
|---|---|
| CDP | Cisco-proprietary discovery. Default on. |
| LLDP | IEEE 802.1AB. Vendor-neutral. Default off on Cisco. |
| Hello interval | CDP 60s, LLDP 30s |
show cdp neighbors | Daily-driver troubleshooting command |
detail | Adds IOS version, IP, native VLAN: more useful, more leakage |
| Security risk | Leaks platform/version info: disable on user ports |
| Voice VLAN | Cisco IP phones use CDP. Keep CDP on phone ports. |
| LLDP-MED | Multi-vendor voice equivalent |
| Multicast MACs | CDP 01:00:0c:cc:cc:cc · LLDP 01:80:c2:00:00:0e |
Frequently asked questions
Q: Should I disable CDP for security? A: On ports facing users or the internet: yes (no cdp enable on the interface). CDP announces device type, IOS version, IP addresses, and platform: great intel for an attacker. On switch-to-switch trunks: leave it on because it powers PoE negotiation, VoIP phone discovery, and network topology tooling. Best practice: no cdp run globally then re-enable per-interface where needed, or leave global on and disable per-interface for user ports.
Q: What’s the difference between CDP and LLDP? A: CDP is Cisco proprietary (also on some Cisco-aligned vendors like Meraki). LLDP (802.1AB) is the IEEE standard, works between Cisco, Juniper, Arista, HP, etc. Both send similar info (neighbor name, port, VLAN), but on different default timers: CDP every 60s, LLDP every 30s. In a mixed-vendor environment, enable both: CDP for Cisco-to-Cisco, LLDP for cross-vendor.
Q: What are the default CDP timers? A: Send every 60 seconds, hold time 180 seconds (3× the send interval). Change with cdp timer <seconds> and cdp holdtime <seconds>. In stable networks, defaults are fine. Only tune down for faster failure detection, and if you’re doing that for redundancy, you’d rather use a routing protocol’s own hellos.
Q: Why does LLDP-MED matter for VoIP phones? A: LLDP-MED (Media Endpoint Discovery) is the extension that lets a Cisco IP phone learn its voice VLAN, power budget (PoE class), and QoS settings automatically from the switch. Without it, you’d manually configure the phone. With it, plug the phone in and it comes up in the right VLAN with the right power, zero-touch deployment. Enable with lldp med-tlv-select on access ports.
Q: Where is CDP information stored? A: In the CDP neighbor table, refreshed by incoming CDP announcements. View with show cdp neighbors (brief) or show cdp neighbors detail (full, including IP addresses and IOS versions). Entries age out after the hold time (180s default). Empty output means either CDP is disabled, the neighbor isn’t Cisco, or the link is broken.
Switching Operation
How a switch actually decides where to forward each frame. Covers source-MAC learning, destination-MAC lookup, the three outcomes (forward / flood / drop), and store-and-forward vs cut-through.
Static Routing
CCNA static routing guide: next-hop vs exit-interface routes, default, floating and summary routes, recursive lookup, IPv6 statics and 8 worked scenarios.
Want this drilled into reflex?
1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA® exam blueprint. Free first session. No card on file until you decide.
Related topics
Spanning Tree Protocol (STP)
CCNA STP guide: why loops are catastrophic, root election, port roles and states, BPDUs, PortFast, BPDU Guard, Root Guard, Loop Guard, RSTP and MSTP.
Network AccessSwitching Operation
How a switch actually decides where to forward each frame. Covers source-MAC learning, destination-MAC lookup, the three outcomes (forward / flood / drop), and store-and-forward vs cut-through.
Network AccessVLANs
CCNA VLAN guide: broadcast domains, access vs trunk ports, 802.1Q tagging, native and voice VLANs, VTP, a 6-step trunk debug, security pitfalls and 7 scenarios.
Get the free CCNA 12-week roadmap
You're already reading up on CDP & LLDP: Neighbor Discovery. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where CDP & LLDP: Neighbor Discovery fits. A written personal reply, not an autoresponder. Expect it within one business day.
Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.
