cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3893
Views
0
Helpful
4
Replies

CDP Vulnerability

londint
Level 1
Level 1

We need to trace all the switches and routers connection in the office and will require the protocol cdp enabled.

Please what are the advantages/disadvantages and Vulnerability of enabling this protocol?

What is the best practice?

Thanks

1 Accepted Solution
4 Replies 4

n.bowbridge
Level 1
Level 1

Best practice is disable CDP on any interfaces accessible from outside your network.

CDP can be used by intruders to determine:

Device type

IOS version

IP address

And more....

With this information in hand a network can be compromised quite easily, especially if out-dated IOS versions are being used.

HTH

Thanks

Is there any documentation I can read further on this as I need to convince my boss.

Thanks

You can disable cdp globally using no cdp run

or disable cdp on certain interfaces

config t

int x/x

no cdp enable

this way you can turn it off with points which might have external network connections such as border routers.

HTH

Peter