Guided buildstarter5 steps~12 min3 devices
Map the network with CDP and LLDP
Let two switches and a router discover each other, find the router's address from a switch that was never told it, add LLDP, then stop the router announcing itself toward the internet.
What you'll be able to do: A small network you can map from any console: which device sits on which port, what it is and what address it answers on — found with neighbour tables instead of documentation, and with discovery kept off the one port that faces strangers.
Topics: CDP/LLDP · Switching · Network security
What you'll build
- R-Edge — a router, the edge router, whose address nobody wrote down
- SW-Core — a switch, the core switch the router plugs into
- SW-Access — a switch, the closet switch, one hop further out
Step by step
1. Two switches, one cable — and CDP is already talking
Drag two switches onto the canvas, name them SW-Core and SW-Access, and cable SW-Access's Gi0/1 to SW-Core's Gi0/2. You configure nothing else: run `show cdp neighbors` on SW-Core and SW-Access is already there — its name, the port it is on at your end, its platform, and its own port at the far end.
- Cable SW-Access Gi0/1 ↔ SW-Core Gi0/2
On SW-Core — Name the core switch
enable configure terminal hostname SW-Core endOn SW-Access — Name the closet switch
enable configure terminal hostname SW-Access endCheck: run
show cdp neighborson SW-Core and look forSW-Access Gi0/2 180 S NF-SWITCH Gi0/1.Why: CDP is a layer 2 advertisement that every device on this CLI sends out of every up port by default — every 60 seconds, with a 180-second holdtime telling the receiver how long to trust each entry. Nothing has to be configured for two directly cabled devices to learn each other's name, platform and ports.
2. Add the router — invisible until its port is up
Drag a router in, name it R-Edge, and cable its Gi0/0 to SW-Core's Gi0/1. Look at SW-Core's neighbour table: no router. A router's ports ship shut, and a shut port sends nothing — CDP included. Give Gi0/0 192.168.1.1/24 and bring it up, and R-Edge appears on SW-Core within the same breath.
- Cable R-Edge Gi0/0 ↔ SW-Core Gi0/1
On R-Edge — Name the router
enable configure terminal hostname R-Edge endOn SW-Core — Look for the router — it is not there yet
enable show cdp neighborsOn R-Edge — Address the router's LAN port and bring it up
enable configure terminal interface Gi0/0 ip address 192.168.1.1 255.255.255.0 no shutdown endCheck: run
show cdp neighborson SW-Core and look forR-Edge Gi0/1 180 R NF-ROUTER Gi0/0.Why: Neighbour discovery rides on a working link. A cable drawn into an administratively down port carries nothing, so the device behind it is invisible to CDP — which makes the neighbour table a quick test of whether a link is really up, not just plugged in.
3. Find the router's address from a switch that can see it
Stand at SW-Access, the closet switch, with no documentation. `show cdp neighbors` lists SW-Core — and only SW-Core: the router is invisible from here. So hop one switch closer and ask SW-Core with `show cdp neighbors detail`: the R-Edge entry carries its address, 192.168.1.1. Now give SW-Access a management address in VLAN 1 and point its default gateway at the router you just found.
On SW-Access — From the closet switch, only SW-Core is visible
enable show cdp neighborsOn SW-Core — Ask the switch that can see the router for its address
enable show cdp neighbors detailOn SW-Access — Give the closet switch a management address and the router as its gateway
enable configure terminal interface vlan 1 ip address 192.168.1.3 255.255.255.0 no shutdown exit ip default-gateway 192.168.1.1 end ping 192.168.1.1Check: run
show cdp neighbors detailon SW-Core and look forIP address: 192.168.1.1.Why: CDP frames are never forwarded: each device hears only the devices on the other ends of its own cables. You map a network by hopping from neighbour to neighbour, and `detail` adds what each neighbour answers on — the fastest way to find a gateway nobody wrote down.
4. LLDP: the open standard, off until you turn it on
Try `show lldp neighbors` on SW-Core first: "% LLDP is not enabled". Turn it on with `lldp run` on both switches. SW-Core now lists SW-Access in its LLDP table — and not R-Edge, which is still visible over CDP. The router never ran LLDP, and a neighbour only shows up when both ends speak the protocol.
On SW-Core — Turn LLDP on for the core switch
enable configure terminal lldp run endOn SW-Access — Turn LLDP on for the closet switch
enable configure terminal lldp run endCheck: run
show lldp neighborson SW-Core and look forSW-Access Gi0/2.Why: CDP belongs to one family of devices; LLDP (IEEE 802.1AB) is the vendor-neutral version every brand of switch, phone and access point can speak. The two run side by side and independently — on this CLI CDP starts on and LLDP starts off.
5. Stop announcing the router to the internet
R-Edge's Gi0/1 will be cabled to the internet provider. CDP would tell whatever is on the far end the router's name, platform and addresses, so turn it off on that one port before it is ever plugged in, and label the port while you are there. CDP stays on everywhere else, where your own team relies on it.
On R-Edge — Label the internet-facing port and keep CDP off it
enable configure terminal interface Gi0/1 description TO-ISP no cdp enable endCheck: run
show running-configon R-Edge and look forno cdp enable.Why: Discovery protocols help a troubleshooter and an attacker equally: they announce model, software and addresses in clear text to anyone plugged into the port. Keep them on the links you own and off every port that faces a network you don't.
The theory behind it
More in Switching & wireless
- Two departments, one switch — Split a single switch into Sales and Ops with VLANs, and watch the pings between them stop.
- One VLAN across two switches — Split four PCs into two VLANs across two switches, then carry both VLANs between the switches over a single tagged trunk.
- Router on a stick — Split one switch into two VLANs and route between them over a single router port.
- Route between VLANs on the switch — Give one switch an SVI in each VLAN, find out why the VLANs still can't talk, then turn on ip routing — inter-VLAN routing with no router at all.
- Choose your root bridge — Close a loop of three switches, find the port spanning tree blocks on its own, then decide which switch is root — and which one takes over when it fails.
- Two cables, one logical link — Add a second uplink between two switches, watch spanning tree block it, then bundle both into an LACP EtherChannel so they carry traffic together.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab