All guided builds

Guided buildstarter5 steps~12 min3 devices

Map the network with CDP and LLDP

Let two switches and a router discover each other, find the router's address from a switch that was never told it, add LLDP, then stop the router announcing itself toward the internet.

What you'll be able to do: A small network you can map from any console: which device sits on which port, what it is and what address it answers on — found with neighbour tables instead of documentation, and with discovery kept off the one port that faces strangers.

Topics: CDP/LLDP · Switching · Network security

What you'll build

Step by step

  1. 1. Two switches, one cable — and CDP is already talking

    Drag two switches onto the canvas, name them SW-Core and SW-Access, and cable SW-Access's Gi0/1 to SW-Core's Gi0/2. You configure nothing else: run `show cdp neighbors` on SW-Core and SW-Access is already there — its name, the port it is on at your end, its platform, and its own port at the far end.

    • Cable SW-Access Gi0/1 ↔ SW-Core Gi0/2

    On SW-Core — Name the core switch

    enable
    configure terminal
    hostname SW-Core
    end

    On SW-Access — Name the closet switch

    enable
    configure terminal
    hostname SW-Access
    end

    Check: run show cdp neighbors on SW-Core and look for SW-Access Gi0/2 180 S NF-SWITCH Gi0/1.

    Why: CDP is a layer 2 advertisement that every device on this CLI sends out of every up port by default — every 60 seconds, with a 180-second holdtime telling the receiver how long to trust each entry. Nothing has to be configured for two directly cabled devices to learn each other's name, platform and ports.

  2. 2. Add the router — invisible until its port is up

    Drag a router in, name it R-Edge, and cable its Gi0/0 to SW-Core's Gi0/1. Look at SW-Core's neighbour table: no router. A router's ports ship shut, and a shut port sends nothing — CDP included. Give Gi0/0 192.168.1.1/24 and bring it up, and R-Edge appears on SW-Core within the same breath.

    • Cable R-Edge Gi0/0 ↔ SW-Core Gi0/1

    On R-Edge — Name the router

    enable
    configure terminal
    hostname R-Edge
    end

    On SW-Core — Look for the router — it is not there yet

    enable
    show cdp neighbors

    On R-Edge — Address the router's LAN port and bring it up

    enable
    configure terminal
    interface Gi0/0
    ip address 192.168.1.1 255.255.255.0
    no shutdown
    end

    Check: run show cdp neighbors on SW-Core and look for R-Edge Gi0/1 180 R NF-ROUTER Gi0/0.

    Why: Neighbour discovery rides on a working link. A cable drawn into an administratively down port carries nothing, so the device behind it is invisible to CDP — which makes the neighbour table a quick test of whether a link is really up, not just plugged in.

  3. 3. Find the router's address from a switch that can see it

    Stand at SW-Access, the closet switch, with no documentation. `show cdp neighbors` lists SW-Core — and only SW-Core: the router is invisible from here. So hop one switch closer and ask SW-Core with `show cdp neighbors detail`: the R-Edge entry carries its address, 192.168.1.1. Now give SW-Access a management address in VLAN 1 and point its default gateway at the router you just found.

    On SW-Access — From the closet switch, only SW-Core is visible

    enable
    show cdp neighbors

    On SW-Core — Ask the switch that can see the router for its address

    enable
    show cdp neighbors detail

    On SW-Access — Give the closet switch a management address and the router as its gateway

    enable
    configure terminal
    interface vlan 1
    ip address 192.168.1.3 255.255.255.0
    no shutdown
    exit
    ip default-gateway 192.168.1.1
    end
    ping 192.168.1.1

    Check: run show cdp neighbors detail on SW-Core and look for IP address: 192.168.1.1.

    Why: CDP frames are never forwarded: each device hears only the devices on the other ends of its own cables. You map a network by hopping from neighbour to neighbour, and `detail` adds what each neighbour answers on — the fastest way to find a gateway nobody wrote down.

  4. 4. LLDP: the open standard, off until you turn it on

    Try `show lldp neighbors` on SW-Core first: "% LLDP is not enabled". Turn it on with `lldp run` on both switches. SW-Core now lists SW-Access in its LLDP table — and not R-Edge, which is still visible over CDP. The router never ran LLDP, and a neighbour only shows up when both ends speak the protocol.

    On SW-Core — Turn LLDP on for the core switch

    enable
    configure terminal
    lldp run
    end

    On SW-Access — Turn LLDP on for the closet switch

    enable
    configure terminal
    lldp run
    end

    Check: run show lldp neighbors on SW-Core and look for SW-Access Gi0/2.

    Why: CDP belongs to one family of devices; LLDP (IEEE 802.1AB) is the vendor-neutral version every brand of switch, phone and access point can speak. The two run side by side and independently — on this CLI CDP starts on and LLDP starts off.

  5. 5. Stop announcing the router to the internet

    R-Edge's Gi0/1 will be cabled to the internet provider. CDP would tell whatever is on the far end the router's name, platform and addresses, so turn it off on that one port before it is ever plugged in, and label the port while you are there. CDP stays on everywhere else, where your own team relies on it.

    On R-Edge — Label the internet-facing port and keep CDP off it

    enable
    configure terminal
    interface Gi0/1
    description TO-ISP
    no cdp enable
    end

    Check: run show running-config on R-Edge and look for no cdp enable.

    Why: Discovery protocols help a troubleshooter and an attacker equally: they announce model, software and addresses in clear text to anyone plugged into the port. Keep them on the links you own and off every port that faces a network you don't.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Map the network with CDP and LLDP — step-by-step network lab · NetForge-AI