In Understanding Cisco Discovery Protocol Part 1, we discussed how CDP was a useful tool for finding directly connected devices. We saw how to enable CDP per device or for the entire interface. We learned how to modify the update interval for how often CDP is sent and when the neighbor information may flush out expired cached information. However there are other things to just be aware of when CDP is in use.
First, Cisco Discovery Protocol has a given vulnerability. CDP is sent out periodically as a layer 2 multicast. As long as a protocol analyzer such as Wireshark is running, anyone would inertly see these frames. The example below, displays an interface with these default timers. We can also see with this command again that it is running on that interface, gigabitethernet 4/1. If this was a public facing interface then every minute the service provider will see some this information.

Continue reading ‘Understanding Cisco Discovery Protocol: Part 2′



