
676767
© 2002, Cisco Systems, Inc. All rights reserved.
l2-security-bh.ppt
Cisco Discovery Protocol (CDP)
¥ Runs at Layer 2 and allows Cisco devices
to chat with one another
¥ Can be used to learn sensible information
about the CDP sender (IP address,
software version, router model É)
¥ CDP is in the clear and unauthenticated
¥ Consider disabling CDP, or being very
selective in its use in security sensitive
environments (backbone vs. user port
may be a good distinction)
¥ Note: there was a reason Cisco developed
CDP, some Cisco apps make use of it!
CatOS> (enable) set cdp disable
<mod>/<port> | all
IOS(config)#no cdp run
IOS(config-if)#no cdp enable
0x2000
SNAP
Proto
0100.0ccc.cccc
DST MAC
Kommentare zu diesen Handbüchern