4 ms·
Security best practices have always recommended disabling CDP in an untrusted environment (that applies to things like LLDP, too). It is comical to see how many
by kitteh 7y ago
Security best practices have always recommended disabling CDP in an untrusted environment (that applies to things like LLDP, too). It is comical to see how many people leave both of those running on internet exchange points or sometimes worse things (like ospf or isis). The general default on nature of products to enable this is unfortunate.
- jcims 7y agoI remember writing it up as part of internal assessments in the late 90's lol.
- fulafel 7y agoSecurity best practices have always recommended treating all networks as untrusted and having non-internet-hardened stuff turned off by default in network facing products. You're right of course too, but Cisco is the real bad guy here.
- kitteh 7y agoEh, I know a lot of folks who do enable CDP/LLDP for internal device to internal device links for discovery and troubleshooting. But they don't turn it on any customer/external facing interfaces (this enforcement thru offline config generation). So there can be a time and a place for it under the right conditions provided you understand the security risks (possibility of someone plugging something on an internal link, changing the router config incorrectly).