2.1.2 Set 'no cdp run'

Information

Disable Cisco Discovery Protocol (CDP) service at device level.

Rationale:

The Cisco Discovery Protocol is a proprietary protocol that Cisco devices use to identify each other on a LAN segment. It is useful only in network monitoring and troubleshooting situations but is considered a security risk because of the amount of information provided from queries. In addition, there have been published denial-of-service (DoS) attacks that use CDP. CDP should be completely disabled unless necessary.

Solution

Disable Cisco Discovery Protocol (CDP) service globally.


hostname(config)#no cdp run

Impact:

To reduce the risk of unauthorized access, organizations should implement a security policy restricting network protocols and explicitly require disabling all insecure or unnecessary protocols.

Default Value:

Enabled on all platforms except the Cisco 10000 Series Edge Services Router





References:

http://www.cisco.com/en/US/docs/ios-xml/ios/cdp/command/cdp-cr-a1.html#GUID-E006FAC8-417E-4C3F-B732-4D47B0447750

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1

Plugin: Cisco

Control ID: c03249086a5d9baaf6f54e01276424312d190125a5f76aaf70f4084e6628079b