1.3.1 Disable CDP

Information

Disable Cisco Discovery Protocol (CDP) service at device level.

The Cisco Discovery Protocol is a proprietary protocol that Cisco devices use to identify each other on a LAN segment. It is useful only in network monitoring and troubleshooting situations but is considered a security risk because of the amount of information provided from queries. In addition, there have been published denial-of-service (DoS) attacks that use CDP. CDP should be completely disabled unless necessary.

Solution

Disable Cisco Discovery Protocol (CDP) service globally.

IOSXR(config)#no cdp

Impact:

To reduce the risk of unauthorized access, organizations should implement a security policy restricting network protocols and explicitly require disabling all insecure or unnecessary protocols.

See Also

https://workbench.cisecurity.org/benchmarks/10473

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Cisco

Control ID: 6d0a36420741f9b68919503b95e9b66229672fa4c4fa4ebff6c69332bfb4640d