IntermediatePublished 2026-07-04
Securing Discovery on Edge Ports
Bundle lab
Harden Cisco IOS edge interfaces by disabling CDP/LLDP toward untrusted endpoints while keeping discovery active on trusted infrastructure links. Routers share a management LAN with a server and form a direct router-to-router adjacency for CDP/LLDP. The learner enables discovery globally, selectively suppresses it on the client-facing edge, and verifies the outcome with show commands.
Learning objectives
- Enable CDP and LLDP globally to support infrastructure discovery on trusted links
- Disable discovery on a specific client-facing edge port using interface-level controls
- Explain why link-local discovery should not be exposed to untrusted hosts
- Verify discovery state using show cdp/lldp interface and neighbor outputs
- Differentiate discovery behavior on direct links vs across a switch
Troubleshooting focus
- If no neighbors appear on the router-to-router link, verify CDP/LLDP are enabled globally on both routers
- If the edge port still shows up in discovery, confirm interface-level suppression: no cdp enable, no lldp transmit, and no lldp receive
- If a router seems to discover a non-adjacent device, re-check cabling: discovery only works to directly connected neighbors and is terminated by switches
- If verifications fail intermittently, confirm the correct interface names and that links are up/up with matching IP subnets
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.