How does LLDP differ from CDP, and why would a network built from several vendors' switches run LLDP?
answer
- same job, different owners
- IEEE standard versus one vendor
- EtherType versus SNAP header
- neither reads the other
basics
~20 sLLDP and CDP both advertise a device's identity, port and capabilities to its direct neighbour, but LLDP is the IEEE 802.1AB standard any vendor implements, while CDP is one vendor's proprietary protocol. Mixed-vendor networks run LLDP so every device can see every other.
solid answer
~40 sBoth are one-hop, periodic, unacknowledged advertisements sent to a link-local multicast address: device name, port, capabilities, addresses and software details. The difference is ownership. LLDP is IEEE 802.1AB, identified by EtherType `0x88CC` and extended through organizationally specific TLVs that IEEE 802.1, IEEE 802.3, TIA and the IETF all use. CDP is defined and controlled by a single vendor, framed as an LLC/SNAP frame under that vendor's OUI, and is reliably understood only by equipment that implements it. A device speaking only one of them does not see a neighbour speaking only the other, so in a mixed-vendor network LLDP is the one protocol every device shares. Many switches run both; each still advertises the same details to whoever is plugged in.
go deeper
Recall that LLDP is the IEEE standard any vendor implements, CDP is one vendor's proprietary protocol, and both describe the device on the other end of a cable.
Explain how each is framed and addressed, why neither is forwarded past the next switch, and why an LLDP-only device does not see a CDP-only neighbour.
Show the operational consequences: gaps in topology maps at vendor boundaries, doubled disclosure when both run on user ports, and reconciling two neighbour tables.
Argue the standardisation choice for a multi-vendor estate, including how extensibility through organizationally specific TLVs affects long-term tooling and procurement.
## Two protocols, one job Network operators want every device to say "I am this box, this is the port you are plugged into, this is what I am". Two layer 2 protocols do that job: - **LLDP**, the Link Layer Discovery Protocol, standardised by the IEEE as **802.1AB**. - **CDP**, a discovery protocol designed by one switch and router vendor for its own equipment, and still proprietary to it. CDP came first and is still common on that vendor's equipment. LLDP was standardised so that equipment from any vendor, plus servers, phones and access points, could exchange the same kind of information. ## Side by side | Property | LLDP | CDP | |---|---|---| | Owner | IEEE 802.1AB, an open standard | a single vendor | | Framing | Ethernet frame with EtherType `0x88CC` | 802.2 LLC/SNAP frame carrying the vendor's OUI and a protocol number under it | | Destination | a reserved multicast in the IEEE `01-80-C2-00-00-0x` block | a multicast address under the vendor's own OUI | | Exchange | one-way, periodic, unacknowledged | one-way, periodic, unacknowledged | | Content | mandatory Chassis ID, Port ID, Time To Live; optional name, description, capabilities, management address | device ID, port, capabilities, addresses, platform and software version | | Extension | organizationally specific TLVs, each under its owner's OUI | additions decided by the vendor | | Who implements | switches, routers, servers, phones, access points from many vendors | mainly the owning vendor; some others add partial support | The framing row is worth knowing precisely. RFC 9542 describes the two ways an IEEE 802 frame can name its payload: a 16-bit **EtherType** (LLDP's route) or an **LLC/SNAP header** that carries an OUI followed by a protocol number assigned by that OUI's owner (CDP's route). The second form is how a company can define a protocol without obtaining an EtherType. ## What they share - Both are **one hop**: the destination addresses are not forwarded by the switches that implement the protocol, so each device learns only about the device at the other end of each cable. - Both are **one-way**: nobody requests an advertisement and nobody acknowledges one; a hold time decides when a silent neighbour is forgotten. - Both need **no IP configuration** to work, so both can map a network whose addressing is broken. - Both are **unauthenticated**: a receiver believes whatever it is told. ## What happens in a mixed network 1. A switch from vendor A speaks only CDP; a switch from vendor B speaks only LLDP. 2. Each sends its advertisements; each receives the other's frames, which it does not recognise as discovery traffic and does not record. 3. Neither lists the other as a neighbour. A topology map built from either side shows a gap exactly where the vendors meet. 4. Enabling LLDP on both closes the gap, because LLDP is the protocol both implement. Servers and phones from third parties are the common case of the same problem. A server's LLDP agent cannot report its switch port to an operator if the switch speaks only CDP. ## Running both Many switches can run both protocols per port, and during a migration that is reasonable. It has two costs: - **Twice the disclosure.** Each protocol advertises system name, software details and management addresses to whatever is plugged in. A port facing untrusted users should send neither unless it needs one. - **Two sources of truth.** Inventory and automation tools must reconcile two neighbour tables that can disagree when one protocol is disabled on one side. Which protocol is enabled by default differs between platforms and software releases; that is an implementation choice, not something either protocol specifies. ## Why extensibility tipped the balance LLDP's TLV type 127 lets any organisation with an OUI add data without changing the base protocol. IEEE 802.1 adds VLAN details, IEEE 802.3 adds link and power details, TIA's LLDP-MED adds voice policy and inventory, and the IETF's RFC 8520 adds a Manufacturer Usage Description URL under IANA's OUI. A single-vendor protocol can only grow in the directions its owner chooses, which is the practical reason multi-vendor designs standardise on LLDP.
- If a switch running only CDP connects to a server running only LLDP, what does each record?Nothing about the other. Each receives frames for a protocol it does not run and does not treat them as discovery advertisements, so neither side has a neighbour entry. Enabling LLDP on the switch port fixes it, because LLDP is the protocol both can speak.
- What does LLDP's extension mechanism give a multi-vendor network that a single-vendor protocol cannot?Organizationally specific TLVs let IEEE 802.1, IEEE 802.3, TIA and the IETF each add fields under their own OUI — VLANs, link and power details, voice policy, a device-profile URL — while every receiver can skip TLVs it does not understand. A proprietary protocol adds only what its owner chooses, and only its owner's devices are guaranteed to read it.
saying these in an interview costs you the question
- CDP and LLDP interoperate, so either side reads the other
- CDP is the IEEE standard and LLDP a vendor extension
- LLDP discovers devices across routers while CDP stays local
- Running both is harmless because they reveal nothing sensitive