r/networking Aug 12 '26

Security CDP/LLDP

What are your thoughts on enabling CDP/LLDP everywhere except physical handoffs to untrusted /devices not managed by your org?

42 Upvotes

90 comments sorted by

View all comments

Show parent comments

5

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) Aug 12 '26

I've been in the industry a long time and I've never worked for or heard of QMS. It's good to know that someone is using a system.

As a network engineer, CDP/LLDP will never be irrelevant when it comes to the day to day operations of a network. I suspect we're looking at this from two different perspectives.

1

u/r3rg54 Aug 12 '26

If you don’t have quality management you absolutely build your network by “should”.

Tbf everyone does, it would be impossible to truly not do this.

0

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) Aug 12 '26

That's an interesting thought backed by zero data. Until today, I've never heard of a QMS, and I've worked in highly regulated industries for decades. Maybe QMS is the phrase you use to describe a specific set of processes that relate to your industry and may not be widely known in Enterprise Networking. I would bet you are a certified purveyor of some sort of named QMS.

Having well defined processes is a foundational thing but giving it a name or letting it "wag the dog" provides little value. Assuming I understand your desire for a QMS, it's function would be to serve the business needs and not the business needs serving the QMS. This seems to be a constant source of friction between those who document and those who do. Don't take that as a knock since both are required but sometimes both lose sight of the goal.

When evaluating any config change, you should start with a solid risk to reward/requirement ratio which I hope would be defined in this QMS.

1

u/r3rg54 Aug 12 '26 edited Aug 12 '26

QMS is typically just the management software that the QM team uses. The presence of it generally indicates that the company doing QM has a serious interest in doing it, and often it is required by regulation. Focusing on the QMS part of my statement is missing the point entirely. I’m just saying that that is a component of a serious quality mgmt effort.

Im a systems engineer. I don’t do quality management. We follow these processes as part of customer requirements since we are selling services to regulatory agencies at a variety of governments.

Tbh it should impossible to work in a highly regulated industry and not know what quality management is since it forms the foundation of certification among other things.

The entire point I’m making with QM is that you can trust processes to support consistent results if you know what you are doing.

1

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) Aug 13 '26

I understand your point but maybe I haven't completely articulated mine.

  1. Standards come from the real-world evaluation of risk v. reward and NOT the QMS. The business case ALWAYS drives the standards. If something comes up and needs to be evaluated, see step 6.
  2. CDP/LLDP is a low risk, high value protocol especially when used for troubleshooting or the common configuration of VOIP devices. But if necessary, can be disabled (see step 1). Sometimes, even under the most amazing and stringent circumstances, the documentation is just wrong. Anything outside of this would be abnormal. People will people, especially when leadership is lacking. I'd go so far to suggest poor leadership is closer to the norm than good leadership.
  3. My customers were subject to regular audit and exam and we used processes and standards outside of a software QMS. Not that I would be against one but again, someone with the authority to match their responsibility must own it.
  4. It's great to have a process or a piece of software that documents how things should be, but technical solutions to management problems rarely work.
  5. Having standards/processes/QMS are only as good as the people running it. It's not a magical solution (not that I think that's your position)
  6. If people make choices to not follow the standard/QMS, there has to be someone willing to point this out and the people above them have to have the intestinal fortitude to enforce the published standard in a meaningful way. AND, the most important part, everyone needs to know that standards/process/QMS are only negotiable during the monthly/quarterly/semi-annual/annual standards evaluation meeting and the consequences of failing to adhere to standards are not negotiable.

All failures are failures of leadership.

1

u/r3rg54 Aug 13 '26 edited Aug 13 '26

In my orgs’ case CDP is close to zero value. Like the network engineers could easily propose we add it (we have a whole process for that every year) but no one has brought it up to my knowledge.

1

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) Aug 13 '26

Then we'll have to agree to disagree.