Build a network map from LLDP, CDP and switch MAC tables
Draw how your network is wired with NetBlade: prepare switches with SNMP and LLDP, read the network, and interpret links, ports and unplaced devices.
A network map answers the questions that cost an afternoon with a torch in the rack: which switch port is that printer on, what hangs off the uplink, where does the access point in the meeting room connect. NetBlade builds the map by asking your network gear over SNMP what is connected where. This article covers what the switches need, the order to do things in, and how to read what comes out.
Before you start
- SNMP working on your switches, router and access points, with a credential filed in NetBlade (SNMP).
- The PC running NetBlade connected to the network you want to map. A network can only be read from a PC connected to it.
- Administrator access to the switches, to turn on LLDP where it is off.
1. Understand how the map is built
NetBlade combines two readings, both over SNMP:
- Neighbour tables (LLDP and CDP). Network devices announce themselves to the device at the other end of each cable. LLDP is the vendor-neutral standard; CDP is Cisco’s own. These tables say which port of which switch goes to which port of which other switch, access point or router. They form the skeleton, and the legend calls them link stated by the devices (LLDP/CDP).
- MAC tables. A switch learns which MAC addresses it hears behind each port. NetBlade uses them to place every other device (PCs, printers, phones) on a port. A device’s MAC is heard on every port between the switch and the device, so NetBlade places it on the port where the fewest MACs are heard: the access port it is plugged into, not the uplink everything travels over. The legend calls these worked out from the MAC table.
2. Turn on LLDP on your network gear
LLDP is on out of the box on Omada, UniFi, HP and Aruba. On other brands, look for LLDP in the switch’s web interface (often under Discovery, Neighbours or Administration) and enable it, both sending and receiving, on all ports. Cisco devices also speak CDP, which NetBlade reads too. This is general switch configuration; your vendor’s manual has the exact page.
Tip: Turn LLDP on for access points and routers too, if they offer it. Every device that announces itself adds a link stated by the devices to the map instead of a deduction.
3. Read the network gear first
The map only asks devices that have already been read successfully over SNMP. This keeps it fast: it does not knock on every device with every community on file.
- Open Devices, filter Type to switches, routers and access points if you like, and press Deep inventory. Or, in Sites, press Read every device.
- Open a switch’s card and check that the read status says «Read … via …» and that the Interfaces tab shows ports.
If a switch is not read, the map cannot ask it. Fix that first.
4. Read the network
- In the menu open Map.
- Choose the site in the list next to the title.
- Press Read the network.
- Wait for the summary line, for example «4 of 5 network devices answered: 6 LLDP/CDP links, 58 devices placed on a port.»
If some gear did not answer, the page names it: «No answer from: … They need an SNMP credential that applies to them (Credentials).»
5. Read the map
- Nodes are devices. Click one to open its card.
- Links stated by the devices (LLDP/CDP) come from the gear itself. You can trust them as you would trust the switch.
- Links worked out from the MAC table are deductions. They are right in the common case and worth a second look in the unusual one.
- Use Zoom in, Zoom out and Fit to window to move around. The status line remembers when the map was last read and how many devices it placed.
Below the map, two lists deserve attention:
- Named by the network devices but not in the catalog. Your gear sees them, your scans do not. Often devices on another VLAN or subnet that the scan did not cover, sometimes devices that ignore ping. Scan that range or identify them.
- Not placed: no switch saw them on a port. Devices in the catalog that no switch reported. Typical causes: they are on a switch that does not answer SNMP, they are wireless behind an access point that does not publish its clients, or they have been idle long enough for the switch to forget their MAC address.
Note: Switches forget MAC addresses of silent devices after a few minutes (the ageing time is set on the switch). Read the map during working hours, when PCs and printers are on and talking.
6. Use the map for everyday answers
- Which port is this device on? Open the device’s card; or open the switch’s card, Interfaces tab, Seen on each port, which lists the MAC addresses learned on each port with the device they belong to.
- What is behind the uplink? Follow the LLDP/CDP link between two switches.
- Is there an unmanaged switch somewhere? Several devices placed on the same access port usually mean a small switch or a docking station under a desk.
- What changed? Read the network again after moving equipment; the status line shows the date of the last reading.
Check that it worked
- The summary line counts LLDP/CDP links and devices placed on a port.
- Your core switch sits in the middle with LLDP/CDP links to the other switches and access points.
- Clicking a PC opens its card, and the switch it hangs from is where you expect.
If something goes wrong
- «The map has not been read yet». Press Read the network. It needs an SNMP credential for the switches and the router, and LLDP on in the devices.
- «This network has not been read yet, and it can only be read from a PC connected to it». The PC running NetBlade is not on that site’s network. Read it from there.
- A switch is missing from the map. It has not been read over SNMP successfully, or it did not answer this time. Read it from its card, then read the network again. Network devices that do not answer SNMP do not appear as network nodes.
- Switches appear but with no links between them. LLDP is off on at least one side of each cable. Turn it on on both.
- Many devices land on one port. Either a small unmanaged switch hangs from that port, or it is an uplink to a switch that did not answer SNMP.
Next
With the inventory complete, turn it into action: Find and fix vulnerabilities.
← All how-to guides Feature guide → The product: NetBlade Windows →