Cisco MCP Network Discovery
Provides tools for discovering Cisco network topology by starting from a seed host, collecting CDP/LLDP neighbor evidence and device information over SSH, and generating an editable Draw.io topology diagram for review.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Cisco MCP Network Discoverydiscover network topology from 10.1.1.1 and create drawio"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Cisco MCP network discovery prototype
Independent project by Andy Kumeda; not an official Cisco product. Start with a seed host, collect CDP/LLDP neighbor evidence and device information, and generate an editable Draw.io topology for engineer review.
Try the offline example
Python 3.10 or newer. No packages, credentials or network access required:
python3 -m cisco_mcp.demo --output-dir demo-outputOpen demo-output/index.html for a readable summary, or import demo-output/topology.drawio into a trusted local Draw.io editor. topology.json contains the evidence. All three devices and addresses are fictional. The demo executes the discovery and diagram code with simulated command responses; it does not connect to Cisco equipment or validate Genie parsing.
Related MCP server: MCP-Telecom
What is implemented
SSH command tool, optional Genie parsing, and MCP tools/resources.
Seed-host traversal with CDP, LLDP fallback when CDP is sparse, and ARP-assisted address resolution.
Hostname/alias merging, bidirectional link deduplication, interface labels and a topology summary in Draw.io XML.
Explicit host/CIDR scope, bounded depth and device count, command restrictions and strict SSH host-key checks.
The diagram is a starting point, not proof of a complete network. Missing discovery protocols, unreachable devices, ambiguous identities and parser differences limit coverage. Routes, VLANs, VRFs, tunnels and full Layer 3 reconstruction are not implemented. Raw-output parsers cover selected output formats; optional Genie behavior needs validation against target platforms. No configuration changes are offered by the default command policy.
Authorized lab use
Live SSH is disabled by default. See CONFIGURATION.md for deliberate setup, credentials, host keys, discovery scope and the MCP client example. Do not enable it against a network without permission. Keep collected topology and operational history private.
Verify
python3 -m unittest discover -s tests -v
python3 scripts/check_public_history.py
# To include the MCP SDK handler checks:
.venv/bin/python -m unittest discover -s tests -vRECOVERY.md explains how the newer implementation was recovered from the existing private project into this clean portfolio snapshot without importing private Git history. The original backup and private history remain separate. This public version is the canonical portfolio/demo source.
This server cannot be deployed
Maintenance
Related MCP Connectors
Offline methodology engine for authorized penetration testing, CTF, and security research.
IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.
Draw your app's architecture on a live canvas and flag the bottlenecks and security gaps.
Discover cloud shapes and create, inspect, validate, patch, and review architecture diagrams.
Related MCP Servers
- AlicenseAqualityDmaintenanceVisual network topology editor with AI agent integration via MCP. One-click SSH + web-service access from any node, nmap/CSV import, smart auto-layout, multi-sheet, local-first. Open-source successor to netViz (CA Technologies 1990-2012)4453 npm3MIT
- AlicenseAqualityCmaintenanceBridges AI agents with network infrastructure, enabling secure read-only access to multiple vendor routers via SSH for natural language queries and troubleshooting.581MIT
- AlicenseAqualityBmaintenanceProvides read-only SSH access to network devices (routers, switches, firewalls) with command allow/deny policies, nt-templates output parsing, and an audit trail, enabling an AI agent to query device state securely.10MIT
- FlicenseNot gradedqualityCmaintenanceEnables read-only access to managed network devices over SSH or Telnet via MCP, allowing users to probe devices, retrieve redacted running or startup configs, gather facts and interfaces, back up multiple devices, and compare configs for drift or unsaved changes.-