Submit a ticketCall us

Announcing NCM 7.7
With NCM 7.7, you can examine the rules that make up an access control list for a Cisco ASA device. Then you can apply filters to display only rules that meet the specified criteria, order the rules by line number or by the hit count, and much more.
See new features and improvements.

Home > Success Center > Network Topology Mapper (NTM) > NTM nodes classified as unidentified or unknown

NTM nodes classified as unidentified or unknown

Updated March 11th, 2016


Unknown or unidentified nodes are nodes for which NTM found some data (IP address, MAC address or sysName) in CDP, LLDP or routing tables. These nodes are unknown/unidentified because they have no “real data”.

In the map you can choose to show all unidentified spokes (one connection), unidentified nodes that connect two or more normal nodes (more than one connection), both or neither.


All NTM versions


Cases that produce unknown/unidentified nodes:

  • Device provides Next Hop IP address (routing table) which was not known (does not match with known IP addresses)
  • Device provides CDP or LLDP record with a "new" (previously unknown) device id (sysname, mac, serial, combination of those)
  • Device provides Bridge table records which indicate several different connections on the same port. If NTM cannot determine which connection is physical it generates a virtual node with this naming convention: "Unidentified_{nodeid}".


NTM can promote an unknown/unidentified node to an identified node:

  • If you verify that the node is within the discovery range and can be polled correctly.
  • If you re-scan the range and the rediscovery includes a match with the unidentified node.
Last modified
09:30, 20 Apr 2017