Administrator Guide
• Set the FCoE MAC address prefix (FC-MAP) value used by an FCF to assign a MAC address to an ECoE
end-device (server ENode or storage device) after a server successfully logs in.
• Set the FCF mode to provide additional port security on ports that are directly connected to an FCF.
• Check FIP snooping-enabled VLANs to ensure that they are operationally active.
• Process FIP VLAN discovery requests and responses, advertisements, solicitations, FLOGI/FDISC requests
and responses, FLOGO requests and responses, keep-alive packets, and clear virtual-link messages.
How FIP Snooping is Implemented
As soon as the Aggregator is activated in an Dell PowerEdge FX2 server chassis as a switch-bridge, existing
VLAN—specific and FIP snooping auto-configurations are applied. The Aggregator snoops FIP packets on
VLANs enabled for FIP snooping and allows legitimate sessions. By default, all FCoE and FIP frames are
dropped unless specifically permitted by existing FIP snooping-generated ACLs.
FIP Snooping on VLANs
FIP snooping is enabled globally on an Aggregator on all VLANs:
• FIP frames are allowed to pass through the switch on the enabled VLANs and are processed to generate
FIP snooping ACLs.
• FCoE traffic is allowed on VLANs only after a successful virtual-link initialization (fabric login FLOGI)
between an ENode and an FCF. All other FCoE traffic is dropped.
• Atleast one interface is auto-configured for FCF (FIP snooping bridge — FCF) mode on a FIP snooping-
enabled VLAN. Multiple FCF trusted interfaces are auto-configured in a VLAN.
• A maximum of eight VLANs are supported for FIP snooping on an Aggregator. FIP snooping processes
FIP packets in traffic only from the first eight incoming VLANs.
FC-MAP Value
The FC-MAP value that is applied globally by the Aggregator on all FCoE VLANs to authorize FCoE traffic is
auto-configured.
The FC-MAP value is used to check the FC-MAP value for the MAC address assigned to ENodes in incoming
FCoE frames. If the FC-MAP values does not match, FCoE frames are dropped. A session between an ENode
and an FCF is established by the switch —bridge only when the FC-MAP value on the FCF matches the FC-
MAP value on the FIP snooping bridge.
Bridge-to-FCF Links
A port directly connected to an FCF is auto-configured in FCF mode. Initially, all FCoE traffic is blocked; only
FIP frames are allowed to pass.
FCoE traffic is allowed on the port only after a successful FLOGI request/response and confirmed use of the
configured FC-MAP value for the VLAN.
FIP Snooping 381