White Papers

Table Of Contents
If you disable FCoE transit, FIP and FCoE traffic are handled as normal Ethernet frames and no FIP snooping ACLs are
generated. The VLAN-specific and FIP snooping configuration is disabled and stored until you re-enable FCoE transit and the
configurations are re-applied.
Enable FIP Snooping on VLANs
You can enable FIP snooping globally on a switch on all VLANs or on a specified VLAN.
When you enable FIP snooping on VLANs:
FIP frames are allowed to pass through the switch on the enabled VLANs and are processed to generate FIP snooping ACLs.
FCoE traffic is allowed on VLANs only after a successful virtual-link initialization (fabric login FLOGI) between an ENode and
an FCF. All other FCoE traffic is dropped.
You must configure at least one interface for FCF (FIP snooping bridge-bridge) mode on a FIP snooping-enabled VLAN.
On an S5000 NPIV proxy gateway:
A maximum of 12 VLANs are supported for FIP snooping.
The maximum number of FCFs supported on a FIP snooping-enabled VLAN is 12.
In NPIV mode, FIP Snooping does not work when the default VLAN is other then VLAN1.
On an S5000 switch not configured as an NPIV proxy gateway:
A maximum of eight VLANs are supported for FIP snooping.
The maximum number of FCFs supported on a FIP snooping-enabled VLAN is 12.
NOTE: When you enable FCoE transit, FIP solicitation responses from an FCF may be forwarded on an FCoE VLAN to
multiple ENodes.
Configure the FC-MAP Value
You can globally configure the FC-MAP on all or individual FCoE VLANs to authorize FCoE traffic.
to check the FC-MAP value for the MAC address assigned to ENodes in incoming FCoE frames, use the configured FC-MAP
value. If the FC-MAP value does not match, FCoE frames are dropped. A session between an ENode and an FCF is established
by the switch-bridge only when the FC-MAP value on the FCF matches the FC-MAP value on the FIP snooping bridge.
Configure a Port for a Bridge-to-Bridge Link
If a switch port is connected to another FIP snooping bridge, configure the FCoE-Trusted Port mode for bridge-bridge links.
Initially, all FCoE traffic is blocked. Only FIP frames with the ALL_FCF_MAC and ALL_ENODE_MAC values in their headers are
allowed to pass. After the switch learns the MAC address of a connected FCF, it allows FIP frames destined to or received from
the FCF MAC address.
FCoE traffic is allowed on the port only after the switch learns the FC-MAP value associated with the specified FCF MAC
address and verifies that it matches the configured FC-MAP value for the FCoE VLAN.
Configure a Port for a Bridge-to-FCF Link
If a port is directly connected to an FCF, configure the port mode as FCF. Initially, all FCoE traffic is blocked; only FIP frames
are allowed to pass.
NOTE:
FCoE-Trusted Port mode used to connect to another FIP snooping bridge (bridge-bridge link) is not supported on
the S5000 switch.
FCoE traffic is allowed on the port only after a successful fabric login (FLOGI) request/response and confirmed use of the
configured FC-MAP value for the VLAN.
Impact on Other Software Features
When you enable FIP snooping on a switch, other software features are impacted.
The following table lists the impact of FIP snooping.
302
FCoE Transit