Reference Guide

Process FIP VLAN discovery requests and responses, advertisements, solicitations, FLOGI/FDISC
requests and responses, FLOGO requests and responses, keep-alive packets, and clear virtual-link
messages.
FIP Snooping in a Switch Stack
FIP snooping supports switch stacking as follows:.
A switch stack configuration is synchronized with the standby stack unit.
Dynamic population of the FCoE database (ENode, Session, and FCF tables) is synchronized with the
standby stack unit. The FCoE database is maintained by snooping FIP keep-alive messages.
In case of a failover, the new master switch starts the required timers for the FCoE database tables.
Timers run only on the master stack unit.
NOTE: While technically possible to run FIP snooping and stacking concurrently, Dell Networking
recommends a SAN design utilizes two redundant FCoE network path versus stacking. This avoids a
single point of failure to the SAN and provides a guaranteed latency. The overall latency could easily
rise above desired SAN limits if a link level failure redirects traffic over the stacking backplane.
How FIP Snooping is Implemented
As soon as the Aggregator is activated in an M1000e chassis as a switch-bridge, existing VLAN-specific
and FIP snooping auto-configurations are applied. The Aggregator snoops FIP packets on VLANs enabled
for FIP snooping and allows legitimate sessions. By default, all FCoE and FIP frames are dropped unless
specifically permitted by existing FIP snooping-generated ACLs.
FIP Snooping on VLANs
FIP snooping is enabled globally on an Aggregator on all VLANs:
FIP frames are allowed to pass through the switch on the enabled VLANs and are processed to
generate FIP snooping ACLs.
FCoE traffic is allowed on VLANs only after a successful virtual-link initialization (fabric login FLOGI)
between an ENode and an FCF. All other FCoE traffic is dropped.
Atleast one interface is auto-configured for FCF (FIP snooping bridge — FCF) mode on a FIP
snooping-enabled VLAN. Multiple FCF trusted interfaces are auto-configured in a VLAN.
A maximum of eight VLANs are supported for FIP snooping on an Aggregator. FIP snooping processes
FIP packets in traffic only from the first eight incoming VLANs.
FC-MAP Value
The FC-MAP value that is applied globally by the Aggregator on all FCoE VLANs to authorize FCoE traffic
is auto-configured.
The FC-MAP value is used to check the FC-MAP value for the MAC address assigned to ENodes in
incoming FCoE frames. If the FC-MAP values does not match, FCoE frames are dropped. A session
between an ENode and an FCF is established by the switch —bridge only when the FC-MAP value on the
FCF matches the FC-MAP value on the FIP snooping bridge.
FIP Snooping
77