Users Guide
Openflow : 0
fedgovacl : 0
nlbclusteracl: 0
st-sjc-s5000-29#
Enabling the FCoE Transit Feature
The following sections describe how to enable FCoE transit.
NOTE: FCoE transit is disabled by default. To enable this feature, you must follow the Conguring FIP Snooping.
As soon as you enable the FCoE transit feature on a switch-bridge, existing VLAN-specic and FIP snooping congurations are
applied. The FCoE database is populated when the switch connects to a converged network adapter (CNA) or FCF port and
compatible DCB congurations are synchronized. By default, all FCoE and FIP frames are dropped unless specically permitted by
existing FIP snooping-generated ACLs. You can recongure any of the FIP snooping settings.
If you disable FCoE transit, FIP and FCoE trac are handled as normal Ethernet frames and no FIP snooping ACLs are generated.
The VLAN-specic and FIP snooping conguration is disabled and stored until you re-enable FCoE transit and the congurations are
re-applied.
Enable FIP Snooping on VLANs
You can enable FIP snooping globally on a switch on all VLANs or on a specied VLAN.
When you enable FIP snooping on VLANs:
• FIP frames are allowed to pass through the switch on the enabled VLANs and are processed to generate FIP snooping ACLs.
• FCoE trac is allowed on VLANs only after a successful virtual-link initialization (fabric login FLOGI) between an ENode and an
FCF. All other FCoE trac is dropped.
• You must congure at least one interface for FCF (FIP snooping bridge-bridge) mode on a FIP snooping-enabled VLAN.
• On an S5000 NPIV proxy gateway:
– A maximum of 12 VLANs are supported for FIP snooping.
– The maximum number of FCFs supported on a FIP snooping-enabled VLAN is 12.
• On an S5000 switch not congured as an NPIV proxy gateway:
– A maximum of eight VLANs are supported for FIP snooping.
– The maximum number of FCFs supported on a FIP snooping-enabled VLAN is 12.
NOTE: When you enable FCoE transit, FIP solicitation responses from an FCF may be forwarded on an FCoE VLAN to
multiple ENodes.
Congure the FC-MAP Value
You can globally congure the FC-MAP on all or individual FCoE VLANs to authorize FCoE trac.
to check the FC-MAP value for the MAC address assigned to ENodes in incoming FCoE frames, use the congured FC-MAP value.
If the FC-MAP value does not match, FCoE frames are dropped. A session between an ENode and an FCF is established by the
switch-bridge only when the FC-MAP value on the FCF matches the FC-MAP value on the FIP snooping bridge.
Congure a Port for a Bridge-to-Bridge Link
If a switch port is connected to another FIP snooping bridge, congure the FCoE-Trusted Port mode for bridge-bridge links.
Initially, all FCoE trac is blocked. Only FIP frames with the ALL_FCF_MAC and ALL_ENODE_MAC values in their headers are
allowed to pass. After the switch learns the MAC address of a connected FCF, it allows FIP frames destined to or received from the
FCF MAC address.
FCoE trac is allowed on the port only after the switch learns the FC-MAP value associated with the specied FCF MAC address
and veries that it matches the congured FC-MAP value for the FCoE VLAN.
320
FCoE Transit