Users Guide

Openflow : 0
fedgovacl : 0
nlbclusteracl: 0
st-sjc-s5000-29#
Enabling the FCoE Transit Feature
The following sections describe how to enable FCoE transit.
NOTE: FCoE transit is disabled by default. To enable this feature, you must follow the Conguring FIP Snooping.
As soon as you enable the FCoE transit feature on a switch-bridge, existing VLAN-specic and FIP snooping congurations are
applied. The FCoE database is populated when the switch connects to a converged network adapter (CNA) or FCF port and
compatible DCB congurations are synchronized. By default, all FCoE and FIP frames are dropped unless specically permitted by
existing FIP snooping-generated ACLs. You can recongure any of the FIP snooping settings.
If you disable FCoE transit, FIP and FCoE trac are handled as normal Ethernet frames and no FIP snooping ACLs are generated.
The VLAN-specic and FIP snooping conguration is disabled and stored until you re-enable FCoE transit and the congurations are
re-applied.
Enable FIP Snooping on VLANs
You can enable FIP snooping globally on a switch on all VLANs or on a specied VLAN.
When you enable FIP snooping on VLANs:
FIP frames are allowed to pass through the switch on the enabled VLANs and are processed to generate FIP snooping ACLs.
FCoE trac is allowed on VLANs only after a successful virtual-link initialization (fabric login FLOGI) between an ENode and an
FCF. All other FCoE trac is dropped.
You must congure at least one interface for FCF (FIP snooping bridge-bridge) mode on a FIP snooping-enabled VLAN.
On an S5000 NPIV proxy gateway:
A maximum of 12 VLANs are supported for FIP snooping.
The maximum number of FCFs supported on a FIP snooping-enabled VLAN is 12.
On an S5000 switch not congured as an NPIV proxy gateway:
A maximum of eight VLANs are supported for FIP snooping.
The maximum number of FCFs supported on a FIP snooping-enabled VLAN is 12.
NOTE: When you enable FCoE transit, FIP solicitation responses from an FCF may be forwarded on an FCoE VLAN to
multiple ENodes.
Congure the FC-MAP Value
You can globally congure the FC-MAP on all or individual FCoE VLANs to authorize FCoE trac.
to check the FC-MAP value for the MAC address assigned to ENodes in incoming FCoE frames, use the congured FC-MAP value.
If the FC-MAP value does not match, FCoE frames are dropped. A session between an ENode and an FCF is established by the
switch-bridge only when the FC-MAP value on the FCF matches the FC-MAP value on the FIP snooping bridge.
Congure a Port for a Bridge-to-Bridge Link
If a switch port is connected to another FIP snooping bridge, congure the FCoE-Trusted Port mode for bridge-bridge links.
Initially, all FCoE trac is blocked. Only FIP frames with the ALL_FCF_MAC and ALL_ENODE_MAC values in their headers are
allowed to pass. After the switch learns the MAC address of a connected FCF, it allows FIP frames destined to or received from the
FCF MAC address.
FCoE trac is allowed on the port only after the switch learns the FC-MAP value associated with the specied FCF MAC address
and veries that it matches the congured FC-MAP value for the FCoE VLAN.
320
FCoE Transit