Reference Guide

Important Points to Remember
Enable DCBx on the switch before enabling the FIP Snooping feature.
To enable the feature on the switch, configure FIP Snooping.
To allow FIP frames to pass through the switch on all VLANs, enable FIP snooping globally on a switch.
A switch can support a maximum eight VLANs. Configure at least one FCF/bridge-to-bridge port mode interface
for any FIP snooping-enabled VLAN.
You can configure multiple FCF-trusted interfaces in a VLAN.
When you disable FIP snooping:
ACLs are not installed, FIP and FCoE traffic is not blocked, and FIP packets are not processed.
The existing per-VLAN and FIP snooping configuration is stored. The configuration is re-applied the next
time you enable the FIP snooping feature.
Enabling the FCoE Transit Feature
The following sections describe how to enable FCoE transit.
NOTE: FCoE transit is disabled by default. To enable this feature, you must follow the Configuring FIP Snooping.
As soon as you enable the FCoE transit feature on a switch-bridge, existing VLAN-specific and FIP snooping
configurations are applied. The FCoE database is populated when the switch connects to a converged network adapter
(CNA) or FCF port and compatible DCB configurations are synchronized. By default, all FCoE and FIP frames are dropped
unless specifically permitted by existing FIP snooping-generated ACLs. You can reconfigure any of the FIP snooping
settings.
If you disable FCoE transit, FIP and FCoE traffic are handled as normal Ethernet frames and no FIP snooping ACLs are
generated. The VLAN-specific and FIP snooping configuration is disabled and stored until you re-enable FCoE transit
and the configurations are re-applied.
Enable FIP Snooping on VLANs
You can enable FIP snooping globally on a switch on all VLANs or on a specified VLAN.
When you enable FIP snooping on VLANs:
FIP frames are allowed to pass through the switch on the enabled VLANs and are processed to generate FIP
snooping ACLs.
FCoE traffic is allowed on VLANs only after a successful virtual-link initialization (fabric login FLOGI) between an
ENode and an FCF. All other FCoE traffic is dropped.
You must configure at least one interface for FCF (FIP snooping bridge-bridge) mode on a FIP snooping-enabled
VLAN. You can configure multiple FCF trusted interfaces in a VLAN.
A maximum of eight VLANS are supported for FIP snooping on the switch. When enabled globally, FIP snooping
processes FIP packets in traffic only from the first eight incoming VLANs. When enabled on a per-VLAN basis,
FIP snooping is supported on up to eight VLANs.
Configure the FC-MAP Value
You can configure the FC-MAP value to be applied globally by the switch on all or individual FCoE VLANs to authorize
FCoE traffic.
The configured FC-MAP value is used to check the FC-MAP value for the MAC address assigned to ENodes in incoming
FCoE frames. If the FC-MAP value does not match, FCoE frames are dropped. A session between an ENode and an FCF is
302