Concept Guide
• You must apply the CAM-ACL space for the FCoE region before enabling the FIP-Snooping feature. If you do not apply CAM-ACL 
space, the following error message is displayed:
DellEMC(conf)#feature fip-snooping
% Error: Cannot enable fip snooping. CAM Region not allocated for Fcoe.
DellEMC(conf)#
NOTE: Manually add the CAM-ACL space to the FCoE region as it is not applied by default.
To support FIP-Snooping and set CAM-ACL, usecam-acl l2acl 4 ipv4acl 4 ipv6acl 0 ipv4qos 2 l2qos 1 l2pt 0 
ipmacacl 0 vman-qos 0 ecfmacl 0 fcoeacl 2 command.
CAM ACL Table
-- Chassis Cam ACL --
 Current Settings(in block sizes)
 1 block = 128 entries
L2Acl : 4
Ipv4Acl : 4
Ipv6Acl : 0
Ipv4Qos : 2
L2Qos : 1
L2PT : 0
IpMacAcl : 0
VmanQos : 0
VmanDualQos : 0
EcfmAcl : 0
FcoeAcl : 2
iscsiOptAcl : 0
ipv4pbr : 0
vrfv4Acl : 0
Openflow : 0
fedgovacl : 0
nlbclusteracl: 0
st-sjc-s5000-29#
Enabling the FCoE Transit Feature
The following sections describe how to enable FCoE transit.
NOTE
: FCoE transit is disabled by default. To enable this feature, you must follow the Congure FIP Snooping.
As soon as you enable the FCoE transit feature on a switch-bridge, existing VLAN-specic and FIP snooping congurations are applied. 
The FCoE database is populated when the switch connects to a converged network adapter (CNA) or FCF port and compatible DCB 
congurations are synchronized. By default, all FCoE and FIP frames are dropped unless specically permitted by existing FIP snooping-
generated ACLs. You can recongure any of the FIP snooping settings.
If you disable FCoE transit, FIP and FCoE trac are handled as normal Ethernet frames and no FIP snooping ACLs are generated. The 
VLAN-specic and FIP snooping conguration is disabled and stored until you re-enable FCoE transit and the congurations are re-applied.
Enable FIP Snooping on VLANs
You can enable FIP snooping globally on a switch on all VLANs or on a specied VLAN.
When you enable FIP snooping on VLANs:
• FIP frames are allowed to pass through the switch on the enabled VLANs and are processed to generate FIP snooping ACLs.
• FCoE trac is allowed on VLANs only after a successful virtual-link initialization (fabric login FLOGI) between an ENode and an FCF. All 
other FCoE trac is dropped.
FIP Snooping
329










