26.10.2013 Views

8.3.17.0 - Force10 Networks

8.3.17.0 - Force10 Networks

8.3.17.0 - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

www.dell.com | support.dell.com<br />

96 | FIP Snooping<br />

FIP Snooping on VLANs<br />

FIP snooping is enabled globally on an Aggregator on all VLANs:<br />

• FIP frames are allowed to pass through the switch on the enabled VLANs and are processed to<br />

generate FIP snooping ACLs.<br />

• FCoE traffic is allowed on VLANs only after a successful virtual-link initialization (fabric login<br />

FLOGI) between an ENode and an FCF. All other FCoE traffic is dropped.<br />

• At least one interface is auto-configured for FCF (FIP snooping bridge-FCF) mode on a FIP<br />

snooping-enabled VLAN. Multiple FCF trusted interfaces are auto-configured in a VLAN.<br />

• A maximum of eight VLANS are supported for FIP snooping on an Aggregator. FIP snooping<br />

processes FIP packets in traffic only from the first eight incoming VLANs.<br />

FC-MAP Value<br />

The FC-MAP value that is applied globally by the Aggregator on all FCoE VLANs to authorize FCoE<br />

traffic is auto-configured.<br />

The FC-MAP value is used to check the FC-MAP value for the MAC address assigned to ENodes in<br />

incoming FCoE frames. If the FC-MAP value does not match, FCoE frames are dropped. A session<br />

between an ENode and an FCF is established by the switch-bridge only when the FC-MAP value on the<br />

FCF matches the FC-MAP value on the FIP snooping bridge.<br />

Bridge-to-FCF Links<br />

A port directly connected to an FCF is auto-configured in FCF mode. Initially, all FCoE traffic is blocked;<br />

only FIP frames are allowed to pass.<br />

FCoE traffic is allowed on the port only after a successful FLOGI request/response and confirmed use of<br />

the configured FC-MAP value for the VLAN.<br />

Impact on other Software Features<br />

FIP snooping affects other software features on an Aggregator as follows:<br />

• MAC address learning: MAC address learning is not performed on FIP and FCoE frames, which are<br />

denied by ACLs dynamically created by FIP snooping on server-facing ports in ENode mode.<br />

• MTU auto-configuration: MTU size is set to mini-jumbo (2500 bytes) when a port is in Switchport<br />

mode, the FIP snooping feature is enabled on the switch, and FIP snooping is enabled on all or<br />

individual VLANs.<br />

• Link aggregation group (LAG): FIP snooping is supported on port channels on ports on which PFC<br />

mode is on (PFC is operationally up).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!