192 | FIP Snooping
www.dell.com | support.dell.com
Enabling the FIP Snooping Feature
As soon as you enable the FIP snooping feature on a switch-bridge, existing VLAN-specific and FIP 
snooping configurations are applied. By default, all FCoE and FIP frames are dropped unless specifically 
permitted by existing FIP snooping-generated ACLs. You can reconfigure any of the FIP snooping 
settings. 
If you disable FIP snooping, FIP and FCoE traffic are handled as normal Ethernet frames and no FIP 
snooping ACLs are generated. The VLAN-specific and FIP snooping configuration is disabled and stored 
until you re-enable FIP snooping and the configurations are re-applied.
Enabling FIP Snooping on VLANs
You can enable FIP snooping globally on a switch on all VLANs or on a specified VLAN. When you 
enable FIP snooping on VLANs:
• FIP frames are allowed to pass through the switch on the enabled VLANs and are processed to 
generate FIP snooping ACLs.
• FCoE traffic is allowed on VLANs only after a successful virtual-link initialization (fabric login 
FLOGI) between an ENode and an FCF. All other FCoE traffic is dropped. 
• You must configure at least one interface for FCF (FIP snooping bridge-FCF) mode on a FIP 
snooping-enabled VLAN. You can configure multiple FCF trusted interfaces in a VLAN.
• A maximum of eight VLANS are supported for FIP snooping on the switch.When enabled globally, 
FIP snooping processes FIP packets in traffic only from the first eight incoming VLANs. When 
enabled on a per-VLAN basis, FIP snooping is supported on up to eight VLANs. 
Configuring the FC-MAP Value
You can configure the FC-MAP value to be applied globally by the switch on all or individual FCoE 
VLANs to authorize FCoE traffic. 
The configured FC-MAP value is used to check the FC-MAP value for the MAC address assigned to 
ENodes in incoming FCoE frames. If the FC-MAP value does not match, FCoE frames are dropped. A 
session between an ENode and an FCF is established by the switch-bridge only when the FC-MAP value 
on the FCF matches the FC-MAP value on the FIP snooping bridge.
Note: When you disable FIP snooping, the switch acts as pure Layer 2 switch that switches FCoE and 
FIP packets.
When you enable FIP snooping, the switch snoops FIP packets on VLANs enabled for FIP snooping and 
allows legitimate sessions. On VLANs disabled for FIP snooping, the switch drops FCoE and FIP packets.