308
CN4093 Application Guide for N/OS 8.4
FCoE Connection Timeout
FCoE
‐
related
ACLs
and
VLANs
are
added,
changed,
and
removed
as
FCoE
device
connection
and
disconnection
are
discovered.
In
addition,
the
administrator
can
enable
or
disable
automatic
removal
of
ACLs
and
VLANs
for
FCFs
and
other
FCoE
connections
that
timeout
(fail
or
are
disconnected)
without
FIP
notification.
By
default,
automatic
removal
of
ACLs
upon
timeout
is
enabled.
To
change
this
function,
use
the
following
CLI
command:
FCoE ACL Rules
When
FIP
Snooping
is
enabled
on
a
port,
the
switch
automatically
installs
the
appropriate
ACLs
to
enforce
the
following
rules
for
FCoE
traffic:
Ensure
that
FIP
frames
from
ENodes
may
only
be
addressed
to
FCFs.
Flag
important
FIP
packets
for
switch
processing.
Ensure
no
end
device
uses
an
FCF
MAC
address
as
its
source.
Each
FCoE
port
is
assumed
to
be
connected
to
an
ENode
and
include
ENode
‐
specific
ACLs
installed,
until
the
port
is
either
detected
or
configured
to
be
connected
to
an
external
FCF.
Ports
that
are
configured
to
have
FIP
snooping
disabled
will
not
have
any
FIP
or
FCoE
related
ACLs
installed.
Prevent
transmission
of
all
FCoE
frames
from
an
ENode
prior
to
its
successful
completion
of
login
(FLOGI)
to
the
FCF.
After
successful
completion
of
FLOGI,
ensure
that
the
ENode
uses
only
those
FCoE
source
addresses
assigned
to
it
by
the
FCF.
After
successful
completion
of
FLOGI,
ensure
that
all
ENode
FCoE
source
addresses
originate
from
or
are
destined
to
the
appropriate
ENode
port.
After
successful
completion
of
each
FLOGI,
ensure
that
FCoE
frames
may
only
be
addressed
to
the
FCFs
that
accept
them.
Initially,
a
basic
set
of
FCoE
‐
related
ACLs
will
be
installed
on
all
ports
where
FIP
snooping
is
enabled.
As
the
switch
encounters
FIP
frames
and
learns
about
FCFs
and
ENodes
that
are
attached
or
disconnect,
ACLs
are
dynamically
installed
or
expanded
to
provide
appropriate
security.
When
an
FCoE
connection
logs
out,
or
times
out
(if
ACL
timeout
is
enabled),
the
related
ACLs
will
be
automatically
removed.
FCoE
‐
related
ACLs
are
independent
of
manually
configured
ACLs
used
for
regular
Ethernet
purposes.
FCoE
ACLs
generally
have
a
higher
priority
over
standard
ACLs.
CN 4093(config)#
[no]
fcoe fips timeout-acl
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...