Dell PowerEdge FX2 Dell PowerEdge FN I/O Aggregator Configuration Guide 9.6(0 - Page 250

NPIV Proxy Gateway: Protocol Services, NPIV Proxy Gateway Functionality

Page 250 highlights

Converged Network Adapter (CNA) ports on servers connect to the FX2 chassis Ten-Gigabit Ethernet ports and log in to an upstream FC core switch through the N port. Server fabric login (FLOGI) requests are converted into fabric discovery (FDISC) requests before being forwarded to the FC core switch. Servers use CNA ports to connect over FCoE to an Ethernet port in ENode mode on the NPIV proxy gateway. FCoE transit with FIP snooping is automatically enabled and configured on the FX2 gateway to prevent unauthorized access and data transmission to the SAN network. FIP is used by server CNAs to discover an FCoE switch operating as an FCoE forwarder (FCF). The NPIV proxy gateway aggregates multiple locally connected server CNA ports into one or more upstream N port links, conserving the number of ports required on an upstream FC core switch while providing an FCoE-to-FC bridging functionality. The upstream N ports on an FX2 can connect to the same or multiple fabrics. Using an FCoE map applied to downstream (server-facing) Ethernet ports and upstream (fabric-facing) FC ports, you can configure the association between a SAN fabric and the FCoE VLAN that connects servers over the NPIV proxy gateway to FC switches in the fabric. An FCoE map virtualizes the upstream SAN fabric as an FCF to downstream CNA ports on FCoE-enabled servers as follows: • As soon as an FC N port comes online (no shutdown command), the NPG starts sending FIP multicast advertisements, which contain the fabric name derived from the 64-bit worldwide name (WWN) of the principal SAN switch. (The principal switch in a fabric is the FC switch with the lowest domain ID.) • When you apply the FCoE map to a server-facing Ethernet port in ENode mode, ACLs are automatically configured to allow only FCoE traffic from servers that perform a successful FLOGI on the FC switch. All other traffic on the VLAN is denied. You can specify one or more upstream N ports in an FCoE map. The FCoE map also contains the VLAN ID of the dedicated VLAN used to transmit FCoE traffic between the SAN fabric and servers. NPIV Proxy Gateway: Protocol Services The Aggregator with the NPG provides the following protocol services: • Fibre Channel service to create N ports and log in to an upstream FC switch. • FCoE service to perform: - Virtualization of FC N ports on an NPG so that they appear as FCoE FCFs to downstream servers. - NPIV service to perform the association and aggregation of FCoE servers to upstream F ports on core switches (through N ports on the NPG). Conversion of server FLOGIs and FDISCs, which are received over the Aggregator with the ENode ports, are converted into FDISCs addressed to the upstream F ports on core switches. NPIV Proxy Gateway Functionality The Aggregator with the NPG provides the following functionality in a storage area network: • FIP Snooping bridge that provides security for FCoE traffic using ACLs. • FCoE gateway that provides FCoE-to-FC bridging. N-port virtualization using FCoE maps exposes upstream F ports as FCF ports to downstream server-facing ENode ports on the NPG. 250 NPIV Proxy Gateway

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292

Converged Network Adapter (CNA) ports on servers connect to the FX2 chassis Ten-Gigabit Ethernet
ports and log in to an upstream FC core switch through the N port. Server fabric login (FLOGI) requests
are converted into fabric discovery (FDISC) requests before being forwarded to the FC core switch.
Servers use CNA ports to connect over FCoE to an Ethernet port in ENode mode on the NPIV proxy
gateway. FCoE transit with FIP snooping is automatically enabled and configured on the FX2 gateway to
prevent unauthorized access and data transmission to the SAN network. FIP is used by server CNAs to
discover an FCoE switch operating as an FCoE forwarder (FCF).
The NPIV proxy gateway aggregates multiple locally connected server CNA ports into one or more
upstream N port links, conserving the number of ports required on an upstream FC core switch while
providing an FCoE-to-FC bridging functionality. The upstream N ports on an FX2 can connect to the
same or multiple fabrics.
Using an FCoE map applied to downstream (server-facing) Ethernet ports and upstream (fabric-facing)
FC ports, you can configure the association between a SAN fabric and the FCoE VLAN that connects
servers over the NPIV proxy gateway to FC switches in the fabric. An FCoE map virtualizes the upstream
SAN fabric as an FCF to downstream CNA ports on FCoE-enabled servers as follows:
As soon as an FC N port comes online (
no shutdown
command), the NPG starts sending FIP
multicast advertisements, which contain the fabric name derived from the 64-bit worldwide name
(WWN) of the principal SAN switch. (The principal switch in a fabric is the FC switch with the lowest
domain ID.)
When you apply the FCoE map to a server-facing Ethernet port in ENode mode, ACLs are
automatically configured to allow only FCoE traffic from servers that perform a successful FLOGI on
the FC switch. All other traffic on the VLAN is denied.
You can specify one or more upstream N ports in an FCoE map. The FCoE map also contains the VLAN
ID of the dedicated VLAN used to transmit FCoE traffic between the SAN fabric and servers.
NPIV Proxy Gateway: Protocol Services
The Aggregator with the NPG provides the following protocol services:
Fibre Channel service to create N ports and log in to an upstream FC switch.
FCoE service to perform:
Virtualization of FC N ports on an NPG so that they appear as FCoE FCFs to downstream servers.
NPIV service to perform the association and aggregation of FCoE servers to upstream F ports on
core switches (through N ports on the NPG). Conversion of server FLOGIs and FDISCs, which are
received over the Aggregator with the ENode ports, are converted into FDISCs addressed to the
upstream F ports on core switches.
NPIV Proxy Gateway Functionality
The Aggregator with the NPG provides the following functionality in a storage area network:
FIP Snooping bridge that provides security for FCoE traffic using ACLs.
FCoE gateway that provides FCoE-to-FC bridging. N-port virtualization using FCoE maps exposes
upstream F ports as FCF ports to downstream server-facing ENode ports on the NPG.
250
NPIV Proxy Gateway