ip use-acl-on-arp

Configures the ARP module to check the source IP address of the ARP request packets received on the interface before applying the specified ACL policies to the packet (ACL ARP filtering).
Syntax
ip use-acl-on-arp { acl-num }
no ip use-acl-on-arp { acl-num }
Command Default

ACL ARP filtering is not enabled.

Parameters
acl-num
Specifies the ACL number to be used for filtering (required).
Modes

Interface configuration sub-mode

Usage Guidelines

ACL ARP filtering is not applicable to outbound traffic.

This filtering occurs on the management processor. The command is available on physical interfaces and virtual routing interfaces. Stnadard and extended IPv4 numbered ACLs can be used. If any other ACL is used, an error is displayed.

When the ip use-acl-on-arp command is configured, the ARP module checks the source IP address of the ARP request packets received on the interface. It then applies the specified ACL policies to the packet. Only the packet with the IP address that the ACL permits will be written in the ARP table; those that are not permitted will be dropped.

ARP requests will not be filtered by ACLs if an ACL ID is specified for the ip use-ACL-on-arp command, but no IP address or "any any" filtering criteria has been defined under the ACL ID.

The no form of the command disables the ACL ARP filtering.

Examples

The following example shows a complete ACL ARP configuration.

device# configure terminal
device(config)# ip access-list extended 101 
(config-ext-ipacl-101)# permit ip host 192.168.2.2 any 
device(config-ext-ipacl-101)# exit
device(config)# ip access-list extended 102
device(config-ext-ipacl-102)# permit ip host 192.168.2.3 any 
device(config-ext-ipacl-102)# exit
device(config)# ip access-list extended 103
device(config-ext-ipacl-103)# permit ip host 192.168.2.4 any 
device(config-ext-ipacl-103)# exit
device(config)# vlan 2 
device(config-vlan-2)# tagged ethernet 1/1/1 to 1/1/2 
device(config-vlan-2)# interface ve 2 
device(config-vlan-2)# vlan 3 
device(config-vlan-3)# tagged ethernet 1/1/1 to 1/1/2 
device(config-vlan-3)#router-interface ve 3 
device(config-vlan-3)# vlan 4 
device(config-vlan-4)# tagged ethernet 1/1/1 to 1/1/2 
device(config-vlan-4)# interface ve 4 
device(config-vlan-4)# vlan 2 
device(config-vlan-2)# ip access-group 101 in 
device(config-vlan-2)# ip address 192.168.2.1/24
device(config-vlan-2)# interface ve 2 
device(config-vif-2)# ip use-acl-on-arp 103 
device(config-vif-2)# vlan 3
device(config-vlan-3)# ip access-group 102 in
device(config-vlan-3)# interface ve 3
device(config-vif-3)# ip use-acl-on-arp 103
device(config-vif-3)# vlan 4
device(config-vlan-4)# interface ve 4
device(config-vif-4)# ip use-acl-on-arp 103
device(config-vif-4)# exit
device(config)# 		 
History
Release version Command history
08.0.95 This command was modified to require an ACL number.