Configuring ACLs for ARP Filtering

To configure ACLs for ARP filtering, enter commands such as the following.

device(config)# ip access-list extended 101 
device(config-ext-ipacl-101)# permit ip host 192.168.2.2 any 
device(config-ext-ipacl-101)# exit
device(config)# ip access-list extended 102
device(config-ext-ipacl-102)# permit ip host 192.168.2.3 any 
device(config-ext-ipacl-102)# exit
device(config)# ip access-list extended 103
device(config-ext-ipacl-103)# permit ip host 192.168.2.4 any 
device(config-ext-ipacl-103)# exit
device(config)# vlan 2 
device(config-vlan-2)# tagged ethernet 1/1/1 to 1/1/2 
device(config-vlan-2)# vlan 3 
device(config-vlan-3)# tagged ethernet 1/1/1 to 1/1/2 
device(config-vlan-3)# vlan 4 
device(config-vlan-4)# tagged ethernet 1/1/1 to 1/1/2 
device(config-vlan-4)# vlan 2 
device(config-vlan-2)# ip access-group 101 in 
device(config-vlan-2)# ip address 192.168.2.1/24
device(config-vlan-2)# interface ve 2 
device(config-vif-2)# ip use-acl-on-arp 103 
device(config-vif-2)# vlan 3
device(config-vlan-3)# ip access-group 102 in
device(config-vlan-3)# interface ve 3
device(config-vif-3)# ip use-acl-on-arp 103
device(config-vif-3)# vlan 4
device(config-vlan-4)# interface ve 4
device(config-vif-4)# ip use-acl-on-arp 103
device(config-vif-4)# exit
device(config)# 		 

When the ip use-acl-on-arp command is configured, the ARP module checks the source IP address of the ARP request packets received on the interface. It then applies the specified ACL policies to the packet. Only the packet with the IP address that the ACL permits will be written in the ARP table. The packets that are not permitted will be dropped.

The ACL ID identifies the standard or extended IPv4 ACL that will be used to filter the packet. Only the source IP address, in the case of a standard ACL, or the source and destination IP addresses, in the case of an extended ACL, will be used to filter the ARP packet. Enter an ACL number to explicitly specify the ACL to be used for filtering. In the example, the ip use-acl-on-arp 103 command specifies ACL 103 to be used as the filter.

ARP requests will not be filtered by ACLs if an ACL ID is specified for the ip use-acl-on-arp command, but no IP address or "any any" filtering criteria have been defined under the ACL name.