Configuring ACLs for ARP Filtering
To configure ACLs for ARP filtering, enter commands such as the following.
device(config)# ip access-list extended 101 device(config-ext-ipacl-101)# permit ip host 192.168.2.2 any device(config-ext-ipacl-101)# exit device(config)# ip access-list extended 102 device(config-ext-ipacl-102)# permit ip host 192.168.2.3 any device(config-ext-ipacl-102)# exit device(config)# ip access-list extended 103 device(config-ext-ipacl-103)# permit ip host 192.168.2.4 any device(config-ext-ipacl-103)# exit device(config)# vlan 2 device(config-vlan-2)# tagged ethernet 1/1/1 to 1/1/2 device(config-vlan-2)# vlan 3 device(config-vlan-3)# tagged ethernet 1/1/1 to 1/1/2 device(config-vlan-3)# vlan 4 device(config-vlan-4)# tagged ethernet 1/1/1 to 1/1/2 device(config-vlan-4)# vlan 2 device(config-vlan-2)# ip access-group 101 in device(config-vlan-2)# ip address 192.168.2.1/24 device(config-vlan-2)# interface ve 2 device(config-vif-2)# ip use-acl-on-arp 103 device(config-vif-2)# vlan 3 device(config-vlan-3)# ip access-group 102 in device(config-vlan-3)# interface ve 3 device(config-vif-3)# ip use-acl-on-arp 103 device(config-vif-3)# vlan 4 device(config-vlan-4)# interface ve 4 device(config-vif-4)# ip use-acl-on-arp 103 device(config-vif-4)# exit device(config)#
When the ip use-acl-on-arp command is configured, the ARP module checks the source IP address of the ARP request packets received on the interface. It then applies the specified ACL policies to the packet. Only the packet with the IP address that the ACL permits will be written in the ARP table. The packets that are not permitted will be dropped.
The ACL ID identifies the standard or extended
IPv4 ACL that will be used to filter the packet. Only the source IP address, in
the
case of a standard ACL, or the source and destination IP addresses, in the case
of
an extended ACL, will be used to filter the ARP packet. Enter an ACL number to
explicitly specify the ACL to be used for filtering. In the example, the ip use-acl-on-arp 103
command specifies ACL 103 to be used as the filter.
ARP requests will not be filtered by ACLs if an
ACL ID is specified for the ip use-acl-on-arp command, but no IP address or "any any" filtering
criteria have been defined under the ACL name.