CLI Reference Guide-R02

Table Of Contents
Chapter 10
| Access Control Lists
ARP ACLs
– 388 –
{any | host destination-ip | destination-ip ip-address-bitmask}
mac {any | host source-mac | source-mac mac-address-bitmask}
[any | host destination-mac | destination-mac mac-address-bitmask] [log]
source-ip – Source IP address.
destination-ip – Destination IP address with bitmask.
ip-address-bitmask
8
– IPv4 number representing the address bits to match.
source-mac – Source MAC address.
destination-mac – Destination MAC address range with bitmask.
mac-address-
bitmask
8
– Bitmask for MAC address (in hexadecimal format).
log - Logs a packet when it matches the access control entry.
Default Setting
None
Command Mode
ARP ACL
Command Usage
New rules are added to the end of the list.
Example
This rule permits packets from any source IP and MAC address to the destination
subnet address 192.168.0.0.
Console(config-arp-acl)#$permit response ip any 192.168.0.0 255.255.0.0 mac
any any
Console(config-arp-acl)#
Related Commands
access-list arp (386)
show access-list arp This command displays the rules for configured ARP ACLs.
Syntax
show access-list arp [acl-name]
acl-name – Name of the ACL. (Maximum length: 32 characters)
Command Mode
Privileged Exec
8. For all bitmasks, binary “1” means relevant and “0” means ignore.