11.07.2015 Views

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 2<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> <strong>Cisco</strong> <strong>IOS</strong> Comm<strong>and</strong>sdeny (ARP access-list configuration)deny (ARP access-list configuration)Use the deny Address Resolution Protocol (ARP) access-list configuration comm<strong>and</strong> on the switch stackor on a st<strong>and</strong>alone switch to deny an ARP packet based on matches against the DHCP bindings. Use theno form of this comm<strong>and</strong> to remove the specified access control entry (ACE) from the access list.deny {[request] ip {any | host sender-ip | sender-ip sender-ip-mask} mac {any | host sender-mac| sender-mac sender-mac-mask} | response ip {any | host sender-ip | sender-ip sender-ip-mask}[{any | host target-ip | target-ip target-ip-mask}] mac {any | host sender-mac | sender-macsender-mac-mask} [{any | host target-mac | target-mac target-mac-mask}]} [log]no deny {[request] ip {any | host sender-ip | sender-ip sender-ip-mask} mac {any | hostsender-mac | sender-mac sender-mac-mask} | response ip {any | host sender-ip | sender-ipsender-ip-mask} [{any | host target-ip | target-ip target-ip-mask}] mac {any | host sender-mac| sender-mac sender-mac-mask} [{any | host target-mac | target-mac target-mac-mask}]} [log]This comm<strong>and</strong> is available only if your switch is running the IP services feature set.Syntax Descriptionrequestipanyhost sender-ipsender-ip sender-ip-maskmachost sender-macsender-macsender-mac-maskresponse iphost target-iptarget-ip target-ip-maskmachost target-mactarget-mactarget-mac-masklog(Optional) Define a match for the ARP request. When request is notspecified, matching is performed against all ARP packets.Specify the sender IP address.Deny any IP or MAC address.Deny the specified sender IP address.Deny the specified range of sender IP addresses.Deny the sender MAC address.Deny a specific sender MAC address.Deny the specified range of sender MAC addresses.Define the IP address values for the ARP responses.Deny the specified target IP address.Deny the specified range of target IP addresses.Deny the MAC address values for the ARP responses.Deny the specified target MAC address.Deny the specified range of target MAC addresses.(Optional) Log a packet when it matches the ACE.DefaultsThere are no default settings. However, at the end of the ARP access list, there is an implicit deny ip anymac any comm<strong>and</strong>.Comm<strong>and</strong> ModesARP access-list configurationOL-9776-08<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> Comm<strong>and</strong> Reference2-129

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!