Blocking ARP packets on SG3428X-M2

Blocking ARP packets on SG3428X-M2

Blocking ARP packets on SG3428X-M2
Blocking ARP packets on SG3428X-M2
Friday
Model: TL-SG3428X-M2  
Hardware Version: V1
Firmware Version: 1.20.2 Build 20240528 Rel.74834

I'm trying to block ARP packets from a specific IP range.

 

I have tried seemingly every possible combination of ACL settings and none of them seem to affect ARP packets (0 packets matched when ethertype is set to 0806).

 

The closest I've come to making this work is using IPv4 IMPB via Manual Binding and Arp Detection to effectively generate a "pass" rule (with implicit deny) for a specific IP/MAC; this blocks the unwanted ARP packets but it also blocks valid replies to the ARPs that I want to pass, and I cannot figure out how to allow the replies. I have tried adding a manual binding for the IP/MAC of the machine that generates the replies but they are still blocked by the switch (and are logged as being blocked due to IMPB MATCH FAILURE).

 

Hardware version: SG3428X-M2 1.20

  0      
  0      
#1
Options
1 Reply
Re:Blocking ARP packets on SG3428X-M2
Monday - last edited Monday

Hi @ekaszubski 

Thanks for posting in our business forum.

For the ACL, you should look it up in the User Guide and test it out yourself. It works as you configs. If it does not work, you need to double-check what you have configured.

 

ekaszubski wrote

The closest I've come to making this work is using IPv4 IMPB via Manual Binding and Arp Detection to effectively generate a "pass" rule (with implicit deny) for a specific IP/MAC; this blocks the unwanted ARP packets but it also blocks valid replies to the ARPs that I want to pass, and I cannot figure out how to allow the replies. I have tried adding a manual binding for the IP/MAC of the machine that generates the replies but they are still blocked by the switch (and are logged as being blocked due to IMPB MATCH FAILURE).

 

Hardware version: SG3428X-M2 1.20

In the end, if you still want to allow valid ARPs, you might wanna try other stuff like Port Security. Not ACL which blocks based on the protocol. ARP proxy.

We also have the use case which you can use deny and allow at the same time. Allow should be placed in the first place.

 

And to the point you asked, we don't provide support on how to block ARP. Blocking ARP is not proper and correct in our opinion. If you insist on doing so, please proceed at your discretion.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#2
Options