Воспользовался этим:
http://tools.ietf.org/html/rfc826
Поймал пакет в сети(для проверки):
13:16:22.047462 arp who-has 10.0.4.103 tell 10.0.4.102
0x0000: ffff ffff ffff 0017 9a08 088e 0806 0001
0x0010: 0800 0604 0001 0017 9a08 088e 0a00 0466
0x0020: 0000 0000 0000 0a00 0467 0000 0000 0000
0x0030: 0000 0000 0000 0000 0000 0000
===========================
Создал Access Profile:
Profile ID 1
Type Packet Content Mask
Offset Offset (0 - 15)
mask:0xffffffff
mask:0xffff0000
mask:0x00000000
mask:0xffff0000
Offset (16 - 31)
mask:0x00000000
mask:0x00000000
mask:0x00000000
mask:0x00000000
Offset (32 - 47)
mask:0x00000000
mask:0x00000000
mask:0x00000000
mask:0x00000000
Offset (48 - 63)
mask:0x00000000
mask:0x00000000
mask:0x00000000
mask:0x00000000
Offset (64 - 79)
mask:0x00000000
mask:0x00000000
mask:0x00000000
mask:0x00000000
===========================
создал правило(для проверки):
Profile ID 1
Access ID 1
Mode Deny
Type Packet Content Mask
Priority ------
Replace Dscp with ------
Offset Offset (0 - 15)
mask:0xffffffff
mask:0xffff0000
mask:0x00000000
mask:0x08060000
Offset (16 - 31)
mask:0x00000000
mask:0x00000000
mask:0x00000000
mask:0x00000000
Offset (32 - 47)
mask:0x00000000
mask:0x00000000
mask:0x00000000
mask:0x00000000
Offset (48 - 63)
mask:0x00000000
mask:0x00000000
mask:0x00000000
mask:0x00000000
Offset (64 - 79)
mask:0x00000000
mask:0x00000000
mask:0x00000000
mask:0x00000000
Port Number Port 24
Owner ACL
===========================
Результат: Пакеты песпрепятственно проходят свич.
Вопрос: Что сделал не так?