The firewall mac-binding acl-number command specifies the packets to implement IP-MAC binding checks. The IP-MAC binding check is implemented only on the packets that match the ACL rule with the permit action. If the IP-MAC mapping entry cannot be found based on the IP address or the bound MAC address is incorrect, the packet is discarded.
The undo firewall mac-binding acl-number command cancels the preceding configuration. That is, IP-MAC binding checks are implemented on all packets.