Hi CF,
Disabling the Gratuitous ARP Setting
By default, Cisco Unified IP Phones accept Gratuitous ARP packets. Gratuitous ARP packets, which devices use, announce the presence of the device on the network. However, attackers can use these packets to spoof a valid network device; for example, an attacker could send out a packet that claims to be the default router. If you choose to do so, you can disable Gratuitous ARP in the Phone Configuration window.
--------------------------------------------------------------------------------
Note Disabling this functionality does not prevent the phone from identifying its default router.
Cisco Unified CallManager Security Guide, Release 5.1(3)
Phone Hardening
http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/security/5_1_3/secu_ph.html
Hope this helps!
Rob