Actually as stated in the 6500 configuration guide:
PACL are indeed applied to routed traffic as well. I apologize if somewhere above I mentioned routed traffic is not affected by PACLs.
Thank you for your response, it was very helpful and thank you Alain for the inbound addition
As you explained, the IP Source Guard solution will not be complete without the DHCP snooping.
However, I forgot to mention that clients are assigned static IPs and since their mac address change a lot wouldn't you agree that PACL in this case require less administrative intervention and may be a better solution?
You can use IP Source Guard with hosts having static IPs.
Don't forget to rate helpful posts.
That is a very special scenario, I don't overseen a scenario where the same user with static ip address change its mac address oftenly. Now, as Alain mentioned, you can also configure Ip Source guard with static ip address configuration, which might involve adminitrative burden to the process but with better results. Anyways there are always different configurations to achieve the same result. I would stick with the IP source guard. Feel free to email me if you have further questions.