You could be hitting the bug - CSCsg18176 (Catalyst 3750 and 3560 switches).
When dynamic ARP inspection is enabled and IP validation is disabled, the switch drops ARP requests that have a source address of 0.0.0.0. The workaround is to configure an ARP access control list (ACL) that permits IP packets with a source IP address of 0.0.0.0 (and any MAC) address) and apply the ARP ACL to the desired DAI VLANs.
Thaks for your reply and CSCsg18176 bug description. It may help in the future, but I am afraid it does not match my present case. My 3750 stack sudenly starts filtering well formed ARP responses, e.g.:
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...