Configuring Dynamic ARP Inspection on Multiple VLANs

Dynamic ARP Inspection (DAI) can be enabled on multiple VLANs using one command. The following task configures multiple VLANs and enables DAI on most of the configured VLANs using a single command.

Complete the following steps to configure DAI for multiple VLANs.

Note: DAI can be configured on a maximum of 511 VLANs.
  1. Enter global configuration mode.
    device# configure terminal
  2. Configure the port-based VLANs.
    device(config)# vlan 100 to 150
  3. Add port Ethernet 1/1/12 as a tagged port.
    device(config-mvlan-100-150)# tagged ethernet 1/1/12
  4. Use the exit command to return to global configuration mode.
    device(config-mvlan-100-150)# exit
  5. Configure more port-based VLANs.
    device(config)# vlan 151 to 200
  6. Add port Ethernet 1/1/12 as a tagged port.
    device(config-mvlan-151-200)# tagged ethernet 1/1/12
  7. Use the exit command to return to global configuration mode.
    device(config-mvlan-151-200)# exit
  8. Use the ip arp inspection command with the to keyword, specifying a VLAN range, to enable DAI on multiple VLANs.
    device(config)# ip arp inspection vlan 100 to 150 160 170 to 200
    The command enables DAI on VLANs 100 through 150, VLAN 160, and VLANs 170 through 200. ARP packets from untrusted ports in this VLAN range will undergo DAI.

    Note: The maximum number of VLANS that can be configured using the to keyword is 1024.

  9. Enable trust on any ports that will bypass DAI.
    1. To enable trust on a port, enter interface configuration mode.
      device(config)# interface ethernet 1/1/12
    2. Enable trust on the port.
      device(config-if-e10000-1/1/12)# arp inspection trust
  10. Enable DHCP snooping to populate the DHCP snooping IP-to-MAC address binding database. Refer to the RUCKUS FastIron DHCP Configuration Guide for more information.

The following example configures a DAI table entry, configures multiple VLANs, and enables DAI on most of the configured VLANS. Port 1/1/12 is designated as trusted.

device# configure terminal
device(config)# arp 10.20.20.12 0000.0002.0003 inspection
device(config)# vlan 100 to 150
device(config-mvlan-100-150)# tagged ethernet 1/1/12
device(config-mvlan-100-150)# exit
device(config)# vlan 151 to 200
device(config-mvlan-151-200)# tagged ethernet 1/1/12
device(config-mvlan-100-150)# exit
device(config)# ip arp inspection vlan 100 to 150 160 170 to 200
device(config)# interface ethernet 1/1/12
device(config-if-e10000-1/1/12)# arp inspection trust