Enabling IP Source Guard on a Multi-VRF instance

You can use IP Source Guard together with Dynamic ARP Inspection on untrusted ports.
Does this just apply to Layer 2 devices?
The RUCKUS implementation of IP Source Guard supports configuration on a port and on specific VLAN memberships on a port (Layer 2 devices only).
  1. Enter global configuration mode.
    device# configure terminal
  2. Enter interface configuration mode.
    device(config)# interface ethernet 1/1/1
  3. Configure IP Source Guard on a port.
    device(config-if-e1000-1/1/1)# source-guard enable
  4. Removing this step. Please confirm
    For Layer 3 devices, enable IP Source Guard on a virtual interface.
    device(config)# interface ve 30
    device(config-vif-30)# source-guard enable ethernet 1/1/1
  5. Manually enter valid IP addresses in the binding database.
    device(config)# ip source binding 1.1.1.2 ethernet 1/1/1 vlan 2
    If the VLAN ID is not provided, this setting will be applied on the port.