Configuring DAI to Support Multi-VRF

DAI supports Multi-VRF. You can deploy multiple Virtual Routing and Forwarding instances (VRFs) on a RUCKUS Ethernet switch. Each VLAN having a Virtual Ethernet (VE) interface is assigned to a VRF.
You can enable DAI on individual VLANs and assign any interface as the ARP inspection trusted interface. If an interface is a tagged port in this VLAN, you can turn on the trusted port per VRF, so that traffic intended for other VRF VLANs will not be trusted.
  1. Enter global configuration mode using the configure terminal command.
    device# configure terminal
  2. Configure DAI on a VLAN.
    device(config)# ip arp inspection vlan 2
    This example configures DAI on VLAN 2.
  3. Add a static ARP inspection entry for a specific VRF.
    device(config)# vrf one-ipv4
  4. Add a static ARP inspection entry for the VRF.
    device(config-vrf-one-ipv4)# arp 5.5.5.5 00a2.bbaa.0033 inspection
    This example creates a static ARP inspection entry for the VRF named "one-ipv4."