IP Source Guard
You can use IP Source Guard (IPSG) together with Dynamic ARP Inspection (DAI) on untrusted ports.
The RUCKUS implementation of the IPSG technology supports configuration on a port and specific VLAN memberships on a port.
When IPSG is first enabled, only DHCP packets are allowed, while all other IP traffic is blocked. IP Source Guard allows IP traffic when the system learns valid IP addresses. The system learns of a valid IP address from DHCP snooping.
When a new IP source entry binding on the port is created or deleted, an access-list with a permit filter for the IP address is added or deleted. By default, if IPSG is enabled without any IP source binding on the port, an ACL that denies all IP traffic is loaded on the port.