Enabling ARP Inspection Trust on a Port for a Nondefault VRF

Dynamic ARP inspection (DAI) trust can be enabled on a port for a nondefault VRF instance.

The default trust setting for a port is untrusted. For ports that are connected to host ports, leave the trust settings as untrusted. The following task enables dynamic ARP inspection trust for Ethernet interface 1/1/4 for VRF green.

  1. Enter global configuration mode.
    device# configure terminal
  2. Specify the interface to be configured in interface configuration mode.
    device(config)# interface ethernet 1/1/4
  3. Use the arp inspection trust command with the vrf keyword, specifying a VRF, to configure DAI trust on the interface for the specified VRF.
    device(config-if-e10000-1/1/4)# arp inspection trust vrf green

The following example enables DAI trust on Ethernet interface 1/1/4 for VRF green.

device# configure terminal
device(config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# arp inspection trust vrf green