Multi-VRF Support for DAI

DAI supports Multi-VRF instances. You can deploy multiple VRFs on a RUCKUS Ethernet switch. Each VLAN having a Virtual Ethernet (VE) interface is assigned to a Virtual Routing and Forwarding instances (VRFs).

You can enable DAI on individual VLANs and assign any interface as the ARP inspection trust interface. If an interface is a tagged port in this VLAN, you can turn on the trust port per VRF, so that traffic intended for other VRF VLANs will not be trusted.

Note: ICX 7150 devices do not support VRFs.

Complete the following steps to configure DAI to support a VRF instance.

  1. Configure DAI on a VLAN using the ip arp inspection vlan vlan-id command.
    device(config)# ip arp inspection vlan 2
  2. Add a static ARP inspection entry for a specific VRF instance.
    device(config-vrf-one-ipv4)# arp 5.5.5.5 00a2.bbaa.0033 inspection