arp inspection trust

Enables dynamic ARP inspection (DAI) trust on a port.
Syntax
arp inspection trust [ vrf vrf-name ]
no arp inspection trust [ vrf vrf-name ]
Command Default

The default trust setting for a port is untrusted.

Parameters
vrf vrf-name
Specifies a VRF instance.
Modes

Interface subtype configuration mode

Usage Guidelines

For ports that are connected to host ports, leave their trust settings as untrusted.

You can enable DAI on individual VLANs and assign any interface as the ARP inspection trust interface. If an interface is a tagged port in this VLAN, you can turn on the trust port per VRF, so that traffic intended for other VRF VLANs will not be trusted.

The no form of the command disables dynamic ARP inspection trust on a port.

Examples

The following example enables dynamic ARP inspection trust on for an Ethernet interface.

device# configure terminal
device (config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# arp inspection trust

The following example enables dynamic ARP inspection trust on for an Ethernet interface for VRF green.

device# configure terminal
device (config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# arp inspection trust vrf green