Enables dynamic ARP inspection (DAI) trust on a port.
Syntax
arp inspection trust
[
vrf
vrf-name
]
no arp inspection trust
[
vrf
vrf-name
]
Command Default
The default trust setting for a port is untrusted.
Parameters
- vrf
vrf-name
- Specifies a VRF instance.
Modes
Interface subtype configuration mode
Usage Guidelines
For ports that are connected to host ports, leave their trust settings as untrusted.
You can enable DAI on individual VLANs and assign any interface as the ARP inspection
trust interface. If an interface is a tagged port in this VLAN, you can turn on the
trust port per VRF, so that traffic intended for other VRF VLANs will not be trusted.
The
no form of the command disables dynamic ARP inspection trust on a port.
Examples
The following example enables dynamic ARP inspection trust on for an Ethernet interface.
device# configure terminal
device (config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# arp inspection trust
The following example enables dynamic ARP inspection trust on for an Ethernet interface
for VRF green.
device# configure terminal
device (config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# arp inspection trust vrf green