Configuring an Inspection ARP Entry

Dynamic ARP inspection must be enabled to use static ARP inspection entries.
Static ARP and static inspection ARP entries must be configured for hosts on untrusted ports. Otherwise, when DAI checks ARP packets from these hosts against entries in the ARP table, it will not find any entries for them, and the RUCKUS device will not allow and learn ARP from an untrusted host.
  1. Enter global configuration mode.
    device# configure terminal
  2. Define the ARP inspection entry in the static ARP table by mapping a device IP address with its MAC address.
    device(config)# arp 10.20.20.12 0000.0002.0003 inspection
    The ARP entry will be moved to the ARP table once DAI receives a valid ARP packet.

The following example defines an inspection ARP entry in the static ARP table, specifies a device IP address 10.20.20.12 and MAC address 0000.0002.0003 pairing.

device# configure terminal
device(config)# arp 10.20.20.12 0000.0002.0003 inspection