Enabling ARP Inspection Trust on a Port

Dynamic ARP inspection (DAI) trust can be enabled on a port.

The default trust setting for a port is untrusted. For ports that are connected to host ports, leave the trust settings as untrusted. If the port is part of a LAG, enable ARP inspection trust on the LAG virtual interface. The following task enables DAI inspection trust for Ethernet interface 1/1/4.

  1. Enter global configuration mode.
    device# configure terminal
  2. Specify the interface to be configured in interface configuration mode.
    device(config)# interface ethernet 1/1/4
  3. Use the arp inspection trust command to configure DAI trust for the interface.
    device(config-if-e10000-1/1/4)# arp inspection trust

The following example enables DAI trust for Ethernet interface 1/1/4.

device# configure terminal
device(config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# arp inspection trust