After I enable DAI or IPSG on an interface, why can the interface still forward packets that do not match the binding table

If the dhcp snooping trusted command is run on the interface, the interface considers all packets to be valid and forwards all packets regardless of whether Dynamic ARP Inspection (DAI) or IP Source Guard (IPSG) is configured.

