aci_endpoint_trace
Trace an ACI endpoint's static fabric path from MAC or IP, revealing attachment, EPG, BD, VRF, contracts, and related faults.
Instructions
[READ] Reconstruct an ACI endpoint's static fabric path from its MAC or IP.
One call follows: endpoint → attachment (pod / leaf / interface or vPC) →
EPG → bridge domain → VRF → contracts the EPG provides/consumes → filter
entries, plus faults whose DN names the EPG or the attachment interface.
Every link is the relation APIC resolved (its tDn), so cross-tenant links
into 'common' are followed correctly.
How to read the result (do not over-state it):
* It is NOT a reachability test. 'staticPathResolved: true' means the
fabric is configured to carry the endpoint, not that traffic flows.
* 'relatedFaultCandidates' are matched by DN only — proximity, not cause.
Never report one as the reason for a problem. 'faults: null' means no
fault scan succeeded (related faults unknown, not none); 'complete:
false' means some scan failed, hit its page limit, or could not run.
* 'tagRelations' in state 'missing-target' are policy-tag lookups and say
nothing about the attachment path; do not report them as a path failure.
* A section that is null with an entry in 'errors' was NOT read — never
describe it as empty or absent. 'segmentResolved'/'staticPathResolved'
are null in that case, not false.
* A cleared fault keeps the description it had when raised; judge it by
severity/lifecycle, not by its text.
* 'contracts.complete: false' means a contract or filter was not read or
not returned (its entry says 'read: false', 'exists: false' or has
'entries: null') — its rules are unknown, not absent. The EPG → BD →
VRF verdict is unaffected.
* An 'epg' with 'supported: false' is a parent object this read does not
trace (e.g. an L2Out external EPG) — the chain is undetermined, not broken.
* 'notFound' means the fabric has not learned the address now, or it is in
a tenant this account cannot see — not that the host is down.
* 'notChecked' lists what this read does not evaluate (vzAny, taboo
contracts, imported contracts, preferred-group peers, service graphs).
Args:
mac: Endpoint MAC (any case; e.g. 00:50:56:AB:CD:EF). Pass mac OR ip.
ip: Endpoint IPv4/IPv6 address. Pass mac OR ip.
limit: Max matching endpoints to trace (default 5, max 20); the result
carries returned/limit/truncated.
fault_limit: Max related-fault candidates per endpoint (default 20).
target: Target name from config (must be 'platform: aci').
Returns dict: {query, endpoints:[{endpoint, ips, attachment, attachmentFormed,
tagRelations, epg, bd, vrf, contracts, segmentResolved, notChecked,
relatedFaultCandidates, staticPathResolved, findings:[{rank, severity,
signal, cause, action}], errors}], returned, limit, truncated,
serverReportedMatches, lookupErrors, note, notFound?}.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ip | No | ||
| mac | No | ||
| limit | No | ||
| target | No | ||
| fault_limit | No |