ACI | Network unreachable from APIC

Some days ago I had to configure a radius server on an APIC cluster. This server was addressed in the range and it worked well for the spines and leaves of the fabric but not for any APIC of the cluster. From the APIC, we had the “unreachable” faults:

From the CLI, the problem seemed more clear:

APIC1# bash
admin@APIC1:~> ping
PING ( 56(84) bytes of data.
From icmp_seq=1 Destination Host Unreachable
From icmp_seq=2 Destination Host Unreachable
From icmp_seq=3 Destination Host Unreachable
— ping statistics —
5 packets transmitted, 0 received, +3 errors, 100% packet loss, time 4090ms
pipe 4

admin@APIC1:~> traceroute
traceroute to (, 30 hops max, 60 byte packets
1 ( 3049.452 ms !H 3049.385 ms !H 3049.357 ms !H

The traceroute stopped at, not the out-of-band gateway configured.

admin@APIC1:~> route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default UG 16 0 0 oobmgmt UG 0 0 0 bond0.3914 UH 0 0 0 bond0.3914 U 0 0 0 oobmgmt U 0 0 0 teplo-1 U 0 0 0 lxcbr0 U 0 0 0 docker0

The radius servers where in the docker range of the APIC, so the docker route is preferred…. as explained in this enhancement request, a service cannot be reached by using the APIC out-of-band management that exists within the sub-net.


The solution is to change the Docker bridge-IP of the APIC, it can be performed from a simple API call (the most complicated action would be to find another /16 subnet available :) ). The detail of the API call is below, the script is replacing the default by another IP in the range :

POST {{apic-url}}/api/plgnhandler/mo/.xml

<?xml version=”1.0″ encoding=”UTF-8″?>


    <apContainerPol containerBip=”“/>



Be careful and change the internal network of the docker service before running under production if you have this internal subnet used on your data center network (even if the action of changing it is not impacting the production, we always prefer to spot and correct this kind of problem before).


Network engineer at CNS Communications. CCIE #47705, focused on R&S, Data Center, SD-WAN & Automation.

More Posts - Website

Follow Me:

Laisser un commentaire

Votre adresse de messagerie ne sera pas publiée. Les champs obligatoires sont indiqués avec *