# Configure VIP

**URL:** <https://community.a10networks.com/t/configure-vip/871>\
**Category:** ADC - Application Delivery\
**Tags:** lacp, slb-adc, acos, virtual-server-vip, thunder-adc\
**Created:** [November 7, 2024, 6:58am UTC](https://community.a10networks.com/t/configure-vip/871 "2024-11-07T06:58:49Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vss\_D](https://avatars.discourse-cdn.com/v4/letter/v/ac91a4/32.png) [@Vss\_D](https://community.a10networks.com/u/Vss_D)\
**Post date:** [November 7, 2024, 6:58am UTC](https://community.a10networks.com/t/configure-vip/871/1 "2024-11-07T06:58:49Z")

</div>

Hi All,

I have a model with Trunk, VLAN, LACP configured on 2 ports connecting to 2 Firewall servers and clients. However, from A10 I can ping the server and client. From the client I can ping the VE on A10, but cannot ping the VIP.

Thanks

---

<div class="post-metadata">

**Author:** ![boteye](https://avatars.discourse-cdn.com/v4/letter/b/8797f3/32.png) [@boteye](https://community.a10networks.com/u/boteye)\
**Post date:** [November 7, 2024, 7:50am UTC](https://community.a10networks.com/t/configure-vip/871/2 "2024-11-07T07:50:15Z")

</div>

Can you check the VIP status? It will not respond if the virtual-server state is disabled.  
Can you share the packet capture on Thunder device?

---

<div class="post-metadata">

**Author:** ![boteye](https://avatars.discourse-cdn.com/v4/letter/b/8797f3/32.png) [@boteye](https://community.a10networks.com/u/boteye)\
**Post date:** [November 7, 2024, 7:56am UTC](https://community.a10networks.com/t/configure-vip/871/3 "2024-11-07T07:56:08Z")

</div>

#show slb virtual-server vs52 ← command to show virtual server status  
Virtual server: vs52 **State: Disb** IP: 10.x.x.52  
Port Curr-conn Total-conn Rev-Pkt Fwd-Pkt Peak-con  
Virtual Port:80 / service: / **state:Disb**

---

<div class="post-metadata">

**Author:** ![boteye](https://avatars.discourse-cdn.com/v4/letter/b/8797f3/32.png) [@boteye](https://community.a10networks.com/u/boteye)\
**Post date:** [November 7, 2024, 8:01am UTC](https://community.a10networks.com/t/configure-vip/871/4 "2024-11-07T08:01:57Z")

</div>

If you still see the issue please contact A10 Tech Support at: +1-888-822-7210

---

<div class="post-metadata">

**Author:** ![Vss\_D](https://avatars.discourse-cdn.com/v4/letter/v/ac91a4/32.png) [@Vss\_D](https://community.a10networks.com/u/Vss_D)\
**Post date:** [November 8, 2024, 8:41am UTC](https://community.a10networks.com/t/configure-vip/871/5 "2024-11-08T08:41:10Z")

</div>

Sorry boteye,

But the VIP have status enable

---

<div class="post-metadata">

**Author:** ![mdunn](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@mdunn](https://community.a10networks.com/u/mdunn)\
**Post date:** [November 8, 2024, 7:12pm UTC](https://community.a10networks.com/t/configure-vip/871/6 "2024-11-08T19:12:02Z")

</div>

If the VIP is enabled but the service-group members are down, then the VIP will not respond to ping. Can you share the output of “show slb virtual-server vip\_name”?

Another possibility is the VIP address is in a different subnet than the VE interfaces. If that is the case, does the backend server have a L3 route to the VIP address?

---

<div class="post-metadata">

**Author:** ![Vss\_D](https://avatars.discourse-cdn.com/v4/letter/v/ac91a4/32.png) [@Vss\_D](https://community.a10networks.com/u/Vss_D)\
**Post date:** [November 11, 2024, 1:59am UTC](https://community.a10networks.com/t/configure-vip/871/7 "2024-11-11T01:59:53Z")

</div>

Hi mdunn. Sorry for the late reply

I checked and all servers are up. - A10 is built in Inline mode (2 Arm). That means the 2 ends of A10 will configure 2 gateways to Firewall (Server VLan area 222) and Firewall (Client Vlan area 221). I have configured VE on these 2 areas in the same subnet (VLan 221:10.10.0.0/29 and Vlan 222: 10.10.0.8/29). My VIP is 10.10.0.5

ThankThanks

---

<div class="post-metadata">

**Author:** ![mdunn](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@mdunn](https://community.a10networks.com/u/mdunn)\
**Post date:** [November 12, 2024, 4:47pm UTC](https://community.a10networks.com/t/configure-vip/871/8 "2024-11-12T16:47:29Z")

</div>

Are there firewall rules blocking the traffic to the VIP address? Can you try to telnet or netcat to the VIP virtual port?

You can also try axdebug to perform TCPDUMP on the traffic. Create a filter for the VIP address or client and see what comes across:

axdebugfilter 1ip 10.10.0.5 /32exitfilter 2ip client.ip.address.here /32exitcapture brief

---

<div class="post-metadata">

**Author:** ![Vss\_D](https://avatars.discourse-cdn.com/v4/letter/v/ac91a4/32.png) [@Vss\_D](https://community.a10networks.com/u/Vss_D)\
**Post date:** [November 19, 2024, 9:34am UTC](https://community.a10networks.com/t/configure-vip/871/9 "2024-11-19T09:34:29Z")

</div>

Thanks

But I use the command ‘axdebug’ but I don’t see the capture. Checking the status, it says ‘axdebug is disabled’. Is there any way to enable axdebug?

---

<div class="post-metadata">

**Author:** ![mdunn](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@mdunn](https://community.a10networks.com/u/mdunn)\
**Post date:** [November 19, 2024, 5:09pm UTC](https://community.a10networks.com/t/configure-vip/871/10 "2024-11-19T17:09:03Z")

</div>

After configuring the filters, “capture brief” enables axdebug, starts the capture, and will display the packets on the screen. Alternatively, you can also save the capture to a file with packet display “capture brief save mypcap” or without packet display “capture save mypcap”.

 ![image.png](https://us1.discourse-cdn.com/flex002/uploads/a10_community/original/1X/f915bed4a841953a52cd176857b83fd809a07d63.png)

Can you share your output of the commands you entered or screenshot?
