# Link Load Balance A10 Thunder

**URL:** <https://community.a10networks.com/t/link-load-balance-a10-thunder/481>\
**Category:** ADC - Application Delivery\
**Tags:** nhld\
**Created:** [November 24, 2017, 6:21pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481 "2017-11-24T18:21:53Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![facevedo](https://avatars.discourse-cdn.com/v4/letter/f/8e8cbc/32.png) [@facevedo](https://community.a10networks.com/u/facevedo)\
**Post date:** [November 24, 2017, 6:21pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/1 "2017-11-24T18:21:53Z")

</div>

Hi Everyone!

I would like to know, what is the best form to make load balance on my A10 if i have 3 ISP links.

Example

LOCAL NET —\> Inside – A10 --Outside ----3 ISP links

i understand that is with a Wildcard VS, but i would like be sure of that.

Please if you can help me.

---

<div class="post-metadata">

**Author:** ![yannt](https://avatars.discourse-cdn.com/v4/letter/y/bcef8e/32.png) [@yannt](https://community.a10networks.com/u/yannt)\
**Post date:** [November 25, 2017, 8:12am UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/2 "2017-11-25T08:12:28Z")

</div>

Hi facevedo, This is correct, you should use a Wildcard VIP to catch the traffic destinated to Internet IPs. Please find below a “basic” config example working (ACOS 4.x or later)

```auto

vlan 150
 untagged ethernet 1
 router-interface ve 150
 name "Inside"
!
vlan 500
 untagged ethernet 2
 router-interface ve 500
 name "Outside_ISP_A"
!
vlan 501
 untagged ethernet 3
 router-interface ve 501
 name "Outside_ISP_B"
!
interface ve 150
 ip address 192.168.100.254
 ip allow-promiscuous-vip
!
interface ve 500
 ip address 10.10.0.1 255.255.255.0
!
interface ve 501
 ip address 10.10.1.1 255.255.255.0
!
interface ethernet 1
 enable
!
interface ethernet 2
 enable
!
interface ethernet 3
 enable
!
ip nat pool ISP_A 10.10.0.50 10.10.0.50 netmask /24 
!
ip nat pool ISP_B 10.10.1.50 10.10.1.50 netmask /24 
!
ip nat pool-group NAT_Internet 
  member ISP_A 
  member ISP_B 
!
slb server ISP_A 10.10.0.254
   port 0 tcp
       health-check-disable
   port 0 udp
       health-check-disable
!
slb server ISP_B 10.10.1.254
   port 0 tcp
       health-check-disable
   port 0 udp
       health-check-disable

slb service-group Internet_TCP tcp
    member ISP_A 0
    member ISP_B 0
!
slb service-group Internet_UDP udp
    member ISP_A 0
    member ISP_B 0
!
slb virtual-server VIP 0.0.0.0
   port 0 tcp
      source-nat pool NAT_Internet
      service-group Internet_TCP
      use-rcv-hop-for-resp
      no-dest-nat
   port 0 udp
      source-nat pool NAT_Internet
      service-group Internet_UDP
      use-rcv-hop-for-resp
      no-dest-nat
   port 0 others
      source-nat pool NAT_Internet
      service-group Internet_TCP
      use-rcv-hop-for-resp
      no-dest-nat

```

---

<div class="post-metadata">

**Author:** ![facevedo](https://avatars.discourse-cdn.com/v4/letter/f/8e8cbc/32.png) [@facevedo](https://community.a10networks.com/u/facevedo)\
**Post date:** [November 25, 2017, 2:23pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/3 "2017-11-25T14:23:31Z")

</div>

Hi, Thanks for your reply…

I have a question, what about the ICMP traffic that is outgoing to my network.

How can i permit that my LAN USER reach something on internit through ICMP…

EXAMPLE

LAN → A10 → ISP → TEST icmp 8.8.8.8

Maybe created another VS Type?

Best Regards!

Fabián A.

---

<div class="post-metadata">

**Author:** ![yannt](https://avatars.discourse-cdn.com/v4/letter/y/bcef8e/32.png) [@yannt](https://community.a10networks.com/u/yannt)\
**Post date:** [November 27, 2017, 7:34am UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/4 "2017-11-27T07:34:56Z")

</div>

Hi Fabian,

You have 3 types of Service configured under the Wildcard VIP : TCP/UDP/Others.  
ICMP traffic is managed through Others. With the given configuration, any type of traffic is Load Balanced across the 2 ISPs routers.

Regards,  
Yann

---

<div class="post-metadata">

**Author:** ![facevedo](https://avatars.discourse-cdn.com/v4/letter/f/8e8cbc/32.png) [@facevedo](https://community.a10networks.com/u/facevedo)\
**Post date:** [November 27, 2017, 4:37pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/5 "2017-11-27T16:37:58Z")

</div>

Thanks again Yantt, i did that and works good, however i have some troubles with the persistent connections…Particulary the destination persisten.

EXAMPLE User goes to internet —\> ISP IP 1 —\> SITE WWW Sometimes the replys on the websites goes to another IP

There are some recommended form to make this???

BEst Regards!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex002/uploads/a10_community/original/1X/bb9f186d33804d3044a0374e589f49fdf3be1328.png) [@system](https://community.a10networks.com/u/system)\
**Post date:** [November 27, 2017, 4:51pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/6 "2017-11-27T16:51:24Z")

</div>

Try to add persistence:  
!  
slb template persist source-ip src-ip-persist  
&nbsp;&nbsp;&nbsp;timeout 10  
!

```auto
slb template persist destination-ip LLB-persist-dest
   netmask 255.255.255.0

```

timeout 10  
!  
slb virtual-server LLB\_vip 0.0.0.0  
&nbsp;&nbsp;&nbsp;port 0 tcp

```auto
      name \_wildcard\_TCP\_65535
      source-nat pool ISP-NAT-Group 
      service-group sg\_pool-isp1-2-tcp
      use-rcv-hop-for-resp
      no-dest-nat
      ha-conn-mirror
      template persist destination-ip LLB-persist-dest

```

port 0 udp

```auto
      name \_wildcard\_UDP\_65535
      source-nat pool ISP-NAT-Group
      service-group sg\_pool-isp1-2-udp
      use-rcv-hop-for-resp

```

template udp vpn-ageout

```auto
      no-dest-nat
      template persist source-ip src-ip-persist

```

port 0 others

```auto
      name \_wildcard\_Others\_65535
      source-nat pool ISP-NAT-Group
      service-group sg\_pool-isp1-2
      use-rcv-hop-for-resp
      no-dest-nat
      template persist destination-ip LLB-persist-dest

```

port 21 ftp

```auto
      name \_wildcard\_FTP\_21
      source-nat pool ISP-NAT-Group

```

service-group ISP1

```auto
      use-rcv-hop-for-resp
      no-dest-nat
      ha-conn-mirror
      template persist destination-ip LLB-persist-dest

```

---

<div class="post-metadata">

**Author:** ![facevedo](https://avatars.discourse-cdn.com/v4/letter/f/8e8cbc/32.png) [@facevedo](https://community.a10networks.com/u/facevedo)\
**Post date:** [November 27, 2017, 5:15pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/7 "2017-11-27T17:15:17Z")

</div>

Thanks i do that, but im still with some troubles:

slb virtual-server wildcard-vip 0.0.0.0  
&nbsp;&nbsp;&nbsp; port 0 tcp

```auto
       name \_wildcard\_v4\_TCP\_0
       source-nat pool outbound-nat-group
       service-group outbound-tcp-links
       use-rcv-hop-for-resp

```

template tcp TCP-5

```auto
       no-dest-nat
       template persist destination-ip LLB-persist-dest

```

port 0 udp

```auto
       name \_wildcard\_v4\_UDP\_0
       source-nat pool outbound-nat-group
       service-group outbound-udp-links
       use-rcv-hop-for-resp use-src-ip-for-dst-persist
       no-dest-nat

```

port 0 others

```auto
       name \_wildcard\_v4\_Others\_0
       source-nat pool outbound-nat-group
       service-group outbound-tcp-links
       use-rcv-hop-for-resp use-src-ip-for-dst-persist
       no-dest-nat

```

I have 3 publics IPs:

```auto
example 100.100.100.100, 100.100.100.101 and 100.100.100.102

When i query a site www.example.com

```

On the session I can see that the Public IP from A10 changes, is like that does not keep the dst-persistence.

Regards!

---

<div class="post-metadata">

**Author:** ![yannt](https://avatars.discourse-cdn.com/v4/letter/y/bcef8e/32.png) [@yannt](https://community.a10networks.com/u/yannt)\
**Post date:** [November 28, 2017, 8:00am UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/8 "2017-11-28T08:00:18Z")

</div>

I’m not sure to understand where the issue is.

Using Persistence, means the A10 will forward the traffic through the SAME Gateway depending the persistence type (Per Client SRC IP or per Server DST IP). Persistence does not mean the A10 will always reuse the same SRC-NAT IP (if multiple IP in the same NAT Pool) for outgoing traffic through an ISP.

Can you please share your config for a full review ? Can you please also give more details about the behaviour you are seeing and what you are expecting ?

Thanks

---

<div class="post-metadata">

**Author:** ![facevedo](https://avatars.discourse-cdn.com/v4/letter/f/8e8cbc/32.png) [@facevedo](https://community.a10networks.com/u/facevedo)\
**Post date:** [November 29, 2017, 1:51pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/9 "2017-11-29T13:51:54Z")

</div>

Hi i proceed to attached the configuration file…  
Regards!

---

<div class="post-metadata">

**Author:** ![jserrano](https://avatars.discourse-cdn.com/v4/letter/j/a9a28c/32.png) [@jserrano](https://community.a10networks.com/u/jserrano)\
**Post date:** [November 29, 2017, 2:02pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/10 "2017-11-29T14:02:58Z")

</div>

Hi,  
Persistency just keep gateway consistency. If you also want to keep same source-nat ip then  
you need to add “clientip-sticky-nat” to the outbound virtual services (tcp, udp & others). From CLI guide:

Description Configure client stickiness for outbound NHLD. Syntax [no] clientip-sticky-nat Default Disabled Mode Virtual port Introduced in Release 2.7.0 Usage Sticky NAT for outbound Next Hop Load Distributor (NHLD) provides a virtual-port option to ensure the ACOS device always uses the same outbound link for a given client’s traffic. You can enable it on individual virtual ports. NOTE: The Sticky NAT option applies only to NHLD. The option does not apply to other features, such as SLB.

Regards

---

<div class="post-metadata">

**Author:** ![facevedo](https://avatars.discourse-cdn.com/v4/letter/f/8e8cbc/32.png) [@facevedo](https://community.a10networks.com/u/facevedo)\
**Post date:** [November 29, 2017, 2:22pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/11 "2017-11-29T14:22:13Z")

</div>

JSerrano…OK i understand that…I try now and will probe the behavior on the network… thanks! i will inform after the test.

---

<div class="post-metadata">

**Author:** ![facevedo](https://avatars.discourse-cdn.com/v4/letter/f/8e8cbc/32.png) [@facevedo](https://community.a10networks.com/u/facevedo)\
**Post date:** [December 4, 2017, 2:32pm UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/12 "2017-12-04T14:32:57Z")

</div>

Hi everyone, it’s works fine all…Thanks by your advices!

Regards!!

---

<div class="post-metadata">

**Author:** ![ianishar](https://avatars.discourse-cdn.com/v4/letter/i/b3f665/32.png) [@ianishar](https://community.a10networks.com/u/ianishar)\
**Post date:** [March 13, 2018, 3:44am UTC](https://community.a10networks.com/t/link-load-balance-a10-thunder/481/13 "2018-03-13T03:44:17Z")

</div>

hi facevedo,

can you upload your configuration ? i want to see.  
thanks
