# Terraform LTM provider - ICMP disabled on resulting VIPs

**URL:** <https://community.f5.com/t/terraform-ltm-provider-icmp-disabled-on-resulting-vips/76514>\
**Category:** Technical Forums\
**Tags:** terraform, big-ip-ltm\
**Created:** [September 8, 2025, 2:22pm UTC](https://community.f5.com/t/terraform-ltm-provider-icmp-disabled-on-resulting-vips/76514 "2025-09-08T14:22:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Scot\_Kreienkamp](https://avatars.discourse-cdn.com/v4/letter/s/f19dbf/32.png) [@Scot\_Kreienkamp](https://community.f5.com/u/Scot_Kreienkamp)\
**Post date:** [September 8, 2025, 2:22pm UTC](https://community.f5.com/t/terraform-ltm-provider-icmp-disabled-on-resulting-vips/76514/1 "2025-09-08T14:22:53Z")

</div>

Hello,

I recently started using the terraform provider to create my VIPs.&nbsp; It works great!&nbsp; It makes my life much easier and faster to create the non-prod environments and migrate those configs to prod.&nbsp; I’ve encountered one strange thing I’m struggling with though.&nbsp; I’m unable to ping the LTM VIPs.

The VIPs work perfectly other than we are unable to ICMP ping them.&nbsp; I hand-created a basic VIP in the same partition, on the same VLAN/Network, and I can ping it, so it’s not a routing or firewall problem.&nbsp; There’s no module other than LTM running on this F5, so there’s no firewall policies or anything like that in play.&nbsp; Just an&nbsp; standard LTM VIP with HTTP and client-SSL profiles.&nbsp; Nothing I create with terraform is pingable though. &nbsp;There are no policies or irules in use.&nbsp; On the virtual address list ICMP Echo is set to always, ARP is enabled, state is enabled.

Has anyone else encountered this?&nbsp; I searched the forums and didn’t find anything notable, and I haven’t been able to find a solution yet.&nbsp; Even comparing the config files from the F5 hasn’t produced anything notable.&nbsp; I’m sure it’s something small that I’m missing.

LTM VIP configuration (sanitized) is inline below.&nbsp; Thanks!

ltm virtual /partition/app1PD-CLL-HTTPS {  
&nbsp; &nbsp; description “server1, Terraform - Servicing the CLL”  
&nbsp; &nbsp; destination /partition/10.1.212.244:443  
&nbsp; &nbsp; ip-protocol tcp  
&nbsp; &nbsp; mask 255.255.255.255  
&nbsp; &nbsp; persist {  
&nbsp; &nbsp; &nbsp; &nbsp; /partition/Cookie-app1CLL {  
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default yes  
&nbsp; &nbsp; &nbsp; &nbsp; }  
&nbsp; &nbsp; }  
&nbsp; &nbsp; pool /partition/app1PD-CLL  
&nbsp; &nbsp; profiles {  
&nbsp; &nbsp; &nbsp; &nbsp; /partition/partition-HTTP-Weblogic-Proxy { }  
&nbsp; &nbsp; &nbsp; &nbsp; /partition/OC-255.255.255.255 { }  
&nbsp; &nbsp; &nbsp; &nbsp; /partition/server1 {  
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; context clientside  
&nbsp; &nbsp; &nbsp; &nbsp; }  
&nbsp; &nbsp; &nbsp; &nbsp; /Common/tcp { }  
&nbsp; &nbsp; }  
&nbsp; &nbsp; serverssl-use-sni disabled  
&nbsp; &nbsp; source 0.0.0.0/0  
&nbsp; &nbsp; source-address-translation {  
&nbsp; &nbsp; &nbsp; &nbsp; pool /partition/10.1.212.244  
&nbsp; &nbsp; &nbsp; &nbsp; type snat  
&nbsp; &nbsp; }  
&nbsp; &nbsp; translate-address enabled  
&nbsp; &nbsp; translate-port enabled  
}

---

<div class="post-metadata">

**Author:** ![Nikoolayy1](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/nikoolayy1/32/3589_2.png) [@Nikoolayy1](https://community.f5.com/u/Nikoolayy1)\
**Post date:** [September 9, 2025, 4:55am UTC](https://community.f5.com/t/terraform-ltm-provider-icmp-disabled-on-resulting-vips/76514/2 "2025-09-09T04:55:58Z")

</div>

If you are using Terraform without AS3 then maybe just modify the virtual address that the virtual server uses [bigip\_ltm\_virtual\_address | Resources | F5Networks/bigip | Terraform | Terraform Registry](https://registry.terraform.io/providers/F5Networks/bigip/latest/docs/resources/bigip_ltm_virtual_address)

If you are using Terraform with AS3 it could be AS3 issue with your version or new bug (use latest as3 and if needed open git case under [GitHub - F5Networks/f5-appsvcs-extension: F5 BIG-IP Application Services 3 Extension · GitHub](https://github.com/F5Networks/f5-appsvcs-extension) ). See [ARP of virtual address may show different property When Declare Virtual server via AS3](https://my.f5.com/manage/s/article/K000150779) as in as3 you can create a service address option and then with “virtualAddresses”: [{“use”: “test.virtual-address”}]," you can reference it in the Virtual server.

---

<div class="post-metadata">

**Author:** ![Scot\_Kreienkamp](https://avatars.discourse-cdn.com/v4/letter/s/f19dbf/32.png) [@Scot\_Kreienkamp](https://community.f5.com/u/Scot_Kreienkamp)\
**Post date:** [September 10, 2025, 2:11pm UTC](https://community.f5.com/t/terraform-ltm-provider-icmp-disabled-on-resulting-vips/76514/3 "2025-09-10T14:11:06Z")

</div>

Thanks @Nikoolayy1 , that was the clue.&nbsp; Even though it creates the virtual address automatically it apparently doesn’t do everything???&nbsp; Not sure why, it looks the exact same in the UI before and after.&nbsp; I had to terraform destroy what I had (because otherwise it already created it and won’t let me create it again), and add the virtual address creation before the VIP and automatic virtual address is created.&nbsp; Only then will it respond to ICMP.
