---
title: "Configure a Cisco Umbrella cloud connector"
canonical: "https://docs.aryaka.com/space/KNOW/1279197302/Configure%20a%20Cisco%20Umbrella%20cloud%20connector"
format: markdown
---
Aryaka enables you to connect your branch locations to Cisco Umbrella cloud service by providing a cloud-controlled SD-WAN solution that selectively forwards Internet traffic to the Cisco Umbrella cloud service using a secure IPSec tunnel. This deployment guide includes details on how to integrate an Aryaka site with the Cisco Umbrella cloud service.  The first section describes the configuration steps that must be performed on the Cisco Umbrella portal. The second section describes the steps that must be performed in MyAryaka. Note that the configuration steps are provided only for one Aryaka site. You must repeat the steps to integrate all of your Aryaka sites with Cisco Umbrella cloud service. This information is designed to be used in conjunction with the general configuration steps described in the  Configure cloud connectors  topic. It assumes the configuration is completed through the Basic Information pane on the Cloud Security Connector (Add) tab page at Sites >  siteName  > Cloud Security Vendors > Cloud Connector (Add). Solution Architecture This section provides a high-level solution overview of a sample deployment that includes two sites: Site A and Site B. An Aryaka Network Access Point (ANAP) device is deployed at each site. The ANAP is a branch edge device that is provided with your Aryaka SmartServices subscription. Site-to-site traffic originating from clients is optimized, accelerated, and encrypted before it is sent over a secure IPSec tunnel to the Aryaka global SD-WAN cloud. Internet-bound traffic is encrypted and sent over a secure IPSec tunnel to Cisco Umbrella where their security policies are applied. The following graphic illustrates the integrated architecture: Prerequisites Satisfy the following prerequisites before integrating Aryaka SmartServices with Cisco Umbrella: Aryaka SmartServices subscription License for Cisco Umbrella and access to the Umbrella portal Configure the Cloud Security Connector in Cisco Umbrella The cloud security connector configuration in Umbrella involves creating and configuring a tunnel, then associating it with an Aryaka site.  While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. To configure the connector in the Umbrella portal Log in to the Cisco Umbrella portal at  login.umbrella.com .   Click  Network Tunnels  in the left navigation pane. The list of configured tunnels appears. Click the blue  Add  icon to configure a new tunnel. The Add A New Tunnel screen appears. Enter a name your tunnel in the Tunnel Name field, preferably with the site name or code. Select  Other  from the Device Type drop-down list. Select the site that this tunnel belongs to from the Associate Tunnel with Site drop-down list (sites must have been added as described in  Map Tunnels to Sites  (at umbrella.com). The tunnel is created, and the Configure Tunnel pane appears. Enter the site's local subnets in the Configure Tunnel pane, then click  Add . The subnets you added appear below the text box. Configure a Tunnel ID and Passphrase: Click the  IP Address/Network  option in the Authentication Method field.  Enter the public IP address of your site in the Tunnel ID field. This is typically the M1/M2 IP address of your ANAP. Enter a string of your choice in the Passphrase field. Reenter the string in the Confirm Passphrase field. Click  Save . You are prompted to save your passphrase. Click  Done . The Network Tunnels list appears again. The status for the newly-added tunnel appears as Unestablished. Proceed to the next section to configure the ANAP with the cloud security connector in MyAryaka. MyAryaka Configuration Aryaka allows you to connect to a cloud security service using a cloud connector. Connector configuration can be done using MyAryaka or with the help of Aryaka’s technical support team. Before you can configure a Cisco Umbrella connector, you must add Cisco Umbrella as a network. To add Cisco Umbrella as a new network Log in to MyAryaka. The Home page appears. Click  SD-WAN  >  Connectivity  in left navigation pane. The Connectivity page appears. It displays a summary tile for each of the networks types included in your subscription.  Click the  Add  icon. The Cloud Security Vendor page appears with the Aryaka Certified tab page displayed by default. Click  Custom  to display the Custom tab page, then enter Cisco Umbrella in the Vendor Name field. Click  Submit . The following events occur: A message prompts you to confirm your request. Click  OK.  The custom or selected vendor's details page appears with no data in the Sites table. A summary tile for the Cisco Umbrella network appears on the Network page. Sites can now connect to the network as described in  Configure cloud connectors  and in the following procedure. To configure the Cisco Umbrella connector On the Cloud Security Connector (Add) tab page, ensure that  Basic  is selected (top right). In the Basic Information pane, verify the following: Click  Cisco Umbrella  in Vendor section. Because Cisco Umbrella is a custom vendor, the Custom Connector Like drop-down list appears. It is populated with the predefined (non-custom) connectors. Click the  Tunnel Type  drop-down list, then select VTI as the type of tunnel for the connector.  Ensure the  Enable IKEv2  field is set to Yes. Click  Add New  in the Tunnel Configurations pane. The Tunnel Configurations tab page appears. Configure the tunnel details as follows: Select the Tunnel Source Interface in the Tunnel Details section. This is the tunnel source IP address and is dependent on ANAP deployment mode: Select  LAN  if the ANAP is deployed in Simple Routed Mode. Select  M1  or  M2  IP addresses if ANAP is deployed in Edge or Inline Routed Mode Select  IP  from the Tunnel Destination Type drop-down list, then select an IP from the  IP address listed by Cisco Umbrella  as the primary public destination IP. Set the Shared Key to match what you configured on the Cisco Umbrella Portal. Click  OK . Click  Advanced  (top right), then modify Phase 1 and Phase 2 tunnel parameters as follows: Determine the routing mode of your ANAP device and how it impacts traffic forwarding: When an ANAP is in  simple routed mode , all traffic that is not destined for the Aryaka POP is routed to the Cisco Umbrella tunnels. If you want to forward only select traffic, you must create some form of policy-based routing in your upstream firewall or router. When an ANAP is in  edge routed mode  or  inline routed mode , you can control what traffic gets forwarded to Cisco in MyAryaka. Click the  Forward Traffic  toggle to configure traffic match criteria that, when matched, forwards traffic to the Cisco Umbrella connector. The following fields appear:  Forward Using—Drop-down list that includes the following options: Internet Policies—Select this if you want the ANAP to route those traffic to Cisco Umbrella that only reaches the public interfaces after all other routing decisions have been made on the traffic.  Local Policies—Select this if you want the ANAP to override all other routing decisions that could possibly make on that traffic. For example, traffic may be heading to ASN but you want to override that decision and send it to Cisco Umbrella. If Forward Fails—Drop-down list that includes the following options: Blackhole—Select this if you want the ANAP to silently discard the traffic and send no response back to the sender. Prohibit—Select this if you want to send a code 13 ICMP administratively prohibited message back to the sender. Policy Name table with Add New button—Click  Add New  to define a local or internet policy (depending on your selection in the Forward Using field), then provide the following details in the Policy (Add) page that appears: Name—Enter a descriptive policy name. Zone—Select the zone where the traffic originates. Match Rules—Set the toggle to  Explicit , click  Choose  in the Match Rules Details table that appears, and then select a preconfigured mach rule from the  Name  drop-down list that matches the traffic you want to forward to Cisco Umbrella. Click  Submit  to create a change request and send it to Aryaka support for processing. To view tunnel status in MyAryaka Click  SD-WAN  >  Status  in the top navigation pane, then click the site name where the Cisco Umbrella cloud security tunnel was configured. Click the  ANAP  tab. The connector type and status, tunnel status, and associated IPs appear in the Services table. To view tunnel status in the Umbrella portal Return to the Cisco Umbrella portal at  login.umbrella.com .   Click  Network Tunnels  in the left navigation pane. The list of configured tunnels appears. It includes the newly-configured tunnel with the Tunnel Status column set to Active: In this topic Related topics Configure cloud connectors Supported IPsec Parameters   (at  umbrella.com ) Map Tunnels to Sites   (at  umbrella.com )