---
title: "Virtual ANAP - uCPE"
canonical: "https://docs.aryaka.com/space/KNOW/1299775528/Virtual%20ANAP%20-%20uCPE"
format: markdown
---
A virtual ANAP (V-ANAP) is a virtual form factor that is deployed similarly to a physical ANAP device, except it is hosted in an infrastructure as a service (IaaS) environment ( AWS  or  Azure ) or on a standalone physical Intel-based x86 computer running a Linux or kernel-based virtual machine (KVM) platform as a  universal customer premises equipment  (uCPE) deployment. uCPE is a physical server or a hardware device that can virtualize multiple network functions—you can have a server on which you can have multiple virtual machines that can emulate an appliance or any network function. This removes the need for one or more vendor-specific hardware devices. Prerequisites Ensure the following prerequisites are satisfied before provisioning uCPE with a V-ANAP: A site license from Aryaka to deploy a V-ANAP. Host requirements: Processor must be x86 architecture Operating system must be Rocky Linux 9.x. A hypervisor and a kernel-based virtual machine (KVM). The ability to dynamically assign an IP using DHCP for the virtual ANAP's M1/M2 interface. If possible, follow these additional recommendations: Create a separate partition for V-ANAP on the host machine. If this is not possible, RAW partition can be used. Use SSD storage for deployment. Supported V-ANAP insertion topology Edge routed mode (ERM) is the only insertion topology supported for V-ANAP deployment at a site. For detailed information, see the following topics: ANAP insertion topology ANAP configuration - Edge Routed Mode V-ANAP responsibility chart Aryaka shares the configuration, management, and operation of the V-ANAP in AWS as follows. V-ANAP Responsibility Aryaka Customer Host server hardware and maintenance. Host operating system. Installation and management of the KVM hypervisor. Bringing up the V-ANAP instance on the host server.   Configuring all of the ANAP interfaces on the hypervisor in the order specified in this document. If any interface is not configured or provisioned in the correct order, it can negatively impact the V-ANAP functionality.   Allocating the required resources for the V-ANAP.   Any process crash in host machine Sharing the V-ANAP image in QCOW2 (zipped) format with the customer.   Provisioning the site.   Maintaining all V-ANAP configuration.   Resolving any issues that arise with the V-ANAP software.   Technical specifications The following table lists the supported interfaces and hardware resources that are required by the V-ANAP. V-ANAP Model Equivalent Physical ANAP Model Site License Interfaces Resources Required CPUs  Memory (GB) Disk (GB) ANAP-6150 ANAP-1500 Small MGMT LAN M1 M2 4 8 128 ANAP-6250 ANAP-2500 Medium MGMT LAN M1 M2 WAN 4 8 256 ANAP-6300 ANAP-3000 Large MGMT LAN M1 M2 WAN 8 32 512 Provision a new site with a V-ANAP Complete the following steps in order to provision a new site to use a virtual ANAP. Step 1 - Install Rocky Linux on the host computer Complete the following steps to install Rocky Linux 9.x. Download the Rocky Linux 9.x ISO image from the Rocky Linux website ( https://rockylinux.org/download ) to a USB drive. Install from the USB drive: Download USB boot creator software such as Rufus or Universal USB Installer (for Windows). Boot the system from the bootable drive and select the Install Rocky Linux 9.x option. Install the OS. During the installation, create the partition required for V-ANAP. The partition size should defined in GBs and be based on the site license.  Virtual-Small: 128GB Virtual-Medium: 256GB Define the swap size depending on your system's RAM as described in  https://opensource.com/article/18/9/swap-space-linux-systems . Note that /home is not a required partition and can be deleted to free up disk space. Configure the IP to manage the host machine. After the installation completes, remove the drive and boot up the system. Step 2 - Download, install, and configure the required packages and services Complete the following steps to download, install, and verify that the required packages are available to the operating system. At the time of publication, the libvirt-5.0.0 download package dated 2019-01-17 09:01 was the most recent available. Always download and install the most recent version supported by your operating system. Download the most recent libvert packages (for example, libvirt-5.0.0-1.el7.x86_64.rpm) from  http://mirror.centos.org/centos/7/virt/x86_64/libvirt-latest/ . Install the following packages: yum install -y libvirt
yum install -y virt-manager
yum install -y virt-install
yum install -y virt-viewer
yum install -y libguestfs-tools (optional) Run the  rpm -qa  command to verify these packages are installed: qemu-kvm
qemu-img
virt-viewer
virt-install
virt-manager
libvirt-client
libvirt-daemon You can list all of the packages using the following command: 'rpm -q -a --qf '%{NAME}\n' | grep -iE 'qemu-kvm|qemu-img|virt-viewer|virt-install|virt-manager|libvirt-client|libvirt-daemon' Start the  libvirtd.service  service as follows: systemctl enable libvirtd.service
systemctl start libvirtd.service Verify that the  libvirtd.service  is running as follows: systemctl status libvirtd.service (Optional) Enable the cockpit GUI to manage the virtual machines on the host. Enable cockpit: systemctl enable --now cockpit.socket Verify that cockpit is running: systemctl status cockpit.socket In a web browser, enter https:// <hostMachine IP> :9090 to access the cockpit UI on the host system using an HTTPS connection on port 9090. If the UI is not accessible, ensure the following firewall rules are added: sudo firewall-cmd --permanent --zone=public --add-service=cockpi
sudo firewall-cmd --reload Update the packages as follows: sudo yum update -y Step 3 - Download the V-ANAP image from MyAryaka. Log in to MyAryaka and  create a site  as described in the linked help topic. On the Site Information page, in the Site Details pane, click  VANAP Image and Details . The V-ANAP Image and Details dialog appears. It contains a Download link and displays the resources required for the V-ANAP. Ensure the requirements are met, then click  Download . The V-ANAP image download begins. Note the following about the image file: qcow2 format (zipped) Image size is approximately 4.2GB (the zipped image size is 250MB) File name is similar to VANAP-4.6.0.7-34147.el7.qcow2 You will complete the site creation procedure in step 6 later in this document. Continue to Step 4 now. Step 4 - Configure the KVM Complete the following steps to configure the virtual machine. Locate or create a storage pool: Run the following command to list the current storage pools: virsh pool-list Use the pool named  default  if it exists, or create it or a custom pool as follows: mkdir /var/lib/libvirt/images
virsh pool-define-as --name default --type dir --target /var/lib/libvirt/images
virsh pool-autostart default
virsh pool-start default
virsh pool-list Set the Default uniform resource identifier (URI): To take advantage of the networking features in libvirt, connect to a system driver as follows: export LIBVIRT_DEFAULT_URI="qemu:///system" Verify that the environment variables are set as follows: echo $LIBVIRT_DEFAULT_URI Create a storage volume: Create a 4GB storage volume in qcow2 format in the default storage pool or the custom one that you created: virsh vol-create-as default VANAP-cf.qcow2 4G --format qcow2 Verify whether the storage volume is created as follows: virsh vol-list --pool default Upload the V-ANAP image: Upload the V-ANAP image that was downloaded from MyAryaka (Step 3 - Download the V-ANAP image from MyAryaka). virsh vol-upload --pool default VANAP-cf.qcow2 /root/<image_name>

Sample image name - VANAP-4.6.0.9-33099.el7.qcow2 Verify that the image is uploaded as follows: virsh vol-info --pool default VANAP-cf.qcow2 Step 5 - Identify the interface configuration requirements There are three different ways in which an V-ANAP interface can be associated to a host interface: Type 1—The physical interface of the host machine is dedicated to an interface of the V-ANAP. Type 2—The VLAN sub-interface can be created on the host machine and each sub-interface can be associated to a V-ANAP interface. Type 3—If the host machine's interface and V-ANAP's interface are expected to use IPs from the same subnet, you can create a  private bridge . These interface types are depicted and described in the sections that follow. It is also important to know that the V-ANAP interfaces called against each license type must be configured whether they are being used or not, and the sequence defined in the Required Resources table must be followed. Type 1- Physical interface of a host machine is dedicated to an interface of the V-ANAP In this case, the LAN of the V-ANAP is directly connected to the eno1 interface of the host server. Type 2 - VLAN sub-interface can be created on the host machine and each sub-interface can be associated to a V-ANAP interface. In this case, M1 of the V-ANAP is connected to sub-interface eno03.116 which has VLAN 116. Similarly, M2 of the V-ANAP is connected to sub-interface eno3.117 which has VLAN 117. Both of the sub-interfaces are created on host interface eno3. eno3—Represents the host's physical interface on which the sub-interface must be created. eno3.116—Represents the sub-interface name.  Run the following command to associate the VLAN's sub-interfaces to the host's physical interface: Sample for creating a sub interface on host ip link add link eno3 name eno3.116 type vlan id 116
ip link set eno3.116 up
ip addr flush dev eno3.116 Type 3 - If the host machine's interface and V-ANAP's interface are expected to use IPs from the same subnet, a  private bridge  can be created An ideal use case for this configuration is to have the the V-ANAP's management interface and the host management interface in the same subnet and accessible over the same physical interface of the host. IP address 172.17.100.110 is used by the host server and is accessible over the interface eno2. IP address 172.17.100.120 is used by the V-ANAP's management interface, which is also accessible using a bridge (mgmtbr) on the eno2 physical interface. Run the following command to create a private bridge: Sample for creating a bridge ip link add mgmtbr type bridge
ip link set mgmtbr up
ip addr add 172.17.100.110/24 dev mgmtbr
ip link set eno2 up
ip link set eno2 master mgmtbr
ip addr flush dev eno1
ip route replace default via 172.17.100.1 Configuration Parameters The following configuration parameters are used for VM creation. Parameter Example Description Name VANAP-<site_name> Name of the V-ANAP instance. OS variant rhel8 Specifes the host's operating system. Memory 8192 Memory allocated for the VM. VCPUs 4 Number of CPUs allocated for the VM. Boot hd Location from where the image has to be booted. Sound None disk "vol=default/VANAP-cf.qcow2,boot_order=1,bus=sata" Call the storage volume that was created. disk "path=/dev/dm-2" Partition on which the VM has to be installed. If you are using a raw disk, use: vol=default/${name}-ssd.raw  Defining Interfaces --network bridge mgmtbr Management Interface of the ANAP is bridged and the bridge name is called. --network type direct, source=eno2 direct,source=eno3.116 direct,source=eno3.216  Associated directly to the physical interface eno2 of the host. Associated to sub-interface eno3.116 of the host. Associated to sub-interface eno3.126 of the host. Step 6 - Install the V-ANAP instance Using the listed configuration parameters, bring up the V-ANAP using the virt-install command* as follows: virsh install virt-install --name <> --noautoconsole --input keyboard --os-variant <> --memory <> --vcpus <> --boot hd --sound none --disk "<>" --disk "<>" --network bridge=<> --network type=<>,source=<>,trustGuestRxFilters='yes' --network type=<>,source=<>,trustGuestRxFilters='yes' --network type=<>,source=<>,trustGuestRxFilters='yes'  * Replace each <> with the corresponding value from your V-ANAP configuration. --network defines each interface of the VM. The order of the interfaces defined here defines the mapping of V-ANAP interfaces based on the sequence mentioned in the Required Resources table. Sample Installation The following example is for a V-ANAP installation with license type as Virtual-Medium. The command uses the configuration parameters from the table that follows it. Sample virt-install executed for a Medium VANAP virt-install --name "VANAP" --noautoconsole --input keyboard --os-variant rhel8 --memory 32768 --vcpus 8 --boot hd --sound none --disk "vol=default/VANAP-cf.qcow2,boot_order=1,bus=sata" --disk "path=/dev/dm-3" --network bridge=mgmtbr --network type=direct,source=eno2,trustGuestRxFilters='yes' --network type=direct,source=eno3.116,trustGuestRxFilters='yes' --network type=direct,source=eno3.216,trustGuestRxFilters='yes' --network type=direct,source=eno4.10 Parameter Value Defined Description Name VANAP Name of the V-ANAP instance OS variant rhel9 The host’s operating system Memory 8192 32 GiB vCPU 4 Number of CPUs disk "vol=default/V-ANAP-cf.qcow2,boot_order=1,bus=sata" Call the storage volume disk "path=/dev/dm-3" Location of the disk Interfaces Required MGMT LAN M1 M2 WAN MGMT - --network bridge=mgmtbr LAN - --network type=direct,source=eno2,trustGuestRxFilters='yes' M1 - --network type=direct,source=eno3.116,trustGuestRxFilters='yes' M2 - --network type=direct,source=eno3.216,trustGuestRxFilters='yes' WAN - --network type=direct,source=eno4.10 Step 7 - Complete Site Configuration You must complete the site configuration in MyAryaka, but before doing so, you must obtain the V-ANAP's UUID from the command line on the host server. Log into the host server then run the following command to display the VM's UUID. virsh dominfo --domain <name> Note the UUID, you need it to complete the site configuration in MyAryaka. Continue the site configuration in MyAryaka from the point stopped in Step 3 - Download the V-ANAP image from MyAryaka (after downloading the V-ANAP image file) as described in  Create a site . On the ANAP Info page: Ensure the VANAP Platform field is set to UCPE-KVM.   Enter your VM Instance ID in the VM1 UUID field. Select DHCP to ensure the ANAP's M1 and M2 (primary and secondary) interfaces get a dynamic IP. Submit the order. After the order is processed by Aryaka's provisioning team, the site's status appears as Configured on the MyAryaka Sites page. Ensure the tunnel's status is Up in the Tunnel Status pane on the SD-WAN > Status >  siteName  page: Configure routing  as described in the linked help topic. Configure advanced settings  as described in the linked help topic. Caveats The following are not supported on V-ANAPs: High availability (HA). Network function virtualization (NFV) firewall. Fiber ports (because the interfaces are virtual). Interface speed and duplex configuration cannot be controlled on a V-ANAP. Note the following about modifying your configuration: An existing site with a physical ANAP cannot be migrated to a V-ANAP. Changing the site license associated with the V-ANAP requires updating the site’s configuration. If the site license changes, the ANAP model is updated and an appropriate serial number is allocated to V-ANAP. This is effectively the same as provisioning a new ANAP for the site. To change the site license of an ANAP, or to move a V-ANAP to a new host, follow the procedure in the next section. Note the following about adding or removing an interface on the host: Deletion or addition of an interface on the host does not require the V-ANAP to be rebooted. If there are 5 interfaces (from 1 to 5) on the host machine, and each interface is associated to ANAP interfaces in the order MGMT, LAN, M1, M2, WAN, if interface number 3 is deleted from the host, it will result in the last interface (WAN) of the ANAP being removed. Change the site license of an existing V-ANAP site or move the V-ANAP from one host to another To change the site license for an existing site with a V-ANAP deployed requires you to provision a new V-ANAP. The existing site configuration in MyAryaka remains, but now also includes a new VM instance. If you want to operate the V-ANAP on a different host server or device, you must provision a new V-ANAP instance on the new host server. Note that a maintenance window—and corresponding downtime—is required while the new V-ANAP instance is provisioned by Aryaka support. Prerequisites Obtain the new virtual site license from Aryaka (only if you are changing the site license). Satisfy the required resources for the new V-ANAP described in the Required Resources table. To change the virtual site license  Perform the following steps during maintenance window: Download the new V-ANAP image as described in Step 3 - Download the V-ANAP image from MyAryaka.  (Optional) Delete the old instance. Bring up the new V-ANAP instance. Obtain the VM UUID from the host machine as described in Step 7.1 - Complete site configuration. Log in to MyAryaka, go to Site >  siteName , edit the site configuration to include the new site license and VM UUID. Submit the order. Aryaka support processes the order: They delete the configuration of the old V-ANAP instance. They provision the new V-ANAP with the configuration from the Aryaka provisioning servers. After the order is processed, the status is updated in the following MyAryaka pages: Site status appears as Configured on the Sites page. Tunnel (from the new V-ANAP to the POP) status appears as Up on the SD-WAN > Status >  siteName  page.  In this topic Related topics Virtual ANAP - AWS Virtual ANAP - Azure