---
title: "ANAP insertion topology"
canonical: "https://docs.aryaka.com/space/KNOW/1299808557/ANAP%20insertion%20topology"
format: markdown
---
This document introduces the Aryaka Network Access Point (ANAP) device and describes the various modes in which the ANAP can be installed and the insertion models that can be deployed for each of your sites. For instructions on how to include ANAP configuration details when adding a new site in MyAryaka, see the  Configure ANAP information  help topic.  Aryaka ships an appropriate ANAP model depending on the bandwidth requirements of your site. The various ANAP models differ slightly, so your ANAP device may look a little different from the images and descriptions in the document. ANAP device The ANAP is used to configure tunnels between the ANAP and the Aryaka POP and provide bandwidth scaling, compression, data deduplication, and other optimization benefits. The ANAP device is provisioned and managed by Aryaka. The following graphic displays the front and panel of the ANAP: The following graphic displays the rear panel of the ANAP:          High availability The ANAP supports device-level redundancy for all insertion modes and can be deployed in high availability (HA) mode as follows:  Only two ANAPs are supported in this mode: the  active ANAP  and the  standby ANAP , which becomes active in the case of connection loss. The standby ANAP synchronizes its configuration and software from the active ANAP. Load balancing is  not  part of HA (this is strictly an active/standby model). ANAP insertion modes The following insertion modes are available when deploying your ANAP: Simple routed mode Edge routed mode Inline routed mode They are described in the sections that follow. Simple routed mode In this insertion mode, the ANAP is connected to a L3 device and the traffic that needs to be optimized is routed to the ANAP using static routes, RIP, or BGP routing protocols. The ANAP establishes redundant route-based VPN tunnels (SVTI) to the POP allowing the ANAP to accelerate, compress, and encrypt all traffic routed through the device. Additionally, the ANAP establishes a backup SVTI to all other ANAPs which are used in the event of any POP failures. Simple routed mode can be deployed with or without HA failover as shown in the follow graphics. Aryaka recommends connecting the ANAP to a different LAN network to avoid ICMP redirect issues. Edge routed mode In this insertion mode, the ANAP is deployed as the internet-facing gateway and uses ports M1 and M2. In addition to terminating the IPSec tunnel from the Aryaka POP, an ANAP in this mode can have any or all of the following features enabled at a site: Act as a stateful firewall Ability to NAT Police and shape internet traffic Perform source-based routing An ANAP in this mode has default outbound source NAT applied on the internet-facing interfaces and does not allow traffic from the internet to get routed to the LAN unless a corresponding NAT rule or flow is available. There are two installation modes available for edge routed ANAPs: single-homed gateway or dual-homed gateway. Edge routed ANAP as single-homed internet gateway In this installation mode, the ANAP’s M1 or M2 port connects to the ISP link. The VPN traffic from the ANAP traveling to the Aryaka POP and the internet traffic from the LAN passes over the single ISP link connecting to M1/M2 port. Edge routed mode with a single-homed gateway can be deployed with or without HA failover as shown in the follow graphics. ANAP as single ISP internet gateway ANAP as single ISP internet gateway with HA Edge routed ANAP as dual-homed internet gateway In this installation mode, the ANAP’s M1 and M2 ports are connected to two different ISP links. IP SLA is configured to decide which ISP is used for internet traffic based on link health. Edge routed mode with a dual-homed gateway can be deployed with or without HA failover as shown in the follow graphics. ANAP edge routed mode as dual ISP internet gateway       ANAP edge routed mode as dual ISP internet gateway with HA Inline routed mode This insertion model is similar to edge routed mode, except inline routed mode places the ANAP behind a firewall, which means NAT and firewalling capabilities are performed by the firewall before before traffic arrives at the ANAP. Note that because the ANAP does not provide firewalling, all incoming packets are forwarded to its LAN gateway. In this mode, the ANAP does  not  have default NAT rules configured, but NAT rules can still be configured on ANAP.  Aryaka recommends not configuring any NAT rules on the ANAP in this mode. Inline routed mode with the ANAP deployed behind a firewall is shown in the follow graphic. ANAP inline routed mode behind a firewall In this topic Related topics Configure ANAP information ANAP configuration - Edge Routed Mode ANAP configuration - Inline Routed Mode ANAP configuration - Simple Routed Mode ANAP security guide