---
title: "Virtual ANAP - Azure"
canonical: "https://docs.aryaka.com/space/KNOW/1299972263/Virtual%20ANAP%20-%20Azure"
format: markdown
---
A virtual ANAP (V-ANAP) is a virtual form factor that is deployed similarly to a physical ANAP device, except it is hosted in an infrastructure as a service (IaaS) environment or on a  uCPE . Currently, the only supported IaaS environments are  Amazon Web Services (AWS)  and Azure IaaS. Prerequisites Ensure the following prerequisites are satisfied before you provision a V-ANAP in Azure: A site license from Aryaka to deploy a V-ANAP. An Azure subscription. A public IP for the V-ANAP's M1/M2 interface. Supported V-ANAP insertion topology Edge routed mode (ERM) is the only insertion topology supported for V-ANAP deployment at a site. For detailed information, see the following topics: ANAP insertion topology ANAP configuration - Edge Routed Mode V-ANAP responsibility chart Aryaka shares the configuration, management, and operation of the V-ANAP in AWS as follows. V-ANAP Responsibility Aryaka Customer Bringing up the V-ANAP instance.   Configuring all of the ANAP interfaces on the hypervisor in the order specified in this document. If any interface is not configured or provisioned in the correct order, it can negatively impact the V-ANAP functionality.   Allocating the required resources for the V-ANAP.   Virtual network subnet management and routing. Ensure the routing is configured with the traffic path always being symmetric.   Have the network security group configured to allow SSH traffic on port 2222, and to allow ICMP and tunnel traffic from the Aryaka POP.   Sharing the V-ANAP image.   Provisioning the site and V-ANAP.   Maintaining all V-ANAP configuration.   Resolving any issues that arise with the V-ANAP software.   Technical specifications The following table lists the interfaces and Azure instance types that are supported by the V-ANAP. V-ANAP Model Equivalent Physical ANAP Model Site License Interfaces Supported Azure Instance Size (CPU/Memory/SSD)  ANAP-8150 ANAP-1500 Small LAN M1 M2 DMZ Standard_D4ds_v5 (4/16G/150G) ANAP-8250 ANAP-2500 Medium LAN M1 M2 DMZ Standard_D8ds_v5 (8/32G/300G) ANAP-8300 ANAP-3000 Large LAN M1 M2 DMZ Standard_D16ds_v5 (16/64G/600G) If you want to repurpose the DMZ interface as an additional LAN interface,  contact Support  to enable this functionality. Caveats The following are not supported on V-ANAPs: High availability (HA). Network function virtualization (NFV) firewall. Fiber ports (because the interfaces are virtual). Azure ExpressRoute connectivity service. Interface speed and duplex configuration cannot be controlled on a V-ANAP. Note the following about modifying your Aryaka configuration: An existing site with a physical ANAP cannot be migrated to a V-ANAP. Changing the site license associated with the V-ANAP requires updating the site’s configuration. If the site license changes, the ANAP model is updated and an appropriate serial number is allocated to V-ANAP. This is effectively the same as provisioning a new ANAP for the site. Note the following about modifying your Azure configuration: You cannot move a V-ANAP instance. If you need to move to another instance, repeat the installation and configuration process to instantiate a new V-ANAP. Provision a new site with a V-ANAP Complete the following steps in order to provision a new site to use a virtual ANAP. Step 1 - Respond to Aryaka support's request for your account ID Your organization's designated technical contact will be contacted by Aryaka customer support requesting that you share the Azure account ID. Respond to them with the Azure account ID that they can use to share the V-ANAP image required in Step 3. Step 2 - Prepare the required Azure components In the Azure dashboard, create a new virtual network under the desired region. Add the following subnets under the new virtual network that you created: One subnet for the LAN One subnet for the V-ANAP's M1 interface (Optional) Additional subnets for M2 and DMZ Create a network security group if required. Step 3 - Create the V-ANAP in Azure In the Azure dashboard, locate the V-ANAP image under Azure Compute Gallery. Launch the V-ANAP Instance: Select the  instance type for your V-ANAP. The supported instances are listed in the Required resources table. Configure the following instance and network Interfaces: eth0—LAN interface of the V-ANAP. Select the subnet created for the LAN interface of the V-ANAP. You can either allow Azure to assign an IP or manually configure an IP. The IP must be static. eth1—M1 interface of the V-ANAP. Add this second required interface, and enable a public IP for it. M2 and DMZ—Optionally, you can configure one or both of these interfaces. Add SSD storage for this instance type. No additional configuration is required. Add tags if they are required. Select an appropriate security group and ensure inbound traffic is allowed to the V-ANAP. Aryaka support provides the POP's IPs that are required for the inbound connections for the V-ANAP's M1 interface. Review the configuration and launch the instance. For SSH, select an existing key pair or create a new one. Enable IP Forwarding for all interfaces of the VM. Take a screen capture of the completed VM Overview page and send it to  support@aryaka.com . Step 4 - Create a new site Log in to MyAryaka and  create a site  as described in the linked help topic. Ensure you make the following V-ANAP-specific entries and selections during the site configuration: On the Site Information page, select your site license in the Site License Type field. On the ANAP Info page: Ensure the VANAP Platform field is set to Azure. Enter your VM Instance ID. The VM Instance ID can be obtained from the JSON View on the VM's Overview tab in the Azure Portal (in the JSON View, the field name is VmId). Submit the order. After the order is processed, the site's status appears as Configured on the MyAryaka Sites page. Ensure the tunnel's status is Up in the Tunnel Status pane on the SD-WAN > Status >  siteName  page. Configure routing  as described in the linked help topic. Configure advanced settings  as described in the linked help topic. In this topic Related topics Virtual ANAP - uCPE Virtual ANAP - AWS