---
title: "ANAPs"
canonical: "https://docs.aryaka.com/space/KNOW/1300856854/ANAPs"
format: markdown
---
The Aryaka Network Access Point (ANAP) can be deployed as a Layer 3 hardware device or as a virtual instance (V-ANAP) that is installed at a site. The physical device is managed by Aryaka and both the physical and virtual ANAPs perform the following operations: Create IPsec tunnels that connect the site to the Aryaka POP. Participate in TCP optimization and any additional optimization for which the site is configured. IP rule-based router functionality including NAT and source-based routing. Load balancing, criteria-based path selection, and loss recovery on outbound traffic. We recommend that you deploy an ANAP at each site unless it meets any of the following conditions: It is a third-party site or data center that does not allow installation of any new hardware (for example, a shared work space, a hosted space, or a third-party customer location). It is a public or private cloud instance (for example, AWS or Azure), or is a SaaS subscription. It has a high bandwidth requirement for site-to-site connectivity using Aryaka that is greater than what a single ANAP can support and you cannot use multiple ANAPs (also known as  stacking ). See the following topics for additional details on ANAPs and V-ANAPs: ANAP insertion topology ANAP configuration - Edge Routed Mode ANAP configuration - Inline Routed Mode ANAP configuration - Simple Routed Mode ANAP access guide ANAP security guide View ANAP devices Erase ANAP configuration Using fiber ports on the ANAP Using fiber ports with ANAP HA Virtual ANAP - AWS Virtual ANAP - Azure Virtual ANAP - uCPE