---
title: "Virtual ANAP - AWS"
canonical: "https://docs.aryaka.com/space/KNOW/1300922393/Virtual%20ANAP%20-%20AWS"
format: markdown
---
A virtual ANAP (V-ANAP) is a virtual form factor that is deployed similarly to a physical ANAP device, except it is hosted in an infrastructure as a service (IaaS) environment or on a  uCPE . Currently, the only supported IaaS environments are Amazon Web Services (AWS) and  Azure  IaaS. AWS delivers IaaS that allows hosting of virtual machine instances. A V-ANAP can be provisioned in AWS as an Amazon Elastic Compute Cloud (EC2) instance. Prerequisites Ensure the following prerequisites are satisfied before you provision AWS with a V-ANAP: Site license from Aryaka to deploy a V-ANAP. An AWS subscription. The account ID must be shared with Aryaka support. They require it to upload the V-ANAP Amazon Machine Image (AMI) to your account. An elastic IP for the V-ANAP's M1/M2 interface. Supported V-ANAP insertion topology Edge routed mode (ERM) is the only insertion topology supported for V-ANAP deployment at a site. For detailed information, see the following topics: ANAP insertion topology ANAP configuration - Edge Routed Mode V-ANAP responsibility chart Aryaka shares the configuration, management, and operation of the V-ANAP in AWS as follows. V-ANAP Responsibility Aryaka Customer AWS Subscription. Bringing up the V-ANAP instance. Configuring all of the ANAP interfaces on the hypervisor in the order specified in this document. If any interface is not configured or provisioned in the correct order, it can negatively impact the V-ANAP functionality. EC2 instance resource allocation.  AWS VPC subnet routing and configuration. Ensure the VPC routing is set up with the traffic path always being symmetric. AWS security groups for inbound and outbound traffic. Have the security group configured to allow SSH traffic on port 2222, and to allow ICMP and tunnel traffic from the Aryaka POP. Regular operation and maintenance of AWS Instances. Procuring V-ANAP image for AWS environment. Provisioning the V-ANAP in AWS environment. V-ANAP configuration to connect multiple sites. Regular operation and maintenance of V-ANAP in AWS. Technical specifications The following table lists the interfaces and AWS instance types that are supported by the V-ANAP. V-ANAP Model Equivalent Physical ANAP Model Site License Interfaces Supported AWS Instance Types (CPU/Memory/SSD)  ANAP-7150 ANAP-1500 Small LAN M1 M2 DMZ m5d.xlarge (4/16GB/150GB) ANAP-7250 ANAP-2500 Medium LAN M1 M2 DMZ m5d.2xlarge (8/32GB/300GB) ANAP-7300 ANAP-3000 Large LAN M1 M2 DMZ m5d.4xlarge (16/64GB/600GB) If you want to repurpose the DMZ interface as an additional LAN interface,  contact Support  to enable this functionality. If the proper EC2 hardware instance guidelines are followed, ANAP-7150 and ANAP-7250 have similar throughout and performance to physical ANAP-1500 and ANAP-2500 respectively. Caveats The following are not supported on V-ANAPs: High availability (HA). Network function virtualization (NFV) firewall. Fiber ports (because the interfaces are virtual). AWS Direct Connect connectivity service. Interface speed and duplex configuration cannot be controlled on a V-ANAP. Note the following about modifying your Aryaka configuration: An existing site with a physical ANAP cannot be migrated to a V-ANAP. Changing the site license associated with the V-ANAP requires updating the site’s configuration. If the site license changes, the ANAP model is updated and an appropriate serial number is allocated to V-ANAP. This is effectively the same as provisioning a new ANAP for the site.  Note the following about modifying your AWS configuration: You cannot move a V-ANAP instance. If you need to move to another instance, repeat the installation and configuration process to instantiate a new V-ANAP. Interfaces cannot be added or removed dynamically. Instead, a V-ANAP must be rebooted for the interfaces to be updated. Traffic is  blackholed  if an interface is deleted in AWS from the VM console. But when the V-ANAP is rebooted, based on the number of available interfaces, the V-ANAP interfaces come up and resume as per their configurations. Only one V-ANAP can be provisioned in a single AWS VPC. Do  not  provision additional disks in AWS. An additional disk would have priority and would come up before the default SSD. This results in certain V-ANAP features running on the new disk instead of the SSD. This can cause unpredictable and unreliable V-ANAP performance. Provision a new site with a V-ANAP Complete the following steps in order to provision a new site to use a virtual ANAP. Step 1 - Respond to Aryaka support's request for your account ID Your organization's designated technical contact will be contacted by Aryaka customer support requesting that you share the AWS account ID. Respond to them with the AWS account ID that they can use to share the V-ANAP AMI required in Step 3. Step 2 - Prepare the required AWS EC2 components In the EC2 dashboard, create a new VPC. You can use the default VPC if desired. Create an internet gateway and attach it to the new (or default) VPC. If there is an internet gateway already available, you can use it. Add the following subnets: Two subnets for the V-ANAP's non-M1 interfaces  One subnet for the V-ANAP's M1 interface One subnet for the LAN Create a security group if required. Step 3 - Create the V-ANAP in AWS In the EC2 dashboard, locate the V-ANAP image that was shared by Aryaka in the AMI Image section. Launch the V-ANAP Instance: Select the AWS instance type for your V-ANAP. The supported instances are listed in the Required resources table. Configure the following network Interfaces in the order shown (note that only the M1 and M2 interfaces can have elastic IPs assigned): Network interface 1: Device index 0—LAN interface of the V-ANAP. Select the subnet created for the LAN interface of the V-ANAP. You can either allow AWS to assign an IP or manually configure an IP. This interface has to be mandatorily configured. Network interface 2: Device index 1—M1 interface of the ANAP. This interface must be configured by one of the following: Allow AWS to assign an IP. Manually configure an IP and assign an elastic IP.  Network interface 3: Device index 2—M2 interface of ANAP, which can optionally be configured. If configured, assign it an elastic IP. Network interface 4: Device index 3—DMZ interface of ANAP, which can optionally be configured. Add SSD storage for this instance type. No additional configuration is required. Add tags if they are required. Select an appropriate security group and ensure inbound traffic is allowed to the V-ANAP. Aryaka support provides the POP's IPs that inbound connections require for the V-ANAP's M1 interface. Review the configuration and launch the instance. For SSH, select an existing key pair or create a new one. Assign an elastic IP to the M1 interface. Stop the Source/Destination Check. Take a screen capture of the completed VM Details page and send it to  support@aryaka.com . Step 4 - Create a new site Log in to MyAryaka and  Create a site  as described in the linked help topic. Ensure you make the following V-ANAP-specific entries and selections during the site configuration: On the Site Information page, select your site license in the Site License Type field. On the ANAP Info page: Ensure the VANAP Platform field is set to AWS. Enter your VM Instance ID. The VM Instance ID can be obtained on the VM Details page in the AWS Console. Submit the order. After the order is processed, the site's status appears as Configured on the MyAryaka Sites page. Ensure the tunnel's status is Up in the Tunnel Status pane on the SD-WAN > Status >  siteName  page: Configure routing  as described in the linked help topic. Configure advanced settings  as described in the linked help topic. In this topic Related topics Virtual ANAP - uCPE Virtual ANAP - Azure Elastic IP addresses  (aws.amazon.com) EC2 instance types  (aws.amazon.com )