---
title: "ANAP access guide"
canonical: "https://docs.aryaka.com/space/KNOW/1300955152/ANAP%20access%20guide"
format: markdown
---
Aryaka’s ANAP can be accessed by an Aryaka Partner after the ANAP contacts the Aryaka POP initially to download its configuration. This document describes how to generate a key to access the ANAP, how to access the ANAP and what actions can be performed once you have logged into the ANAP. Generating the ANAP key Each partner that wants to access their ANAP must generate a private key that is used to access the ANAP. Perform the following procedure that corresponds with your client operating system. Linux clients On a Linux client, use the  ssh-keygen command to generate an RSA key. This command generates a private key and a corresponding public key. It is strongly advised that you apply a strong passphrase when using this tool to generate the private key. ssh-keygen -f anap_partner_key
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in anap_partner_key.
Your public key has been saved in anap_partner_key.pub.
The key fingerprint is:
ba:8b:41:c1:da:de:c5:63:4f:fd:68:61:c4:ef:ec:54 achetur@A-MacBookPro.local
The key's randomart image is:
+--[ RSA 2048]----+
|                 |
|                 |
| .       o       |
|  o   o . *      |
| o . + oSo =    E|
|. o   o.. o o  . |
| o . ..  . o  .  |
| o .. .     o.   |
|  .. o.    ..    |
+-----------------+ Keep the private key and passphrase secure and email  support@aryaka.com  with the public key file what was just generated. Issue the following command to generate an md5sum of the public key file—this is verified by Aryaka support when they receive the file: md5sum anap_partner_key.pub Windows client On a Windows client, use  PuTTYgen  or similar programs to generate an RSA key.  Start the application and display the key generator. Click  Generate . You are prompted to move the mouse around to generate a random key. After the key is generated, it is strongly advised that you apply a strong passphrase using the key generator.  Click  Save Public Key  and  Save Private Key  to save the generated files on your computer. Locate the md5sum of the public key file. This is verified by Aryaka support when they receive the file. The md5sum can be found using several tools on Windows including  HashTab . Securely store the private key and passphrase, then email  support@aryaka.com  with the  public  key file that you generated. Aryaka support completes the configuration for your ANAP access. Accessing the ANAP In general, the following process is used for ANAP access: Aryaka support receives the public key that you sent by email, they contact you to verify the hash of the file that they just received. After it is verified, Aryaka support processes the key and reply to you with a username that you can use to login to the ANAP. Upon receipt of this username, login to the ANAP with the username, private key, and the passphrase of the private key. The next sections describe the differences for ANAP access depending on the client operating system. Linux client On a Linux client, use ssh, for example: ssh –i <path to presharedkey> -l <username> <anapip> When prompted, enter the passphrase of the private key. Windows client On a Windows client, you can use a Putty configuration session to load the private key: Enter the IP address of the ANAP in the Host Name (or IP Address) field. Click  Connection  >  Data  in the left navigation pane, then enter the username in the Auto-login Username field. Click  Connection  >  SSH  >  Auth  in the left navigation pane, click  Browse  next to the Private Key for Authentication field, and then select your private key file. Click  Open . You are prompted for the passphrase. Enter the passphrase, then click  Save . ANAP access commands The Aryaka ANAP has its own modified bash shell commands that are available to users. This section describes the most commonly used ones: show The show command displays the state of the ANAP, its configuration, and its logs. Type show and then press enter to display the available options. [admin2@anap:MIL ~]$ show
Usage:
  show all              :shows all below status
  show [napsec | fw]    :security rules counters
  show ipsec            :ipsec tunnel status
  show dprm             :DPRM information
  show connexus         :connexus status summary
  show connexus detail  :connexus status detail
  show ip <ip-addr>     :IP connexus lookup
  show a2a              :A2A tunnel information
  show sys              :system information
  show net              :network information
  show routes           :kernel routing tables
  show arp              :arp table
  show proc             :ASN related process status
  show swinfo           :installed software information
  show upgrade          :upgrade status
  show [alarms | msg]   :shows messages
  show naplink          :naplink status
  show ifc              :interface counters
  show qos              :qos information
  show varp.            :VARP information
  show dhcp.            :DHCP-Server information
  show log              :System, ANAP, flows, drops log
  show config           :show configuration ping Run the ping command using the following syntax to check network reachability: ping <destination IP> -i <source IP>

[admin2@anap:MIL ~]$ ping 8.8.8.8 -I 172.16.21.7
PING 8.8.8.8 (8.8.8.8) from 172.16.21.7 : 56(84) bytes of data.
64 bytes from 8.8.8.8: icmp_seq=1 ttl=55 time=4.53 ms
64 bytes from 8.8.8.8: icmp_seq=2 ttl=55 time=4.33 ms
--- 8.8.8.8 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1157ms
rtt min/avg/max/mdev = 4.337/4.437/4.538/0.120 ms traceroute Run the traceroute command using the following syntax to display the hops in the path that the traffic takes to reach the specified destination: traceroute <destination IP> -s <source IP>

[admin2@anap:MIL ~]$ traceroute 8.8.8.8 -s 172.16.21.7
traceroute to 8.8.8.8 (8.8.8.8), 30 hops max, 60 byte packets
1   172.16.21.5 0.582 ms 0.650 ms 1.323 ms
2   207.140.44.225 1.562 ms 1.732 ms 1.960 ms
3   12.251.77.237 2.812 ms 2.933 ms 3.001 ms
4   12.249.231.14 3.521 ms 3.684 ms 3.691 ms
5   209.85.244.25 5.784 ms 66.249.95.63 6.065 ms 209.85.244.25 5.785 ms
6   216.239.49.125 7.162 ms 6.580 ms 216.239.58.195 6.468 ms
7   8.8.8.8 5.598 ms 5.403 ms 5.253 msmtr mtr Run the mtr command using the following syntax to display the continuous state of the network to the specified destination: mtr <destination IP> -a <source IP>

[admin2@anap:MIL ~]$ mtr 8.8.8.8 -a 172.16.21.7
My traceroute [v0.75]
anap-2000-0180.aryaka.net (0.0.0.0)
Wed May 18 21:53:13 2016
Keys: Help Display mode Restart statistics Order of fields quit

Packets Pings
Host                               Loss%  Snt  Last   Avg   Best  Worst   StDev
1. 172.16.21.5                     0.0%   14   0.4    0.6   0.4     1.2     0.3
2. 207.140.44.225                  0.0%   14   0.6    0.6   0.5     0.8     0.1
3. 12.251.77.237                   0.0%   14   2.1    5.1   2.1    25.2     7.5
4. 12.249.231.14                   0.0%   14   9.4    3.3   2.5     9.4     1.8
5. 66.249.95.63                    0.0%   13   4.8    4.7   4.6     4.8     0.0
6. 216.239.43.239                  0.0%   13   4.6   13.5   4.5   119.7    31.9
7. google-public-dns-a.google.com  0.0%   13   4.8    4.7   4.3     7.4     0.8 tcpdump Run the tcpdump command using the following syntax to capture and view traffic on the LAN, WAN, M1, and M2 interfaces. Note that tcpdump has been modified to have some additional options and restrictions as described in the two Usage sections. [admin2@anap:MIL ~]$ tcpdump

Insufficient arguments
Usage: tcpdump [-TO <duration in minutes that tcpdump runs>]
  [See below for all the other usage options]
  Note: [-TO <duration>] must be the first argument if present

tcpdump version 4.1-PRE-CVS_2012_03_26
libpcap version 1.4.0
Usage: tcpdump [-aAdDefIKlLnNOpqRStuUvxX] [ -B size ] [ -c count ]
  [ -C file_size ] [ -E algo:secret ] [ -F file ] [ -G seconds ]
  [ -i interface ] [ -M secret ] [ -r file ]
  [ -s snaplen ] [ -T type ] [ -w file ] [ -W filecount ]
  [ -y datalinktype ] [ -z command ] [ -Z user ] [ expression ]
  Note: The file specified with [-w] will always be saved in /tmp. This does 
        not apply to the file specified with any other option For example: [admin2@anap:MIL ~]$ tcpdump -TO 1 -i lan host 172.16.1.1 -w test.pcap
Running capture for 1 minutes
pcap file will be /var/core/tmp/test.pcap
tcpdump: listening on lan, link-type EN10MB (Ethernet), 
capture size 65535 bytes Copying files from the ANAP To move any saved packet capture (PCAP) or other file from your ANAP to your system for analysis or archiving, complete the following procedure that corresponds with your client operating system: Linux client On a Linux client, use the scp command as follows: scp –I <private key> <username>@<ip address>:<full path to file name>

scp -i anap_partner_key testanu@172.16.21.7:/tmp/test.pcap 
test.pcap 100% 426KB 426.4KB/s 00:00  Windows client On a Windows client, use  WinSCP  or a similar SFTP client. Open the SFTP application and initiate a login session. Specify the following in the corresponding field, then click  Login : Host name Port number User credentials Location of the private key file When prompted, enter the passphrase associated with the private key. The following file management window appears. The left pane shows your computer and the right pane displays the file system on the ANAP. Navigate to the directory of your choice, drag one or more files from the right pane and drop them into the left pane to make a copy of the file. In this topic Related topics ANAP insertion topology ANAP security guide