---
title: "Create virtual machines"
canonical: "https://docs.aryaka.com/space/KNOW/1511339/Create%20virtual%20machines"
format: markdown
---
The Add Virtual Machine page enables you to configure, deploy, and operate virtual machines. The Add Virtual Machine page also enables you to define VM profiles and upload VM images either from your local computer or from a portable USB flash drive. As discussed elsewhere in this section, these operations have their own dedicated pages for creating and managing these components. The design is intended simplify the creation and management of images and profiles in organizations that have large numbers of these components and intend to reuse them at multiple sites. If you prefer to configure all aspects of your VM in one place, you can do so from the Add Virtual Machine page. To create a virtual machine Log in to MyAryaka. The Home page appears. Click  SD-WAN  >  Settings  in the left navigation pane. The Settings page appears and displays a series of tiles. Click  Virtual Machines  in the VM Configuration tile. The Virtual Machines page appears and displays a table of all VMs. Click the  Add  icon. The Add Virtual Machine page appears. Complete the fields in the Basic Information pane: Enter a name for the virtual machine in the Name field. Select the location to deploy this VM from the  Sites  drop-down list.  Complete the fields in the Profile Details pane: Select the VM's vendor from the  Vendor  drop-down list. Select a previously-defined VM profile from the  Profile  drop-down list or select  Add New Profile  to display the following: Name—Enter a name for the profile. Image—Select a previously-defined VM image from the drop-down list, select  Upload New Image  to upload from your local computer as described in the  Upload VM images  procedure in the  Virtual machine images   topic, or enter the file name, and upload directly to the ANAP from a USB drive as described in the  Upload VM images from a flash drive  procedure in the  Virtual machine images  topic. MD5 Checksum—Enter the numeric value obtained from the VM vendor. The checksum is used to ensure the data integrity of the image file when it is uploaded and when it is deployed to the ANAP. VM Model—Confirm the Aryaka-recommended default model or edit if necessary. OK button—Click this button after completing the required fields to create the new VM profile. Complete the fields in the VM To ANAP Connectivity Details pane. These fields describe the IP of the ANAP software instance when it and the VM's firewall both reside on an ANAP. ANAP IP Address—IP address of the ANAP where the virtual machine is deployed. ANAP Mask—Subnet that divides the ANAP IP address into a network address and a host address. ANAP Gateway—Node that enables the ANAP to communicate with other networks on the LAN's network. If you are deploying Check Point HA, use the interface's cluster IP. Monitoring IP—IP address used by the ANAP to monitor the connectivity to the remote ANAP. Typically, the ANAP's LAN IP is used for monitoring, but when a VM is deployed, the firewall loses the LAN IP, so it must be explicitly defined here. Complete the fields in the WAN IP Details pane. These fields are used for network address translation (NAT) by the firewall provided by the virtual machine. Configuring these WAN IP fields ensures the ANAP updates the required rules to route the packets to the VM. WAN 1 IP/Subnet—Public IP address of the WAN where the ANAP is deployed. Enter the IP address of the WAN or subnet, or select the appropriate IP group from the drop-down list. This address is mapped to the M1 Gateway unless the Custom Gateway option is selected (in the WAN 1 Gateway field). WAN 1 Gateway—Select one of the following gateway options for the ANAP: ANAP's M1 Gateway—VM uses the IP configured for the ANAP's M1 gateway. Custom Gateway—Displays the WAN 1 Custom Gateway field where you can specify the IP that the VM uses. WAN 1 Custom Gateway—Enter the IP address of the custom gateway. (This field appears only if the Custom Gateway option is selected for the WAN 1 Gateway.) WAN 2 IP/Subnet—Public IP address of the WAN where the ANAP is deployed. Enter the IP address of the WAN or subnet, or select the appropriate IP group from the drop-down list. This address is mapped to the M2 Gateway unless the Custom Gateway option is selected (in the WAN 2 Gateway field). WAN 2 Gateway—Select one of the following gateway options for the ANAP: ANAP's M2's Gateway—VM uses the IP configured for the ANAP's M2 gateway. Custom Gateway—Displays the WAN 2 Custom Gateway field where you can specify the IP that the VM uses. WAN 2 Custom Gateway—Enter the IP address of the custom gateway. (This field appears only if the Custom Gateway option is selected for the WAN 2 Gateway.) (Optional) Enable HA configuration for your VM vendor: Palo Alto Networks: Select  Firewall Management Interface  for the HA1 Interface. This is used for the HA1 control link.  Select  ANAP WAN Interface  for the HA2 Interface. This is used for the HA2 data link.  Configure the second VM's Management IP: Management IP—IP address that the VM uses to allow management access. This management IP of the VM firewall is reachable over the ANAP's SYNC physical port. Management Mask—Subnet that divides the VM Management IP address into a network address and a host address. Management Gateway—Node that enables the VM to communicate with other networks. Check Point: Select ANAP WAN Interface for the Sync Interface. This is used for HA SYNC.  Configure the second VM's Management IP: Management IP—IP address that the VM uses to allow management access. This management IP of the VM firewall is reachable over the ANAP's SYNC physical port. Management Mask—Subnet that divides the VM Management IP address into a network address and a host address. Management Gateway—Node that enables the VM to communicate with other networks. Configure the VM WAN Interface Physical IP (the VMs participating in HA are identified as VM1 and VM2): VM1: WAN1 Interface Physical IP—For VM1, the IP configured on the WAN1 interface. WAN2 Interface Physical IP—For VM2, the IP configured on the WAN2 interface. VM2: WAN1 Interface Physical IP—For VM1, the IP configured on the WAN1 interface. WAN2 Interface Physical IP—For VM2, the IP configured on the WAN2 interface. WAN1 Physical Interface Gateway IP/CIDR—On both the firewalls, WAN1 interface uses the same gateway address on both of the VMs using the following format:  x.x.x.x /32. WAN2 Physical interface Gateway IP/CIDS—On both the firewalls, WAN2 interface uses the same gateway address on both of the VMs.  Select the MDM/SMS firewall connectivity type: If the server is on the local LAN, enter the VM Management Server IP (from step 10). If the server is on a remote network, enter the physical IPs of each VM's VPN interface. (Optional) Complete the fields in the VM Health Config pane. These fields determine when and how often the ANAP device contacts the ANAP’s gateway address to ensure that the VM installed there is running and processing traffic. If the ANAP is unable to reach the gateway address, it attempts to restart the VM. By default, this functionality is disabled until you configure one or more of the following fields: Ping Interval—Number of seconds between attempts to contact the VM's IP. Ping Retries—Number of contact attempts to make before determining the status of the VM. Restart Threshold—Number of VM restart attempts to make before assuming the VM is unavailable. Note:  Enabling the VM Health functionality requires you to allow ICMP on the VPN interface of the firewall. (Optional) Complete the fields in the Optional Initialization Config pane. Note:  The VM uses these configuration settings only during the first startup and the corresponding initialization. After the VM is started, these configuration parameters cannot be edited using MyAryaka. You can update and manage these configuration settings using the VM's administration software. Management IP—IP address that the VM uses to allow management access. This management IP of the VM firewall is reachable over the ANAP's SYNC physical port. Management Mask—Subnet that divides the VM Management IP address into a network address and a host address. Management Gateway—Node that enables the VM to communicate with other networks. VM Management Server IP—Applicable only for Check Point and the IP is required to be configured if the server is on the local LAN. Click  Submit . You are prompted to select one of the following submit options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. The following events occur when activated: The profile is created and added to the table on the Virtual Machines page. It is assigned the  Provisioning status.  A change request is sent to Aryaka to process. You can track the request in the  Ticketing Portal . After Aryaka completes processing the request, the status changes to Pending: If the image is available, Pending means partitioning is required.  If the image is  not  available, Pending means you must wait until ANAP gets the image from one of the sources (uploaded to MyAryaka or uploaded to the ANAP using a flash drive). The newly-created virtual machine's detail page appears. From here you can initialize and start the VM as described in the  Operate a virtual machine  procedure in the  Manage virtual machines  topic. Related topics Manage virtual machines Virtual machine profiles Virtual machine images