---
title: "Configure routing"
canonical: "https://docs.aryaka.com/space/KNOW/1511461/Configure%20routing"
format: markdown
---
The Routing page enables you to configure a site as follows: Associate the site with an existing segment or DMZ zone. See  Configure zones  for information about segments and DMZ zones. Define the site's routing configuration for segments and DMZ zones. The fields on the Routing page change dynamically depending on whether the site you are creating has an ANAP and, if there is no ANAP at the site, whether the site's point of presence (POP) has Route Service Engine (RSE) enabled.  Contact Aryaka Customer Support  if you need assistance to determine whether your site's POP has RSE enabled. Route Service Engine (RSE) is a process that runs on any number of network interfaces on an Aryaka Network Access Point (ANAP) or point of presence (POP) and performs routing and basic firewall operations for your configured site. Routing can  not  be configured for Virtual Office site types.  Click the following links to display instructions to configure routing for each type of site: This section is applicable to sites with the following location types: On Premises Hosted Cloud (only if the Deployment Type field is defined as Secure VPN) To associate a site with an existing segment Navigate to  Sites  >  siteName  >  Routing . The Routing page displays the the default segment (named vpn0 unless it has been changed previously) and any other segments associated with the selected site. Click the  Edit  icon. The page appears in edit mode, which includes the Add Segment (and Add Zone) buttons. Click  Add Segment . The Routing > New Segment page appears and displays the following information in the Basic Information pane: The first segment appears in the Segment drop-down list. For example, if you created segments vpn1, vpn2, and vpn3, vpn1 appears by default. Thin RIP appears in the Advertise Routes Using drop-down list. (Optional) Edit one or both of the default entries in the fields in the Basic Information pane: Click the  Segment  drop-down list and select the segment you want to associate with this site. Click the  Advertise Routes Using  drop-down list and select one of the following protocols that define how the segment routes traffic to the LAN of the site: ThinRIP—Recommended If your router does not support eBGP. ThinRIP is a modified RIP v2 protocol that the ANAP uses to advertise routes to the router. Because the ANAP cannot learn routes from the router, you must configure local subnets of the site in the Local Subnets section of this page (described later in this procedure). eBGP—Recommended if you have a router that supports this feature. This option allows the ANAP to learn routes from, and advertise routes to, the site. When you select this option, you must configure the the following fields that appear: Aryaka IP—IP address of the ANAP that connects to the router or firewall. BGP Peer AS—The autonomous system (AS) number for the router or firewall that the BGP peer uses with the ANAP. This number must be unique. Preferred Path Advertisement Method—The mechanism the ANAP uses to advertise the optimal route to this site. Select one of the following advertisement methods from the Preferred Path Advertisement Method drop-down list: MED—Uses the multi-exit discriminator (MED) attribute to determine the path preference. AS Path Prepend—Prepends one or more entries of an autonomous system number to the BGP route. Community—Uses the BGP Communities to determine the path preference.  If possible, Aryaka suggests that you use the same preferred path advertisement method at all of your sites. Alternatively, you can use Let Aryaka Decide for Aryaka to use default method. BGP Peer IP—The IP address of the router or firewall that the BGP peer uses with the ANAP. Static Routing Only—Recommended if your router is not capable of eBGP or RIP V2. You must configure the routes statically. This option is also available even if eBGP or RIPV2 is configured. (Optional) If you want to define a secondary (backup) eBGP configuration, select the  Enable Secondary eBGP Configuration  toggle to turn it to the ON position, then configure the fields described for eBGP in step 4b. When enabling a secondary eBGP configuration, note the following: The secondary BGP session can be from the same LAN interface as the first session or from a different LAN interface. Based on the Aryaka IP configured, the ANAP will choose the relevant zone/interface for the BGP session. If same route is received over the primary and secondary BGP session, the route received over the secondary session is advertised with a higher cost. Create at least one entry in the VLAN Configuration pane. Segments are identified by these VLANs. Click  Add New . The VLAN ID, VLAN IP Address, VLAN Mask, and VLAN Interface fields appear. Enter VLAN ID, IP address, mask, and interface in the corresponding field. Click the  Save  icon. The VLAN entry is saved and appears in the VLAN table. (Optional) Repeat steps a through c for each VLAN that is part of this site.  (Optional) Click the  Delete  icon in any row to remove a VLAN from the zone. (Conditional) If this site is  not  using eBGP to specify local subnets for this site, you must add subnets in the Local Subnets pane using one or both of the following options:  Add an individual subnet by entering the subnet mask using the CIDR (classless inter-domain routing) notation or selecting a predefined network object from the  IP Group  drop-down list, and then entering a VLAN ID. You can also add an optional comment to identify the subnet. Import a number of subnets by clicking the  Advanced  tab and select a CSV file to import. Click  OK  below the Local Subnets pane to validate your entries. This caches the entries, but does  not  save them. They are lost if you reload the page.  (Optional) If you want to enable Inter-VLAN firewall, click the  Inter-VLAN Traffic Control  drop-down list in the Inter-VLAN Traffic Control pane and select  Enabled . This feature is not configured by default. See the  Inter-VLAN traffic control  topic for details about this feature. Note that Inter-Zone Traffic Control is enabled by default and cannot be edited.   Do one of the following: Click  Save Draft  to save a draft of the entries made on this page. Click the  Next  icon or the  Advanced Settings  icon to continue your site configuration on one of Advanced Settings pages as described in  Configure advanced settings . Click  Submit  to send a change request with the entries made on this page to Aryaka support. Configure a DMZ zone for this site as described in the next section of this topic. To associate a site with an existing DMZ zone Navigate to  Sites  >  siteName  >  Routing . The Routing page appears. Unlike segments, there is no default DMZ zone, so the DMZ Zones pane is hidden until you enter the edit view, or have already created one or more DMZ zones. Click the  Edit  icon.  Click  Add Zone  in the DMZ Zones pane. The New Zone page appears. Click the  DMZ   Zone  drop-down list in the Basic information pane and select the zone you want to associate with this site. Create at least one entry in the VLAN Configuration pane. Click  Add New . The VLAN ID, VLAN IP Address, VLAN Mask, and VLAN Interface fields appear. Enter VLAN ID, IP address, mask, and interface in the corresponding field. Click the  Save  icon. The VLAN entry is saved and appears in the VLAN table. (Optional) Repeat steps a through c for each VLAN that is part of this site.  (Optional) Click the  Delete  icon in any row to remove a VLAN from the zone. (Optional) Configure Additional Local Subnets  Add an individual subnet by entering the subnet mask using the CIDR (classless inter-domain routing) notation or selecting a predefined network object from the  IP Group  drop-down list, and then entering a VLAN ID. You can also add an optional comment to identify the subnet. Import a number of subnets by clicking the  Advanced  tab and select a CSV file to import. Click  OK  below the Local Subnets pane to validate your entries. This caches the entries, but does  not  save them. They are lost if you reload the page.  (Optional) If you want to enable Inter-VLAN firewall, click the  Inter-VLAN Traffic Control  drop-down list in the Inter-VLAN Traffic Control pane and select  Enabled . This feature is not configured by default. See the  Inter-VLAN traffic control  topic for details about this feature. Note that Inter-Zone Traffic Control is enabled by default and cannot be edited.  Do one of the following: Click  Save Draft  to save a draft of the entries made on this page. Click the  Next  icon or the  Advanced Settings  icon to continue your site configuration on one of Advanced Settings pages as described in  Configure advanced settings . Click  Submit  to send a change request with the entries made on this page to Aryaka support. A site that does not have an ANAP and does not have RSE enabled can be associated with a segment only in terms of routing. This means that the segment configured for the site does not have any features associated with it (for example, WAN Routing and Basic Firewall policies, internet policies, or cloud connectors).  Sites without an ANAP can only be associated with one segment and they do not support DMZ zones. The fields displayed on the Routing page change dynamically depending on the following location types: On Premises Hosted Cloud To associate an on-premises site with an existing segment Navigate to  Sites  >  siteName  >  Routing . The Routing page displays the Segment, Routing Configuration, and Local Subnets panes. Click the  Edit  icon. The page appears in edit mode, where the segment can now be changed to any other segment available at the Network Configuration > Zones. Click the  Advertise Routes Using  drop-down list and select one of the following protocols that define how the segment routes traffic to the LAN of the site: Static Routing Only—Recommended if your router is not capable of eBGP. You must configure the routes statically.  eBGP—Recommended if you have a router at that supports this feature. This option allows the POP to learn routes from, and advertise routes to, the site. When you select this option, you must configure the the following fields that appear: Aryaka IP—IP address of the POP that connects to the router or firewall. This input is disabled and is filled by Aryaka. BGP Peer AS—The autonomous system (AS) number for the router or firewall that the BGP peer uses with the POP. This number must be unique. Preferred Path Advertisement Method—The mechanism the POP uses to advertise the optimal route to this site. Select either of the following advertisement methods from the Preferred Path Advertisement Method drop-down list: MED—Uses the multi-exit discriminator (MED) attribute to determine the path preference.  AS Path Prepend—Prepends one or more entries of an autonomous system number to the BGP route. Community—Uses the BGP Communities to determine the path preference.  If possible, Aryaka suggests that you use the same preferred path advertisement method at all of your sites. Alternatively, you can use Let Aryaka Decide for Aryaka to use default method. Peer IP—The IP address of the router or firewall that the BGP peer uses with the POP. There is also an option to define a secondary BGP Peer IP. Secondary BGP Peer IP—The IP address of the backup router or firewall that the BGP peer uses with the POP. (Conditional) If this site is  not  using eBGP to specify local subnets for this site, you must add subnets in the Local Subnets pane using one or both of the following options:  Add an individual subnet by entering the subnet mask using the CIDR (classless inter-domain routing) notation or selecting a predefined network object from the  IP Group  drop-down list, and then entering a VLAN ID. You can also add an optional comment to identify the subnet. Import a number of subnets by clicking the  Advanced  tab and select a CSV file to import. Click  OK  below the Local Subnets pane to validate your entries. This caches the entries, but does  not  save them. They are lost if you reload the page.  Do one of the following: Click  Save Draft  to save a draft of the entries made on this page. Click the  Next  icon or the  Advanced Settings  icon to continue your site configuration on one of Advanced Settings pages as described in  Configure advanced settings . Click  Submit  to send a change request with the entries made on this page to Aryaka support. To associate a hosted cloud site with an existing segment Complete the fields displayed on the Routing page for the hosted cloud sites. Note that they change dynamically depending on the following deployment types: Secure VPN and Custom Settings off—This scenario is the same as when the Location Type is On Premises. Secure VPN and Custom Settings on—In this scenario, the Routing page does not display any fields. Aryaka reviews the routing configuration in the configuration settings provided in the  Configure site information  fields and then configures the routing in the backend.  Private Connect—This scenario is the same as when the Location Type is On Premises except that eBGP is the only allowed routing configuration. If the Aryaka Provides BGP IP field is On, all Aryaka IP and Peer IP fields are populated by Aryaka. If the Aryaka Provides BGP IP is Off, Aryaka sets the autonomous system (AS) number to 11179 in the Aryaka AS Number field, and you must configure the following fields: Aryaka IP—Enter /30 or /31 IP as provided by the cloud service provider. Usually this IP is referred to as Remote BGP IP   in the service provider's portal. Peer IP—Enter /30 or /31 IP as provided by the cloud service provider. Usually this IP is referred to as Local BGP IP   in the service provider's portal. Peer AS Number—The autonomous system (AS) number provided by the cloud service provider. A site that does not have an ANAP and has RSE enabled can be associated with a segment that has features associated with it (for example, WAN Routing and Basic Firewall policies, internet policies, or cloud connectors).  Sites without an ANAP can only be associated with one segment and they do  not  support DMZ zones. This section is applicable to sites with the following location types: On Premises Hosted Cloud To associate a site with an existing segment Navigate to  Sites  >  siteName  >  Routing . The Routing page displays the default segment (named vpn0 unless it has been changed previously). Click the  Edit  icon. The page appears in edit mode. Click the default segment. The Routing >  segmentName  page appears in edit mode and displays the Basic Information and Local Subnets panes.  (Optional) Change the segment: Click the  Change Segment  toggle. A warning message is displayed. Changing a segment removes all WAN Routing and Basic Firewall policies, internet policies, and other segment-related configurations. Click  OK  to proceed. The Segment drop-down list appears in edit mode.  Click the  Segment  drop-down list and select the segment you want to associate with this site. Click the  Advertise Routes Using  drop-down list and select one of the following protocols that define how the segment routes traffic to the LAN of the site: Static Routing Only—Recommended if your router is not capable of eBGP. You must configure the routes statically.  eBGP—Recommended if you have a router at that supports this feature. This option allows the POP to learn routes from, and advertise routes to, the site. When you select this option, you must configure the the following fields that appear: Aryaka IP—IP address of the POP that connects to the router or firewall. This input is disabled and is filled by Aryaka. Peer AS Number—The autonomous system (AS) number for the router or firewall that the BGP peer uses with the POP. This number must be unique. Aryaka AS Number—The AS number for the POP that connects to the router or firewall. This input is disabled and is filled by Aryaka. Peer IP—The IP address of the router or firewall that the BGP peer uses with the POP. (Conditional) If this site is  not  using eBGP to specify local subnets for this site, you must add subnets in the Local Subnets pane using one or both of the following options:  Add an individual subnet by entering the subnet mask using the CIDR (classless inter-domain routing) notation or selecting a predefined network object from the  IP Group  drop-down list, and then entering a VLAN ID. You can also add an optional comment to identify the subnet. Import a number of subnets by clicking the  Advanced  tab and select a CSV file to import. Click  OK  below the Local Subnets pane to validate your entries. This caches the entries, but does  not  save them. They are lost if you reload the page.  Do one of the following: Click  Save Draft  to save a draft of the entries made on this page. Click the  Next  icon or the  Advanced Settings  icon to continue your site configuration on one of Advanced Settings pages as described in  Configure advanced settings . Click  Submit  to send a change request with the entries made on this page to Aryaka support. Next step Configure advanced settings Related topics Configure site information Configure ANAP information Configure site to site topology Configure zones