---
title: "Configure cloud connectors"
canonical: "https://docs.aryaka.com/space/KNOW/1511637/Configure%20cloud%20connectors"
format: markdown
---
You can configure tunnels from your ANAP to the following Aryaka-certified cloud security vendors:  Check Point Harmony Connect Symantec Netskope Palo Alto Networks Zscaler You can also configure tunnels from the ANAP to to following  custom vendors  that are modeled after one of the Aryaka-certified vendors: Cisco Umbrella Menlo Security RBI Depending on the vendor, the ANAP can connect using a GRE or IPSec VTI-based tunnel, which can either be IKEv1 or IKEv2. Refer to the linked deployment documents for additional information about integrating with each vendor. You must satisfy the following prerequisites to configure a cloud connector: Site must have a supported ANAP device. Active subscription from the respective cloud security vendor. Access to the vendor's administration portal. The following table lists the supported Aryaka ANAP device topologies and tunnel types for each vendor. Cloud Security Vendor Supported Device Topologies Supported Tunnel Types Zscaler Simple routed mode Inline routed mode Edge routed mode GRE  VTI-IKEv1 VTI-IKEv2 Palo Alto Networks Inline routed mode Edge routed mode VTI-IKEv1 VTI-IKEv2 Symantec Inline routed mode Edge routed mode VTI-IKEv1  VTI-IKEv2 Check Point Harmony Connect Inline routed mode Edge routed mode GRE VTI-IKEv2 Netskope Inline routed mode Edge routed mode GRE VTI-IKEv1 VTI-IKEv2 Cisco Umbrella Inline routed mode Edge routed mode VTI-IKEv2 Menlo Security RBI Inline routed mode Edge routed mode VTI-IKEv2 If your ANAP device supports segmentation, you can have multiple cloud connectors configured to any of these vendors. The sections that follow describe cloud connector configuration with and without segmentation. Configure a cloud connector Depending on the version you are running, MyAryaka enables you to configure multiple cloud connectors to support different cloud security vendors. If you do not see this option, you may be running a version that does not support multiple connectors.  Contact customer support  to get your account upgraded. In general, the connector configuration involves defining tunnel parameters and then specifying the traffic that can be forwarded that connector. If you are using segmentation and multiple security vendors, you must repeat the configuration for each additional vendor. Before you can configure a cloud connector, you must  add the Cloud Security vendor network . To create a cloud connector Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears and lists all sites in your network. Click the site for which you want to create a cloud connector. The selected site's page appears. Click the  Connectivity  section to expand it. The Connect to Cloud Security Vendor tile appears. Click  Configure  or, if you have previously configured a cloud connector, click  View . The Cloud Security Vendors page appears. Click  Add   Connector . The Cloud Security Connector (Add) pane appears.  Perform the following in the Basic Information pane: Enter a name for the connector and, optionally, a description in the appropriate fields. Select the tile for the vendor you want to use. The selected vendor's logo displays a dark outline.  Complete one of the following, depending on whether the selected vendor is certified or custom: For certified vendors, click the  Tunnel Type  drop-down list, then select the type of tunnel for the connector. The list only displays supported tunnel types. If you select the VTI tunnel type, the Enable IKE v2 field appears. Click  Yes  or  No  in the Enable IKEv2 field depending on whether you want the VTI tunnel to use IKEv2. For custom vendors, click the  Custom Connector Like  drop-down list, then select the name of the vendor and tunnel type that the custom vendor must be modeled after. Complete the configuration as described in one of the following vendor-specific topics: Configure a Check Point cloud connector Configure a Symantec cloud connector Configure a Netskope cloud connector Configure a Palo Alto Networks cloud connector Configure a Zscaler cloud connector Configure a Cisco Umbrella cloud connector Configure a Menlo Security RBI cloud connector (Optional) If the ANAP device topology mode is  inline routed  or  edge routed , and you want to specify the type of traffic that can flow through the tunnel, you must configure routes as described in  Route controller . Note that route controllers are  not  supported for cloud connectors created on sites that run versions that allow multiple segments. If this is the case, see  Create internet policies  for configuration details. Click  Submit  to send a change request with the entries made on this page to Aryaka support. To edit or delete a cloud connector Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears. Click the site for which you want to edit or delete a cloud connector. The selected site's page appears. Click the  Connectivity  section to expand it. The Connect to Cloud Security Vendor tile appears. Click  View . The Cloud Security Vendors page appears and displays a tile for each configured cloud security vendor. Click the tile for the vendor you want to edit or delete. The Cloud Security Connector page appears in read-only mode.  Click the  Edit  icon. The Cloud Security Connector page appears in edit mode. Do one of the following: Edit the fields as appropriate, then click  Submit  to send a change request based on the new settings to Aryaka Support for processing. If you are deleting the connector and the routes for this connector in the  Route controller , delete those routes now. After the routes are deleted, click the  Delete  icon (top right). You are prompted to activate the change now or later. Choose Activate Later if you plan to make additional changes to the configurations of your sites. Related topics View and add a Cloud Security Vendor network