---
title: "ANAP Datasheet <br><span>Aryaka Network Access Point</span>"
url: "https://www.aryaka.com/datasheet/anap-datasheet/"
markdown_url: "https://www.aryaka.com/datasheet/anap-datasheet.md"
llm_canonical: "https://www.aryaka.com/datasheet/anap-datasheet.md"
canonical_for_llm: true
entity_type: "WebPage"
primary_entity: "ANAP Datasheet <br><span>Aryaka Network Access Point</span>"
citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/datasheet/anap-datasheet/."
last_updated: "2025-09-28T19:38:10-07:00"
---

<h1>ANAP Datasheet &lt;br&gt;&lt;span&gt;Aryaka Network Access Point&lt;/span&gt;</h1>

Aryaka’s edge appliance, the Aryaka Network Access Point (ANAP), delivers on a virtualized software-defined edge and branch solution as part of our Unified SASE as a Service. The ANAP is included in the services delivery and a key component of our single-pass architecture. The ANAP aggregates multiple WAN connections and provides converged network services including routing, encryption, security, deep packet inspection engine, and traffic management. It also supports redundancy with high-availability configuration options​.

<h4>Aryaka OnePASS ArchitectureTM</h4>

![Aryaka OnePASS Architecture](https://www.aryaka.com/wp-content/uploads/2025/07/Aryaka-OnePASS-Architecture-Diagram.webp)

   ![ANAP 100](https://www.aryaka.com/wp-content/uploads/2024/10/ANAP-100.jpg)

The ANAP is the on-ramp to Aryaka’s managed global SD-WAN and Unified SASE as a Service platform. The ANAP integrates advanced networking, application optimization, and acceleration, and security functions.

The ANAP portfolio consists of physical and virtual appliances based on an adaptable white box architecture running the industry-standard Linux operating system, which provides built-in virtualization (KVM) and containerization technology to support Virtual Network Functions (VNFs).

Companies of all sizes can deliver enterprise-class connectivity to remote and branch locations – which often lack qualified IT personnel – within less than 48 hours by leveraging the ANAP’s ZTD (Zero Touch Deployment) model.

<h4>Benefits</h4>

| Deployment Simplicity and Integrated Design | The ANAP comes pre-configured and is easily implemented with a zero-touch deployment model. |
| --- | --- |
| Software-defined Solution | The ANAP implements networking, application optimization and security services as software functions, built on top of a hardened Linux operating system. It avoids the costly built-in obsolescence of custom architectures. |
| Built-in SD-WAN | The ANAP is an integral component of Aryaka’s network services. It helps enterprises leverage any last-mile transport (MPLS, hardened Internet) and can leverage the high-quality Aryaka core network to attain better than MPLS quality-of-service levels. |
| HybridWAN | support providing Aryaka L2 & L3 Core, MPLS peering, site-to-site Internet and public Internet path options. |
| Built-in Cloud Network Support | Azure Virtual WAN and AWS Transit Gateway support. |
| Built-in Security | The ANAP implements a stateful L3/L4, DPI-L7 NGFW firewall to thwart attacks to the branch, combined with a SWG built for web traffic inspection and policy enforcement. Optional security capabilities include IDPS, CASB, and Anti-Malware.​ |
| Redundancy | Support for link (dual ISP links) and device (VRRP) redundancy delivers on very high availability requirements (see illustration). Fail-to-wire is supported for inline mode |
| Better User Experience | Deterministic, predictable performance for applications residing in the data center or in the cloud. |
| Multi-Tenant Solution | Aryaka’s ANAP supports up to 32 tenants via micro-segmentation. |
| Flexible Branch Deployment | options including inline, simple routed, hybrid and edge routed mode. |
| Greater Agility | Faster, easier deployment and operation of of your managed SD-WAN and SASE, with greater performance using less bandwidth. Add new revenue generating services in minutes not months. |

<h4>ANAP Redundancy</h4>

![ANAP redundancy](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/ANAP-redundancy.svg)

<h4>Hardware Specifications</h4>

|  | ANAP 1500 | ANAP 2500/2600 | ANAP 3000 | ANAP 4000 | ANAP 10000 |
| --- | --- | --- | --- | --- | --- |
| Bandwidth | Up to 150Mbps | Up to 650Mbps | Up to 1 Gbps | TBD | Up to 3Gbps |
| Interface type | Copper | Copper | Copper/Fiber | Copper/Fiber | Copper/Fiber​ |
| NFV Capable | No | No/Yes | Yes | Yes | Yes |
| QoS / WAN | Yes | Yes | Yes | Yes | Yes |
| Optimization | Yes | Yes | Yes | Yes | Yes |
| Routing | Yes | Yes | Yes | Yes | Yes |
| Edge Security | Yes | Yes | Yes | Yes | Yes |
| Cloud Security | Yes | Yes | Yes | Yes | Yes |
| Connectors | Yes | Yes | Yes | Yes | Yes |
| Monitoring | Yes | Yes | Yes | Yes | Yes |
| Recommended for | Small Sites | Medium Sites | Large Sites | Large Sites | Large/X-Large Sites |

<h4>ANAP Architecture Highlights</h4>

<h5>– QoS</h5>

  Classification and Marking IP 5-tuple-based marking DSCP/ToS-based classification
 DNS lookup
 SNI lookup
 DPI (Deep Packet Inspection Class of Service Shaping 5 classes of service with bandwidth reservation/limits Hierarchical
 token-bucketbased queuing and shaping TCP/IP Shaping TCP-IP flow-level advanced shaper with two classes Adaptive QoS Sharing unused ASN link capacity with low priority internet traffic Supported on ERM only and enabled by default

<h5>– WAN Optimization</h5>

  TCP Boost Minimize latency and congestion avoidance over the last-mile with WAN rate control ARR Patented compression and data deduplication algorithms

<h5>– Routing</h5>

  eBGP eBGP support with Preferred Path selection using AS PATH Prepend and MED (Multi-Exit Discriminator) attributes
 MP-BGP and BGP Communities support Thin RIP (T-RIP) RIPv2.0-compliant routing advertisements to simplify routing configuration Static Routing Static route configuration for local subnets, default gateway and IPSec tunnel gateway Forwarding decision based on 6-tuple match criteria and/or DNS Policy-based Routing • Forward to LAN • Forward to Internet • Forward to Aryaka • Drop Policy-based Routing based on Source Address Forward packets based on IP source address Route Filters Granular 6-tuple policy control to forward/drop Aryaka- and internet-bound traffic

<h5>– Redundancy</h5>

  Edge Redundancy Dual IPSec tunnels to different ISPs for link redundancy VARP (Virtual ANAP Redundancy Protocol) VRRP-like model for ANAP redundancy in active-standby model ANAP-to-ANAP backup tunnels Direct IPSEc tunnels between ANAPs across the internet in the unlikely case the primary Aryaka tunnel fails ISP link redundancy SMARTlink allows the use of 2 ISP links in an active-active configuration
 • Path Selection: Selective routing across the links
 • Load Balancing: Distribute traffic across the links on a per-packet basis
 • FEC: Replicate or duplicate traffic across the links to recover lost packets
 • Timed Replay: flows can be replayed within a link after a delay, to recover lost packets
 • Path Loss Recovery (PLR): Introduces a feedback mechanism between the POP and ANAP to determine the exact packets lost during transmission, and recover these packets MPLS link redundancy Dual MPLS tunnels with redundant ANAP deployment

<h5>– Security</h5>

  NAT Support Stateful flow tracking based on NAT policies
 • Source NAT support – 1-to-1 NAT, dynamic IP and port
 • Destination NAT support – port forwarding and port translation Firewall and Branch Segmentation L3/L4 Stateful NGFW-SWG for perimeter firewalling, web traffic inspection/policy enforcement, and East-West branch segmentation​ Intrusion Detection and Protection​ Inspects inbound traffic on the WAN interface and outbound traffic on the LAN interface Cloud Access Security Broker (CASB)​​ Secure and enforce policies on application traffic passing through the ANAP Anti-Malware​​ Evaluate network traffic against database of known malware signatures and patterns for detection Multi-Tenancy Multi-Tenancy support through VRF-based Microsegmentation Check Point Hosted VM Next Generation Firwewall as VNF (Virtual Network Function) Palo Alto Networks Hosted VM Next Generation Firwewall as VNF (Virtual Network Function) Zscaler IPSec IKev1 support (in addition to GRE tunnels) Private VLANs ANAP Hardening SEC-2 Ability to group a set of VLANs and restrict access only to internet Secure ANAP bootstrap process with secure ANAP image

<h5>– Cloud Security Connectors</h5>

  Check Point IPsec IKEv1, IKEv2 or GRE tunnels
 Policy-based routing between internet, Aryaka and Check Point CloudGuard Connect bound traffic CloudGuard Connect MyAryaka for Tunnel Connectivity monitoring to Cloudguard Connect Zscaler Support for Redundant GRE tunnels Policy based routing between internet, Aryaka and Zscaler bound traffic MyAryaka support for visibility and configurability Palo Alto Prisma IKEv1 based IPsec tunnel Policy based routing between internet, Aryaka and Palo Alto Prisma bound traffic MyAryaka support for visibility and configurability Symantec IKEv1 based IPsec tunnel Policy based routing between internet, Aryaka and Symantec bound traffic MyAryaka support for visibility and configurability

<h5>– Monitoring</h5>

  Syslog Flow logs for packets routed between LAN, internet and Aryaka sites
 Flow Logs for packets dropped due to policies or firewall rules
 System logs
 RFC 5424 support
 Key, value pair-based attribute logging for easier parsing
 Support for UDP and TCP based connectivity to collector Netflow Support for NDE version 1,5 and 9. Default of 9.
 Ability to monitor LAN, Internet, cloud security connectors, and Aryaka traffic. 1:1 sampling rate
 Flow information is uploaded to ANAP to MyAryaka every 300 seconds

<h5>– Virtual Network Function Support</h5>

  Hosted Virtual Machine (VM) Support of 3rd party VMs via Linux KVM

<h4>About Aryaka</h4>

Aryaka is the leader in delivering Unified SASE as a Service, a fully integrated solution combining networking, security, and observability. Built for the demands of Generative AI as well as today’s multi-cloud hybrid world, Aryaka enables enterprises to transform their secure networking to deliver uncompromised performance, agility, simplicity, and security. Aryaka’s flexible delivery options empower businesses to choose their preferred approach for implementation and management. Hundreds of global enterprises, including several in the Fortune 100, depend on Aryaka for their secure networking solutions. For more on Aryaka, please visit [www.aryaka.com](https://www.aryaka.com/).

[Download Datasheet](https://www.aryaka.com/docs/anap-datasheet.pdf)
