Software Secure Access
Activity Manage

Anycast Configuration Support

The Umbrella VA enables the use of Anycast DNS addressing within an enterprise.

The VA currently supports enabling Anycast using the BGP protocol. This requires support for BGP on the VA's neighboring router, or any router that is reachable from the VA within 255 hops. See the Configure Anycast topic for information about how to configure Anycast on the VA.

In addition, keep the following in mind when configuring Anycast on the Alibaba cloud:

  • Configure an additional route on the VSwitch for the Anycast IP address for packets with the destination IP as Anycast.
  • The Anycast IP/network can be routed only per single ECS or ENI per VSwitch, where the next hop is the VA instance on which Anycast is enabled and 10.0.0.5 is the Anycast IP.

Note: VAs participating in anycast DNS should belong to different VSwitches or different networks; the following image shows the route table of a VSwitch configured with an Anycast route.

image