The Umbrella Documentation Hub

Welcome to the Umbrella documentation hub. Here you'll find access to all of our Cisco Umbrella user guides.

Get Started    

Configure Anycast

The Umbrella virtual appliance (VA) enables the use of Anycast DNS addressing within an enterprise.

The advantage of using Anycast is that all your endpoints can use the same DNS IP address irrespective of the site to which they belong. Configuring an Anycast IP address on the VA adds resiliency for DNS resolution.

The VA currently supports enabling Anycast using the BGP protocol. This requires support for BGP on the VA’s neighboring router.

Two VAs in different branches can also be configured with the same Anycast IP address, ensuring resiliency across branches. However, if AD integration is required, these VAs must be in the same Umbrella site, since the AD Connector propagates IP-AD user mappings only to VAs in its Umbrella site.

Configure Anycast over BGP on the VA

  1. Enter the Configuration Mode on the VA.
  2. Enable Anycast support on the VA. Enter config anycast bgp <options>
    Command returns an ASN for the VA.
    Options are:
    • enable <anycast_ip> <bgp_info>—Enable the anycast mode
    • <anycast_ip>—Anycast IP address
    • <bgp_info>—ASN:IPAddress of the BGP router to publish
    • disable—Disable anycast mode
    • status—Show status of anycast
    • test—test Anycast connectivity
    • help—Display this usage information
  3. Validate status. Enter config anycast bgp status
  4. On the router, add the VA’s ASN from step 2 as the neighbour of the router.
    Note: If your VA is running version 2.3.1 or earlier, use the command support anycast bgp <options>.

Configuration Example

In the following configuration, the VA needs to be configured with Anycast IP, the BGP router’s ASN is 7105, and IP address is

  1. Enable Anycast support on the VA. Enter:
    config anycast bgp enable 7105:
    config anycast bgp status

VA Output

Anycast is Enabled:
BGP ASN => 787744
BGP Router id =>
Anycast IP =>
BGP Neighbor:
IP =>
ASN => 7105

  1. On the router, configure the neighbour as the VA's ASN (787744).

Configure Dual-NIC Support < Configure Anycast > Appendix A – Updates

Updated 24 days ago

Configure Anycast

Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.