Low
EC2
Regional
EC2 Client VPN endpoints should have client connection logging enabled
NIST 800-53PCI DSS v4.2.1PCI DSS v10.2.1ISO 27001HIPAA
Description
Ensures Client VPN endpoints have client connection logging enabled.
Remediation
Enable connection logging for your AWS Client VPN endpoint to track user activity and provide visibility into VPN connections.
Steps
- Open the Amazon VPC console.
- In the navigation pane, choose 'Client VPN Endpoints'.
- Select the Client VPN endpoint you want to modify.
- Choose 'Actions' and then 'Modify client VPN endpoint'.
- In the 'Connection logging' section, select 'Enable connection logging'.
- Choose a CloudWatch Logs log group for the connection logs.
- Choose 'Modify client VPN endpoint'.
Compliance
NIST 800-53PCI DSS v4.2.1PCI DSS v10.2.1ISO 27001HIPAA