Low EC2 Regional

EC2 Client VPN endpoints should have client connection logging enabled

NIST 800-53PCI DSS v4.2.1PCI DSS v10.2.1ISO 27001HIPAA

Description

Ensures Client VPN endpoints have client connection logging enabled.


Remediation

Enable connection logging for your AWS Client VPN endpoint to track user activity and provide visibility into VPN connections.

Steps

  1. Open the Amazon VPC console.
  2. In the navigation pane, choose 'Client VPN Endpoints'.
  3. Select the Client VPN endpoint you want to modify.
  4. Choose 'Actions' and then 'Modify client VPN endpoint'.
  5. In the 'Connection logging' section, select 'Enable connection logging'.
  6. Choose a CloudWatch Logs log group for the connection logs.
  7. Choose 'Modify client VPN endpoint'.

Compliance

NIST 800-53PCI DSS v4.2.1PCI DSS v10.2.1ISO 27001HIPAA