EC2 Client VPN endpoints should have client connection logging enabled

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

This control verifies if client connection logging is enabled for an AWS Client VPN endpoint. AWS Client VPN endpoints facilitate secure connections between remote clients and resources within a Virtual Private Cloud (VPC). Enabling connection logging enhances visibility by allowing you to monitor user activity on the VPN endpoint. When connection logging is activated, you can assign a log stream name within a log group, or if none is specified, the Client VPN service automatically generates one.

Remediation

For instructions on configuring logging, refer to the Enable connection logging for an existing Client VPN endpoint section of the AWS Client VPN Administrator Guide.