AWS Client VPN with SSO doesn't work - suddenly

0

Hello,

For a specific account (managed by our Control Tower) I have set up two VPNs: Site2Site, so we can connect directly to the servers and services from the office and Client VPN for remote users.

I also set up the client VPN with Google SSO. As long as there are users in the AWS AD, those same users can also connect via VPN using Google SSO. THIS worked since I created it more than 6 months ago. Suddenly it doesn't work anymore! There has been no change from my side.

According to the log file, the last client VPN SSO connections were in September (07th + 21st).

When I try to connect (from home), it always just says: "Re-establishing connection."

But one thing is noticeable: in the logfile you can find the entry: RESOLVE: Cannot resolve host address: 9c19xxxxxxx.cvpn-endpoint-xxxxxxxxxx.prod.clientvpn.xxxxxxx.amazonaws.com:443 (No such host is known. ) This is probably the reason that no browser tab opens to connect to the Google account.

But I have no influence on this name, it comes from AWS. I also re-downloaded the VPN profile from AWS, same result.

This did NOT help either: https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/troubleshooting.html (Endpoint name)

Finally, my configuration was not changed (so AWS must have changed something or something is broken). Google SSO everything looks fine. I am at a loss here.

The help I got from the Business Support (we don't have premium/technical support) is not helpful because they sent me some links which will explain how to configure VPNs or troubleshoot other issues.

So, what's wrong here?

Thx.

질문됨 일 년 전329회 조회
1개 답변
1

Can you ping a public ip address?

Also have you tried this?

Check whether you are able to resolve the DNS name.
* If you are unable to resolve the DNS name, verify that you have specified the DNS servers for the Client VPN endpoint. 
* If you manage your own DNS server, specify its IP address. Verify that the DNS server is accessible from the VPC.
* If you're unsure about which IP address to specify for the DNS servers, specify the VPC DNS resolver at the .2 IP address in your VPC.
AWS
답변함 일 년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠