1 Answer
- Newest
- Most votes
- Most comments
2
At this moment you cannot associate multiple subnets from the same Availability Zone with a Client VPN endpoint. You can associate multiple subnets with a Client VPN endpoint for high availability. All subnets must be from the same VPC. Each subnet must belong to a different Availability Zone.
Refer Limitations and rules of Client VPN section - https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/what-is.html
Relevant content
- asked a year ago
- AWS OFFICIALUpdated 3 years ago
- AWS OFFICIALUpdated 3 years ago
- How do I get notified when the certificate associated to the Client VPN endpoint is about to expire?AWS OFFICIALUpdated a year ago
Can I associate multiple different VPN endpoints within different subnets within the same AZ? This is what is not working, but the docs are not clear.
The document calls out in the limitations here https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/what-is.html#what-is-limitations. Also is mentioned over here https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/cvpn-working-target.html
"If you associate more than one subnet with a Client VPN endpoint, each subnet must be in a different Availability Zone. We recommend that you associate at least two subnets to provide Availability Zone redundancy."