AWS Client VPN with SSO doesn't work - suddenly

0

Hello,

For a specific account (managed by our Control Tower) I have set up two VPNs: Site2Site, so we can connect directly to the servers and services from the office and Client VPN for remote users.

I also set up the client VPN with Google SSO. As long as there are users in the AWS AD, those same users can also connect via VPN using Google SSO. THIS worked since I created it more than 6 months ago. Suddenly it doesn't work anymore! There has been no change from my side.

According to the log file, the last client VPN SSO connections were in September (07th + 21st).

When I try to connect (from home), it always just says: "Re-establishing connection."

But one thing is noticeable: in the logfile you can find the entry: RESOLVE: Cannot resolve host address: 9c19xxxxxxx.cvpn-endpoint-xxxxxxxxxx.prod.clientvpn.xxxxxxx.amazonaws.com:443 (No such host is known. ) This is probably the reason that no browser tab opens to connect to the Google account.

But I have no influence on this name, it comes from AWS. I also re-downloaded the VPN profile from AWS, same result.

This did NOT help either: https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/troubleshooting.html (Endpoint name)

Finally, my configuration was not changed (so AWS must have changed something or something is broken). Google SSO everything looks fine. I am at a loss here.

The help I got from the Business Support (we don't have premium/technical support) is not helpful because they sent me some links which will explain how to configure VPNs or troubleshoot other issues.

So, what's wrong here?

Thx.

asked a year ago321 views
1 Answer
1

Can you ping a public ip address?

Also have you tried this?

Check whether you are able to resolve the DNS name.
* If you are unable to resolve the DNS name, verify that you have specified the DNS servers for the Client VPN endpoint. 
* If you manage your own DNS server, specify its IP address. Verify that the DNS server is accessible from the VPC.
* If you're unsure about which IP address to specify for the DNS servers, specify the VPC DNS resolver at the .2 IP address in your VPC.
AWS
answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions