AWS VPN service outage due to DNS not resolve

1

Hi,

We have three AWS accounts that have AWS VPN Client services configured. Two of them are not working. The issue started happening suddenly on January 14 2022 (with no known changes to our configurations).

I have sanity checked our OVPN configurations. Booting up my Wireshark on my laptop, it seems that the reason why I could not connect is likely due to failure to resolve DNS A records related AWS VPN related services.

I saw the following DNS names got queried (all of which the DNS servers responded with "Standard query response, No such name"):

For the first account, DNS A record queries that failed:

  1. ed-<REDACTED>.cvpn-endpoint-0a<REDACTED>..prod.clientvpn.us-east-1.amazonaws.com
  2. 00-<REDACTED>.cvpn-endpoint-0a<REDACTED>..prod.clientvpn.us-east-1.amazonaws.com
  3. .cv-<REDACTED>-0a<REDACTED>..prod.clientvpn.us-east-1.amazonaws.com
  4. a4-<REDACTED>.cvpn-endpoint-0a<REDACTED>..prod.clientvpn.us-east-1.amazonaws.com
  5. 82-<DREDACTED>.cvpn-endpoint-0a<REDACTED>..prod.clientvpn.us-east-1.amazonaws.com

For the second account, DNS A record queries that failed:

  1. 12-<REDACTED>.cvpn-endpoint-0c-<REDACTED>.prod.clientvpn.us-east-1.amazonaws.com

DNS servers (mine and some others on the Internet) could not resolve those. So, it's unlikely just my DNS servers as I checked it against multiple DNS servers.

Is AWS Client VPN currently experiencing outage? Is it just more widespread than issues in my two accounts? Or is my configuration wrong somewhere?

Thanks, Rob

已提問 2 年前檢視次數 425 次
1 個回答
0
已接受的答案

We managed to get them "resolved"; at least whatever seemingly irrelevant things I did managed not to trigger this bug.

  1. I went to the Client VPN endpoint settings and found that there were some lingering security group associations that show up in GuI but the underlying SG is already gone. I deleted those SGs.
  2. Turn logging settings off and then back on again

Those actions do not seem to be directly related to AWS not being able to resolve VPN endpoint DNS -- but somehow correlated with the fixes.

已回答 2 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南