How to debug a Site-to-Site VPN tunnel IPSec on AWS?

Viewed 719

Is it possible to access logs of a Site-to-Site VPN connection IPsec tunnel establishment? If the tunnel establishment is failing, there's no visibility on the AWS side of what is the reason.

If accessing the logs is not possible, is it possible to inspect packets at the Site-to-Site VPN endpoint on the AWS side? I tried creating a Traffic Mirror Session, but couldn't feed it the right ENI as the source. I can't find the ENI interfaces that are created by transit gateway VPN attachments. This information is not returned by any of these commands.

$ aws ec2 describe-vpn-connections
$ aws ec2 describe-transit-gateways
$ aws ec2 describe-transit-gateway-attachments
1 Answers

Site-to-Site VPN connection logging was announced in August, 2022:

The Terraform aws provider v4.30.0 also added this configuration:

If you’ve created a VPN but there are no attempts to connect, you won’t see any logs. CloudWatch Logs encrypts logs at rest by default; however, if you want control over the key or want to rotate encryption keys, you can use KMS to encrypt the logs. You can see how to grant CloudWatch permissions to the KMS key here:

A user viewing the log doesn’t permission to access to the key in KMS. The key is just used by the KMS services to encrypt the data at rest. The IAM permissions mentioned in the documentation are the permissions required of the user or role to enable VPN connection logging. You don’t need to change the service linked role. Note, you'll only see a service linked role when using a customer gateway with certificate authentication:

Related