I want to know why I received a notification in my Health Dashboard that AWS replaced an endpoint for my AWS Site-to-Site VPN connection.
Resolution
AWS Site-to-Site VPN replaces one or both of your tunnel endpoints for the following reasons:
- You use the AWS Management Console, AWS Command Line Interface (AWS CLI), or SDK to modify components of your Site-to-Site VPN connection.
- AWS performs maintenance on your Site-to-Site VPN connection.
Note: AWS Site-to-Site VPN updates one of your tunnels at a time. When Site-to-Site VPN replaces your tunnel endpoint, your endpoint's outside IP address doesn't change.
When AWS Site-to-Site VPN replaces a tunnel endpoint, Health Dashboard and the primary email that's associated with your AWS account receive a notification.
If a tunnel is in the UP status when Site-to-Site VPN replaces the tunnel, then its status changes to DOWN. The tunnel remains in the DOWN status until AWS or your customer gateway device initiates an Internet Key Exchange (IKE) negotiation. If you configured your tunnel to use IKEv2 and its start-up action is Start, then AWS initiates IKE negotiation. If you configured your tunnel with IKEv1 and its startup action is Add, then the tunnel remains DOWN after AWS Site-to-Site VPN replaces the endpoint. It remains down until the customer gateway device initiates an IKE negotiation.
Configure two VPN tunnels
To avoid traffic interruptions when AWS Site-to-Site VPN replaces your tunnels, be sure to configure two tunnels. For more information, see Redundancy.
Important: It's a best practice to use dynamic routing, also known as Border Gateway Protocol (BGP), instead of static routing. For more information, see Static and dynamic routing.
Check that your customer gateway device supports BGP. If your customer gateway device supports BGP, then configure your connection to use dynamic routing. If your device doesn't support BGP, then configure your connection to use static routing. Be sure to configure your static VPN to avoid asymmetric routing.
Add a contact for Health Dashboard notifications
To receive notifications from a different email address, update the alternate contacts for your AWS account.