Checks whether encryption algorithms are enabled for VPN connections to ensure data confidentiality and integrity.
Scenarios
Configure encryption algorithms for VPN connections to protect the confidentiality and integrity of transferred data.
Risk level
Default risk level: high.
You can change the risk level based on your business requirements when you apply this rule.
Compliance evaluation logic
- If an encryption algorithm is enabled for each VPN connection, the evaluation result is Compliant.
- If no encryption algorithm is enabled for any VPN connection, the evaluation result is Incompliant. To remediate this, see the "Incompliance remediation" section of this topic.
Rule details
| Parameter | Description |
| Rule name | vpn-ipsec-connection-encrypt-enable |
| Rule ID | vpn-ipsec-connection-encrypt-enable |
| Tag | VPN and VpnGateway |
| Automatic remediation | Not supported |
| Trigger type | Periodic execution |
| Evaluation frequency | Interval of 24 hours |
| Supported resource type | IPsec-VPN connection |
| Input parameter | None |
Incompliance remediation
Enable encryption algorithms for your VPN connections. For more information, see VPN gateway.