If an encryption algorithm is enabled for each VPN connection, the evaluation result is Compliant.

Scenarios

You can configure encrypted certificates to encrypt transferred data. This can ensure data confidentiality and integrity during data transfer.

Risk level

Default risk level: high.

When you apply this rule, you can change the risk level based on your business requirements.

Compliance evaluation logic

  • If an encryption algorithm is enabled for each VPN connection, the evaluation result is Compliant.
  • If no encryption algorithm is enabled for any VPN connection, the evaluation result is Incompliant. For more information about how to remediate an incompliant configuration, see the "Incompliance remediation" section of this topic.

Rule details

ParameterDescription
Rule namevpn-ipsec-connection-encrypt-enable
Rule IDvpn-ipsec-connection-encrypt-enable
TagVPN and VpnGateway
Automatic remediationNot supported
Trigger typePeriodic execution
Evaluation frequencyInterval of 24 hours
Supported resource typeIPsec-VPN connection
Input parameterNone

Incompliance remediation

Enable encryption algorithms for your VPN connections. For more information, see Create and manage a VPN gateway.