Checks whether the health check feature is enabled for each IPsec-VPN connection.

Scenario

The health check feature helps you monitor IPsec-VPN connections. We recommend that you enable this feature for each IPsec-VPN connection.

Risk level

Default risk level: low.

You can change the risk level as required when you apply this rule.

Compliance evaluation logic

  • If the health check feature is enabled for each IPsec-VPN connection, the evaluation result is compliant.
  • If the health check feature is disabled for an IPsec-VPN connection, the evaluation result is non-compliant. For more information about how to correct the non-compliant configuration, see Non-compliance remediation.

Rule details

Item Description
Rule name vpn-ipsec-connection-health-check-open
Rule ID vpn-ipsec-connection-health-check-open
Tag IPsec, VPN, and Connection
Automatic remediation Not supported
Trigger type Configuration change
Supported resource type IPsec-VPN connection
Input parameter None

Non-compliance remediation

Enable the health check feature for the IPsec-VPN connection. For more information, see Modify an IPsec-VPN connection.