Checks whether the health check feature is enabled for each IPsec-VPN connection.
Scenario
The health check feature helps you monitor IPsec-VPN connections. We recommend that you enable this feature for each IPsec-VPN connection.
Risk level
Default risk level: low.
You can change the risk level as required when you apply this rule.
Compliance evaluation logic
- If the health check feature is enabled for each IPsec-VPN connection, the evaluation result is compliant.
- If the health check feature is disabled for an IPsec-VPN connection, the evaluation result is non-compliant. For more information about how to correct the non-compliant configuration, see Non-compliance remediation.
Rule details
Item | Description |
---|---|
Rule name | vpn-ipsec-connection-health-check-open |
Rule ID | vpn-ipsec-connection-health-check-open |
Tag | IPsec, VPN, and Connection |
Automatic remediation | Not supported |
Trigger type | Configuration change |
Supported resource type | IPsec-VPN connection |
Input parameter | None |
Non-compliance remediation
Enable the health check feature for the IPsec-VPN connection. For more information, see Modify an IPsec-VPN connection.