Prevent VPN traffic leaks with Client VPN Route Enforcement in AWS Client VPN
Networking & Content Delivery Blog
This article explains Client Route Enforcement, a new AWS Client VPN feature that prevents VPN traffic leaks by monitoring and correcting routing table modifications on connected devices.
- Continuously monitors device routing tables and removes conflicting routes that divert traffic outside the VPN tunnel
- Protects against DHCP-based route injection attacks like TunnelVision (CVE-2024-3661) and rogue network configurations
- Works with both split-tunnel and full-tunnel VPN configurations, supporting IPv4, IPv6, and dual-stack endpoints
- Requires AWS-provided VPN client version 5.2.0 or higher (5.3.0 for IPv6)
- Activated via Amazon VPC console or AWS CLI with no infrastructure changes needed
- Complements authorization rules and should be paired with EDR or MDM solutions for comprehensive security
Client Route Enforcement integrates seamlessly with existing Client VPN deployments to maintain routing integrity and ensure remote access traffic follows intended paths.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.