Home icon

Prevent VPN traffic leaks with Client VPN Route Enforcement in AWS Client VPN

Networking & Content Delivery Blog



This article explains Client Route Enforcement, a new AWS Client VPN feature that prevents VPN traffic leaks by monitoring and correcting routing table modifications on connected devices.

  • Continuously monitors device routing tables and removes conflicting routes that divert traffic outside the VPN tunnel
  • Protects against DHCP-based route injection attacks like TunnelVision (CVE-2024-3661) and rogue network configurations
  • Works with both split-tunnel and full-tunnel VPN configurations, supporting IPv4, IPv6, and dual-stack endpoints
  • Requires AWS-provided VPN client version 5.2.0 or higher (5.3.0 for IPv6)
  • Activated via Amazon VPC console or AWS CLI with no infrastructure changes needed
  • Complements authorization rules and should be paired with EDR or MDM solutions for comprehensive security

Client Route Enforcement integrates seamlessly with existing Client VPN deployments to maintain routing integrity and ensure remote access traffic follows intended paths.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Apr 28
2025
AWS Client VPN now supports Client Routes Enforcement
Mar 18
2025
AWS Client VPN increases authorization rules and route quotas
Jul 30
2024
Integrating AWS Client VPN with AWS Network Firewall
Jan 30
2026
Streamline AWS Client VPN usage reporting with Amazon CloudWatch Logs Insights queries

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.