# AWS243 Client VPN Operations Workbook

## Safety and scope

- Case/endpoint type:
- Account/Region (redacted):
- UTC window:
- Client OS/client version:
- Expected identity/group:
- Expected destination/protocol/port:
- No profile, key, assertion, or full log shared: Yes / No
- No AWS/production change: Yes / No

## Gate analysis

| Gate | Expected | Evidence | Healthy / failed / unknown |
|---|---|---|---|
| Local network and endpoint DNS | | | |
| TLS server certificate | | | |
| Client/user authentication | | | |
| Client IP/session | | | |
| Authorization destination/group | | | |
| Endpoint route | | | |
| Association/TGW route | | | |
| SG/NACL/firewall | | | |
| DNS server/private zone | | | |
| Application and return path | | | |

## Endpoint architecture

- Endpoint and traffic IP types:
- Client CIDR and overlap/capacity check:
- VPC-subnet or TGW association:
- SNAT/source observed by destination:
- AZ associations and consistency:
- Split or full tunnel:
- Client routes before/after connection:
- DNS servers and their route/authorization:

## Authentication and certificate lifecycle

- Server certificate Region/validity/chain:
- Mutual CA/client cert/CRL evidence:
- AD directory/MFA/group evidence:
- SAML signature/time/audience/NameID/memberOf evidence:
- Profile owner/version/distribution:
- Propagation/reset consideration:

## Diagnosis and response

- First failed gate:
- Root cause/proof:
- Unknowns:
- Smallest correction/owner:
- Blast radius:
- Rollback:
- Reconnect/reset communication:
- Layer retest:
- End-to-end retest:
- Prevention:

## Cost and closeout

- Association-hours:
- Connection-hours/concurrency:
- Public IPv4:
- Transfer/NAT/TGW:
- Logs/Lambda/directory/PKI:
- Pricing Region/date:
- Before/after inventory:
- Changes: None
