# AWS243 Supplied Client VPN Cases

Fictional/redacted evidence. Diagnose only.

## 1. TLS server certificate

Endpoint name resolves. Client log reports certificate expired yesterday; ACM metadata confirms `NotAfter`. No connection-attempt record exists. Identify why authorization is irrelevant, the renewal/change propagation risk, and rollback.

## 2. Mutual certificate revoked

Server certificate is valid. Client certificate serial appears in the current CRL; client reports mutual TLS failure. Connection logging has no failed event. Explain this expected blind spot and proper identity-specific recovery—do not remove the whole CRL.

## 3. SAML group mismatch

Tunnel authentication fails for finance users. Signed assertion has correct audience/time/NameID but sends `memberof`; configured group rules require exact case-sensitive `memberOf`. Local port 35001 and browser flow work. Identify first failure and IdP-side verification.

## 4. Missing authorization

User connects and receives client IP. Route `10.40.0.0/16` is active. Authorization covers `10.30.0.0/16` only. SG and return path for `10.40.5.20:443` are valid. Explain route versus authorization and choose narrow group access.

## 5. Unequal association routes

Two VPC subnet associations exist in AZ-a/AZ-b. Destination route exists only through AZ-a. Users intermittently fail after reconnecting through AZ-b. Explain identical-destination requirement, change reset implications under split tunnel, and multi-AZ proof.

## 6. DNS server unreachable

Session connects; private IP connection succeeds. Endpoint pushes DNS `10.0.2.53`, but no endpoint route or authorization covers that subnet. Both UDP/TCP 53 controls would allow traffic. Identify why editing the private hosted zone is not first.

## 7. Overlapping client network

Client CIDR is `10.50.0.0/22`; user's home LAN is `10.50.0.0/24`. Client sends internal destination traffic to its local LAN despite a healthy endpoint. Endpoint client CIDR cannot be modified. Explain redesign/replacement and migration rollback instead of a route hack.

## 8. TGW return path

TGW-associated endpoint preserves client `10.60.0.14`. Endpoint route and authorization cover spoke `10.70.0.0/16`; TGW forward route is correct. Spoke subnet has no route for `10.60.0.0/22` back to TGW. SG allows client CIDR. Find the first reverse-path failure and prove symmetry after correction.

## Cross-case review

For every case record first failed gate, safe evidence, correction owner, rollback, reset/reconnect impact, retest, prevention, and cost implication.
