VPN

VPN gateway.

class: Network

Realizing resources

aws aws

resourcescopeenumeraterequired permissions
aws:directconnect:connection regional directconnect:DescribeConnections directconnect:DescribeConnections

Exposure sites

None.

Rules that touch VPN 7

A CA-issued certificate authenticates as the downstream identity a trust consumer maps it to.
An active S2S VPN connection (vpnConnections, connectionStatus=Connected) is an explicit routing fact: the Virtual Hub routes traffic to and from the on-premises branch via the VPN tunnel.
azure RoutesTo
Issue a cert for an attacker-chosen subject/SAN that a downstream trust accepts, impersonating that identity.
An internal Application Load Balancer or internal passthrough NLB (loadBalancingScheme INTERNAL or INTERNAL_MANAGED) is reachable only from within the VPC, peered VPCs, or connected on-premises networks. A compute resource with a foothold in the same VPC can reach the internal LB frontend and, through it, the backends.
A source whose subnet routes to the destination's subnet (intra-VPC/VNet routing) reaches the destination when its ingress rule admits the source.
A source reaches a destination through a shared transit hub (Transit Gateway/VWAN/NCC/Direct Connect gateway/VPN gateway) that forwards between attachments - transitive across the hub's associated route table.
move · open · esc close