generated: '2026-09-01' method: searched source: https://docs.aws.amazon.com/vpn/latest/s2svpn/tunnel-configure.html docs: - https://docs.aws.amazon.com/vpn/latest/s2svpn/tunnel-configure.html - https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-static-dynamic.html - https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-tunnel-authentication-options.html - https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/cvpn-getting-started.html - https://aws.amazon.com/compliance/programs/ derived_from: openapi/amazon-vpn-aws-vpn-api-amazon-ec2-query-api-subset-api-openapi.yml note: >- Two distinct layers are recorded separately below, because they are different claims. `api_standards` describes the HTTP contract, where AWS VPN conforms to almost nothing cross-cutting — no OAuth, no OIDC, no RFC 9457, no JSON:API. `domain_standards` describes the WIRE PROTOCOL the service actually implements, which is where AWS VPN is strongly standards-based: the whole product is an implementation of IETF IPsec/IKE, BGP and (for Client VPN) OpenVPN. Evidence points at the published option tables, not at a marketing claim. standards: - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in the OpenAPI and no OAuth documentation. Authorization is AWS IAM policy evaluated against a SigV4-signed request. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host — see well-known/amazon-vpn-well-known.yml. - id: aws-sigv4 conforms: true evidence: >- openapi securitySchemes SigV4 (apiKey in header Authorization); every VPN action requires an AWS4-HMAC-SHA256 signature. Unsigned requests return AuthFailure, observed live 2026-09-01. - id: rfc9457-problem-details conforms: false evidence: >- Errors are an AWS Query XML envelope (Response.Errors.Error.Code/Message), not application/problem+json. See errors/amazon-vpn-problem-types.yml. - id: json-api conforms: false evidence: Responses are text/xml; there is no JSON representation on the Query API. - id: idempotency conforms: true partial: true evidence: >- CreateVpnConnection is idempotent by default; AssociateClientVpnTargetNetwork, AuthorizeClientVpnIngress, CreateClientVpnEndpoint and CreateClientVpnRoute accept a ClientToken. 16 other mutating actions have no mechanism. See conventions/amazon-vpn-conventions.yml. - id: pagination conforms: false evidence: >- The Site-to-Site VPN Describe actions are unpaginated — no MaxResults, no NextToken. Server-side Filter.N filtering is offered instead. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation response headers are documented on the EC2 Query API. - id: rfc9116-security-txt conforms: true evidence: >- https://aws.amazon.com/.well-known/security.txt returned HTTP 200 on 2026-09-01 with Policy, Contact, Preferred-Languages, Encryption, Expires and Hiring fields. Saved verbatim to well-known/amazon-vpn-security.txt. - id: mcp conforms: true evidence: >- https://knowledge-mcp.global.api.aws/mcp answered a JSON-RPC initialize with protocolVersion 2025-03-26 and serverInfo AWSKnowledgeMCP 1.0.0, and tools/list with 5 tools. Probed 2026-09-01. See mcp/amazon-vpn-mcp.yml. - id: llms-txt conforms: true evidence: >- https://docs.aws.amazon.com/vpn/latest/s2svpn/llms.txt returned HTTP 200 (17,942 bytes) in llms.txt format. Saved verbatim to llms/amazon-vpn-llms.txt. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json missed on all four probed hosts (301/401/404). No card exists, so none was written. - id: ietf-ipsec name: IPsec (IP Security Architecture) conforms: true evidence: >- The VPN connection `Type` value in the API is literally `ipsec.1`; the Site-to-Site VPN product is an IPsec implementation. Tunnel option tables at docs.aws.amazon.com/vpn/latest/s2svpn/tunnel-configure.html enumerate the Phase 1 and Phase 2 IPsec parameters. spec_location: openapi Action=CreateVpnConnection, Type=ipsec.1 - id: ietf-ike name: Internet Key Exchange (IKEv1 and IKEv2) conforms: true versions: [IKEv1, IKEv2] evidence: >- tunnel-configure.html publishes selectable IKE versions (IKEv1, IKEv2). The 2021-09-21 document-history entry records IKEv2 parameter support added to the Download Configuration utility for customer gateway devices. - id: ike-crypto-suites name: IKE/IPsec cryptographic algorithm suites conforms: true evidence: >- Published selectable Phase 1/Phase 2 encryption algorithms AES128-GCM-16 and AES256-GCM-16, integrity algorithms SHA2-256, SHA2-384 and SHA2-512, and Diffie-Hellman group numbers — tunnel-configure.html option tables. - id: ietf-bgp4 name: BGP-4 (Border Gateway Protocol) conforms: true evidence: >- Dynamic routing on Site-to-Site VPN is BGP. The API takes a BGP ASN on CreateCustomerGateway and CreateVpnGateway (custom Amazon-side ASN, added 2017-10-10), and vpn-static-dynamic.html documents BGP route exchange with published advertised-route quotas (100 / 1,000 / 5,000 routes). spec_location: openapi Action=CreateCustomerGateway, BgpAsn parameter - id: nat-traversal name: IPsec NAT Traversal (NAT-T) conforms: true evidence: >- NAT traversal was added 2015-10-28 per the document history; the Large Bandwidth Tunnel requirements reference the NAT-T port explicitly. - id: openvpn name: OpenVPN protocol conforms: true scope: AWS Client VPN only evidence: >- "You can connect to the Client VPN endpoint using the AWS provided client or another OpenVPN-based client application and the configuration file that you just created." — clientvpn-admin/cvpn-getting-started.html. Client certificates are generated with the OpenVPN easy-rsa utility. - id: x509-mutual-tls name: X.509 certificate mutual authentication conforms: true evidence: >- Site-to-Site VPN tunnel endpoints can authenticate with a private certificate from AWS Private Certificate Authority (vpn-tunnel-authentication-options.html); Client VPN mutual authentication uses server and client certificates held in ACM. domain_standard: market: network connectivity / secure hybrid networking declared: true primary: ietf-ipsec supporting: [ietf-ike, ike-crypto-suites, ietf-bgp4, nat-traversal, openvpn, x509-mutual-tls] note: >- AWS VPN's market DOES have a standard, and AWS implements it rather than a proprietary tunnel. A buyer who already speaks IPsec/IKEv2 and BGP integrates a customer gateway device with no bespoke connector — which is exactly the distinction this field exists to draw. Evidence is the published tunnel option tables and the API's own `Type=ipsec.1` and `BgpAsn` parameters, not a marketing page. standards_ids: [ietf-ipsec, ietf-ike, ike-crypto-suites, ietf-bgp4, nat-traversal, openvpn, x509-mutual-tls] compliance_programs: published: true url: https://aws.amazon.com/compliance/programs/ certifications: - SOC 2 - ISO 27001 - PCI DSS - HIPAA - FedRAMP - GDPR - FIPS 140 see_also: security/amazon-vpn-trust-center.yml note: >- Certifications are held by Amazon Web Services and apply to AWS VPN as an in-scope service. They are an AWS-level compliance program, not a VPN-specific one.