AWS Security ChangesHomeSearch

AWS outposts medium security documentation change

Service: outposts · 2026-02-22 · Security-related medium

File: outposts/latest/network-userguide/private-connectivity.md

Summary

Added IP planning guidance to prevent Service Link conflicts

Security assessment

New section explicitly warns about IP range conflicts causing BGP routing failures. This documents security-critical network configuration requirements to prevent service disruption.

Diff

diff --git a/outposts/latest/network-userguide/private-connectivity.md b/outposts/latest/network-userguide/private-connectivity.md
index ffce1dd7a..3ad72759f 100644
--- a//outposts/latest/network-userguide/private-connectivity.md
+++ b//outposts/latest/network-userguide/private-connectivity.md
@@ -22,0 +23,4 @@ Second-generation Outposts racks require a larger subnet size (/24 or larger) an
+###### IP Address Planning for Private Connectivity
+
+When configuring private connectivity for the Outposts service link, plan your IP addressing carefully to avoid future conflicts. Service Link VIFs are immutable. You cannot create CoIP pools or DVR subnet ranges assigned to the Local Gateway (LGW) that overlap with existing Service Link address ranges or VPC CIDR ranges used for the dedicated private connectivity VPC, as they will cause BGP routing conflicts and affect Service Link functionality.
+