AWS AWSEC2: Updated ENI quota reference for application status checks
Summary
Clarified that managed ENIs count against 'Network interfaces per Region' quota (enforced per AZ) instead of global ENI limit per VPC.
Security assessment
The change updates quota terminology but doesn't address vulnerabilities, security controls, or attack vectors. It's an operational clarification about resource limits.
Evidence
+ 8. _Available ENI quota._ AWS creates a managed elastic network interface (ENI) in your account for each source subnet and security group combination. Confirm your account has not reached its _Network interfaces per Region_ quota, which is enforced per Availability Zone. If your account has reached this quota, AWS cannot create the managed ENI and the check cannot run. For more information, see [Amazon VPC quotas](https://docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html).
Diff
diff --git a/AWSEC2/latest/UserGuide/application-status-checks.md b/AWSEC2/latest/UserGuide/application-status-checks.md index 2433f73d1..f9ccf7353 100644 --- a//AWSEC2/latest/UserGuide/application-status-checks.md +++ b//AWSEC2/latest/UserGuide/application-status-checks.md @@ -60 +60 @@ During a reboot, application status checks report a failure until the instance b -Application status checks originate from the Amazon EC2 application status checks service. To reach your instances, AWS creates a managed elastic network interface (ENI) in your VPC. AWS creates one ENI per combination of source subnet and security group that has associated instances. AWS creates the managed ENI when an application status check first requires that combination, and removes it when no remaining application status check requires it. The managed ENI does not count against your instance ENI limit, but does count against your global limit for ENIs per VPC. +Application status checks originate from the Amazon EC2 application status checks service. To reach your instances, AWS creates a managed elastic network interface (ENI) in your VPC. AWS creates one ENI per combination of source subnet and security group that has associated instances. AWS creates the managed ENI when an application status check first requires that combination, and removes it when no remaining application status check requires it. The managed ENI does not count against your instance ENI limit, but does count against the _Network interfaces per Region_ quota for your account, which is enforced per Availability Zone. For more information, see [Amazon VPC quotas](https://docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html). @@ -445 +445 @@ When an application status check reports impaired but you expect your applicatio - 8. _Available ENI quota._ AWS creates a managed elastic network interface (ENI) in your account for each source subnet and security group combination. Confirm your account has an available ENI in its quota for the VPC. If your account has reached its ENIs per VPC quota, AWS cannot create the managed ENI and the check cannot run. For more information, see [Amazon VPC quotas](https://docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html). + 8. _Available ENI quota._ AWS creates a managed elastic network interface (ENI) in your account for each source subnet and security group combination. Confirm your account has not reached its _Network interfaces per Region_ quota, which is enforced per Availability Zone. If your account has reached this quota, AWS cannot create the managed ENI and the check cannot run. For more information, see [Amazon VPC quotas](https://docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html).