AWS Security ChangesHomeSearch

AWS vpn: Remove docs for modifying endpoints to dual-stack IP types

Service: vpn · 2026-09-27 · Documentation low

File: vpn/latest/clientvpn-admin/cvpn-working-endpoint-modify.md

Summary

Removes the guidance that existing IPv4 Client VPN endpoints can be modified to dual-stack for both endpoint IP and traffic IP types, removes the corresponding console steps (Endpoint IP address type and Traffic IP address type), removes the accompanying note about IPv6-only endpoints, and deletes the CLI example using --endpoint-ip-address-type/--traffic-ip-address-type. Remaining steps are renumbered accordingly; their security-related content (server certificate ARN, client connect handler, DNS servers, split-tunnel, security groups, session timeout, login banner) is unchanged aside from numbering.

Security assessment

The change only removes documentation of a dual-stack address-type modification feature and renumbers the remaining numbered steps; it does not fix a vulnerability or introduce/describe any new security control. The lines touching certificates, client connect handler, DNS, split-tunnel and security groups are reworded only by step number, so there is no concrete security implication.

Evidence

-  * You can modify existing IPv4 endpoints to dual-stack for both endpoint IP and traffic IP types. If you need IPv6-only for endpoint IP and traffic IP, you must create a new endpoint.

Diff

diff --git a/vpn/latest/clientvpn-admin/cvpn-working-endpoint-modify.md b/vpn/latest/clientvpn-admin/cvpn-working-endpoint-modify.md
index 18bf1935d..f0c68e0a9 100644
--- a//vpn/latest/clientvpn-admin/cvpn-working-endpoint-modify.md
+++ b//vpn/latest/clientvpn-admin/cvpn-working-endpoint-modify.md
@@ -21,2 +20,0 @@ The following limitations apply when modifying an endpoint
-  * You can modify existing IPv4 endpoints to dual-stack for both endpoint IP and traffic IP types. If you need IPv6-only for endpoint IP and traffic IP, you must create a new endpoint.
-
@@ -46,5 +44 @@ You can modify a Client VPN endpoint using either the console or the AWS CLI.
-  5. For **Endpoint IP address type** , you can modify an existing IPv4 endpoint to dual-stack. This option is only available for IPv4 endpoints.
-
-  6. For **Traffic IP address type** , you can modify an existing IPv4 endpoint to dual-stack. This option is only available for IPv4 endpoints.
-
-  7. For **Server certificate ARN** , specify the ARN for the TLS certificate to be used by the server. Clients use the server certificate to authenticate the Client VPN endpoint to which they are connecting.
+  5. For **Server certificate ARN** , specify the ARN for the TLS certificate to be used by the server. Clients use the server certificate to authenticate the Client VPN endpoint to which they are connecting.
@@ -56 +50 @@ The server certificate must be present in AWS Certificate Manager (ACM) in the r
-  8. Specify whether to log data about client connections using Amazon CloudWatch Logs. For **Enable log details on client connections** , do one of the following:
+  6. Specify whether to log data about client connections using Amazon CloudWatch Logs. For **Enable log details on client connections** , do one of the following:
@@ -62 +56 @@ The server certificate must be present in AWS Certificate Manager (ACM) in the r
-  9. For **Client connect handler** , to activate the [client connect handler](./connection-authorization.html) turn on **Enable client connect handler**. For **Client Connect Handler ARN** , specify the Amazon Resource Name (ARN) of the Lambda function that contains the logic that allows or denies connections.
+  7. For **Client connect handler** , to activate the [client connect handler](./connection-authorization.html) turn on **Enable client connect handler**. For **Client Connect Handler ARN** , specify the Amazon Resource Name (ARN) of the Lambda function that contains the logic that allows or denies connections.
@@ -64 +58 @@ The server certificate must be present in AWS Certificate Manager (ACM) in the r
-  10. Turn on or off **Enable DNS servers**. To use custom DNS servers, for **DNS Server 1 IP address** and **DNS Server 2 IP address** , specify the IPv4 addresses of the DNS servers to use. For IPv6 or dual-stack endpoints, you can also specify **DNS Server IPv6 1** and **DNS Server IPv6 2** addresses. To use VPC DNS server, for either **DNS Server 1 IP address** or **DNS Server 2 IP address** , specify the IP addresses, and add the VPC DNS server IP address.
+  8. Turn on or off **Enable DNS servers**. To use custom DNS servers, for **DNS Server 1 IP address** and **DNS Server 2 IP address** , specify the IPv4 addresses of the DNS servers to use. For IPv6 or dual-stack endpoints, you can also specify **DNS Server IPv6 1** and **DNS Server IPv6 2** addresses. To use VPC DNS server, for either **DNS Server 1 IP address** or **DNS Server 2 IP address** , specify the IP addresses, and add the VPC DNS server IP address.
@@ -70 +64 @@ Verify that the DNS servers can be reached by clients.
-  11. Turn on or off **Enable split-tunnel**. By default, split-tunnel on a VPN endpoint is off.
+  9. Turn on or off **Enable split-tunnel**. By default, split-tunnel on a VPN endpoint is off.
@@ -72 +66 @@ Verify that the DNS servers can be reached by clients.
-  12. For **VPC ID** , choose the VPC to associate with the Client VPN endpoint. For **Security Group IDs** , choose one or more of the VPC's security groups to apply to the Client VPN endpoint.
+  10. For **VPC ID** , choose the VPC to associate with the Client VPN endpoint. For **Security Group IDs** , choose one or more of the VPC's security groups to apply to the Client VPN endpoint.
@@ -74 +68 @@ Verify that the DNS servers can be reached by clients.
-  13. For **VPN port** , choose the VPN port number. The default is 443.
+  11. For **VPN port** , choose the VPN port number. The default is 443.
@@ -76 +70 @@ Verify that the DNS servers can be reached by clients.
-  14. To generate a [self-service portal URL](./cvpn-self-service-portal.html) for clients, turn on **Enable self-service portal**.
+  12. To generate a [self-service portal URL](./cvpn-self-service-portal.html) for clients, turn on **Enable self-service portal**.
@@ -78 +72 @@ Verify that the DNS servers can be reached by clients.
-  15. For **Session timeout hours** , choose the desired maximum VPN session duration time in hours from the available options, or leave set to default of 24 hours.
+  13. For **Session timeout hours** , choose the desired maximum VPN session duration time in hours from the available options, or leave set to default of 24 hours.
@@ -80 +74 @@ Verify that the DNS servers can be reached by clients.
-  16. For **Disconnect on session timeout** , choose if you want to terminate the session when the maximum session time is reached. Choosing this option requires that users reconnect manually to the endpoint when the session times out; otherwise, Client VPN will automatically try to reconnect.
+  14. For **Disconnect on session timeout** , choose if you want to terminate the session when the maximum session time is reached. Choosing this option requires that users reconnect manually to the endpoint when the session times out; otherwise, Client VPN will automatically try to reconnect.
@@ -82 +76 @@ Verify that the DNS servers can be reached by clients.
-  17. Turn on or off **Enable client login banner**. If you want to use the client login banner, enter the text that will be displayed in a banner on AWS provided clients when a VPN session is established. UTF-8 encoded characters only. Maximum of 1400 characters.
+  15. Turn on or off **Enable client login banner**. If you want to use the client login banner, enter the text that will be displayed in a banner on AWS provided clients when a VPN session is established. UTF-8 encoded characters only. Maximum of 1400 characters.
@@ -84 +78 @@ Verify that the DNS servers can be reached by clients.
-  18. Choose **Modify Client VPN endpoint**.
+  16. Choose **Modify Client VPN endpoint**.
@@ -93,9 +86,0 @@ Use the [modify-client-vpn-endpoint](https://docs.aws.amazon.com/cli/latest/refe
-Example for modifying an IPv4 endpoint to dual-stack:
-    
-    
-    aws ec2 modify-client-vpn-endpoint \
-      --client-vpn-endpoint-id cvpn-endpoint-123456789123abcde \
-      --endpoint-ip-address-type "dual-stack" \
-      --traffic-ip-address-type "dual-stack" \
-      --client-cidr-block "172.31.0.0/16"
-