GetClientVpnEndpointAuthorizationPolicy
Describes the authorization policy for a Client VPN endpoint.
Request Parameters
The following parameters are for this specific action. For more information about required and optional parameters that are common to all actions, see Common Query Parameters.
- ClientVpnEndpointId
-
The ID of the Client VPN endpoint.
Type: String
Required: Yes
- DryRun
-
Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is
DryRunOperation. Otherwise, it isUnauthorizedOperation.Type: Boolean
Required: No
Response Elements
The following elements are returned by the service.
- clientVpnEndpointId
-
The ID of the Client VPN endpoint.
Type: String
- description
-
A brief description of the authorization policy.
Type: String
- policyDocument
-
The authorization policy document, written in the Cedar policy language.
Type: String
- requestId
-
The ID of the request.
Type: String
- shadowMode
-
Specifies whether the authorization policy is evaluated in shadow mode. Possible values include:
-
enabled- The authorization policy is evaluated and the results are logged, but access is not enforced. -
disabled- The authorization policy is enforced.
Type: String
Valid Values:
enabled | disabled -
- status
-
The current state of the authorization policy.
Type: String
Valid Values:
creating | updating | active | failed | deleting
Errors
For information about the errors that are common to all actions, see Common Error Types.
Examples
Example
This example describes the authorization policy for a Client VPN endpoint.
Sample Request
https://ec2.amazonaws.com/?Action=GetClientVpnEndpointAuthorizationPolicy
&ClientVpnEndpointId=cvpn-endpoint-00c5d11fc4EXAMPLE
&AUTHPARAMS
Sample Response
<GetClientVpnEndpointAuthorizationPolicyResponse xmlns="http://ec2.amazonaws.com/doc/2016-11-15/">
<requestId>691de4ea-32ef-447b-b4f8-d8463EXAMPLE</requestId>
<clientVpnEndpointId>cvpn-endpoint-00c5d11fc4EXAMPLE</clientVpnEndpointId>
<policyDocument>permit(principal, action, resource) when { context.crowdstrike.assessment.overall > 80 };</policyDocument>
<description>Allow devices with a CrowdStrike overall assessment score above 80</description>
<shadowMode>disabled</shadowMode>
<status>active</status>
</GetClientVpnEndpointAuthorizationPolicyResponse>
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: