View a markdown version of this page

CLI 命令语法 - AWS Client VPN

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

CLI 命令语法

您可以使用以下语法使用 CLI 命令:

aws-vpn-client <COMMAND> [OPTIONS]

CLI 工具支持以下命令。

Usage: aws-vpn-client <COMMAND>

Commands:
  connect                Connect a profile through the AWS VPN Client
  disconnect             Disconnect a profile from the AWS VPN Client
  delete-profile         Delete a profile from the AWS VPN Client
  import-profile         Import a VPN connection profile
  list-profiles          List all VPN profiles
  get-config             Get configuration for a profile
  put-preference         Put a preference value
  list-preferences       List all preferences
  get-connection-status  Get the current connection status for a VPN profile
  list-connections       List all active VPN connections
  send-diagnostic-logs   Send diagnostic logs to AWS for troubleshooting
  help                   Print this message or the help of the given subcommand(s)

Options:
  -h, --help     Print help
  -V, --version  Print version

connect

说明

建立与配置文件的 VPN 连接。

摘要

aws-vpn-client connect --profile-name <PROFILE> [--auth-user-pass <AUTH_USER_PASS>]

选项

--profile-name(字符串)

要连接的配置文件的名称。此选项是必需的。

--auth-user-pass(字符串)

包含用户名(第 1 行)、密码(第 2 行)和可选 MFA 代码(第 3 行)的文件路径。此选项不是必需的。

示例

示例:连接到 VPN 配置文件

以下connect示例建立了与配置文件的 VPN 连接。

aws-vpn-client connect --profile-name "Production-VPN"

输出:

{
  "status": "Connected"
}

断开连接

说明

终止活跃的 VPN 连接。

摘要

aws-vpn-client disconnect --profile-name <PROFILE_NAME>

选项

--profile-name(字符串)

要断开连接的已连接配置文件的名称。此选项是必需的。

示例

示例:断开与 VPN 配置文件的连接

以下disconnect示例终止 VPN 连接。成功时没有输出。

aws-vpn-client disconnect --profile-name "Production-VPN"

示例:断开连接错误

以下disconnect示例显示了配置文件未连接时的错误。

aws-vpn-client disconnect --profile-name "Production-VPN"

输出:

{
  "status": "Error",
  "message": "Profile is not connected"
}

导入配置文件

说明

导入 VPN 连接配置文件。

摘要

aws-vpn-client import-profile --profile-name <PROFILE_NAME> --config-path <CONFIG_PATH> [--global]

选项

--profile-name(字符串)

导入配置文件的自定义名称。此选项是必需的。

--config-path(字符串)

OpenVPN 配置文件 (.ovpn) 的路径。此选项是必需的。

--global(布尔值)

作为全局配置文件导入,可供所有用户使用。此选项需要管理员权限。

示例

示例:导入配置文件

以下import-profile示例导入 VPN 连接配置文件。

aws-vpn-client import-profile --profile-name "Production-VPN" --config-path /path/to/vpn-config.ovpn

输出:

{
  "status": "Success"
}

示例:导入全球配置文件

以下import-profile示例导入全局配置文件。这需要管理员权限。

sudo aws-vpn-client import-profile --profile-name "Company-VPN" --config-path /path/to/config.ovpn --global

输出:

{
  "status": "Success"
}

示例:文件路径无效导致导入错误

以下import-profile示例显示了找不到配置文件时的错误。

aws-vpn-client import-profile --profile-name "test" --config-path /invalid/path.ovpn

输出:

{
  "status": "Error",
  "message": "Failed to read OpenVPN config file: No such file or directory (os error 2)"
}

删除个人资料

说明

从客户端删除个人资料。

摘要

aws-vpn-client delete-profile --profile-name <PROFILE_NAME>

选项

--profile-name(字符串)

要删除的配置文件的名称。此选项是必需的。

示例

示例:删除个人资料

以下delete-profile示例删除了 VPN 配置文件。成功时没有输出。

aws-vpn-client delete-profile --profile-name "Production-VPN"

示例:删除配置文件不存在的错误

以下delete-profile示例显示了配置文件不存在时的错误。

aws-vpn-client delete-profile --profile-name "nonexistent"

输出:

{
  "status": "Error",
  "message": "Profile not found"
}

清单配置文件

说明

列出所有 VPN 配置文件。

摘要

aws-vpn-client list-profiles

示例

示例:列出所有 VPN 配置文件

以下list-profiles示例列出了所有导入的 VPN 配置文件。

aws-vpn-client list-profiles

输出:

[
  {
    "profile-name": "Production-VPN",
    "owned-by": "jdoe",
    "auth-type": "saml",
    "imported-at": "2026-07-21T13:04:42-07:00"
  },
  {
    "profile-name": "Staging-VPN",
    "owned-by": "jdoe",
    "auth-type": "ma",
    "imported-at": "2026-07-22T10:30:00-07:00"
  }
]
注意

全局配置文件(随导入--global)没有owned-by字段。

get-config

说明

检索配置文件的 OpenVPN 配置。

摘要

aws-vpn-client get-config --profile-name <PROFILE_NAME>

选项

--profile-name(字符串)

要检索配置的配置文件的名称。此选项是必需的。

示例

示例:检索 OpenVPN 配置

以下get-config示例检索配置文件的 OpenVPN 配置。

aws-vpn-client get-config --profile-name "Production-VPN"

输出:

client
dev tun
proto udp
remote cvpn-endpoint-0123456789abcdef0.prod.clientvpn.us-east-1.amazonaws.com 443
remote-random-hostname
resolv-retry infinite
nobind
remote-cert-tls server
cipher AES-256-GCM
verb 3
<ca>
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
</ca>
auth-user-pass
reneg-sec 0

获取连接状态

说明

获取 VPN 配置文件的当前连接状态。

摘要

aws-vpn-client get-connection-status --profile-name <PROFILE_NAME> [--show-details]

选项

--profile-name(字符串)

要检索连接状态的配置文件的名称。此选项是必需的。

--show-details(布尔值)

在输出中包括连接字节统计信息。

示例

示例:获取连接状态

以下get-connection-status示例检索配置文件的连接状态。

aws-vpn-client get-connection-status --profile-name "Production-VPN"

输出:

{
  "connection-status": "Connected",
  "latest-connection-attempt": {
    "initiated-by": "jdoe",
    "updated-at": "2026-07-24T15:50:36-07:00"
  }
}

示例:获取包含详细信息的连接状态

以下get-connection-status示例使用--show-details选项包含字节统计信息。

aws-vpn-client get-connection-status --profile-name "Production-VPN" --show-details

输出:

{
  "connection-status": "Connected",
  "latest-connection-attempt": {
    "initiated-by": "jdoe",
    "updated-at": "2026-07-24T15:50:36-07:00",
    "details": {
      "tunnel-bytes-in": 0,
      "tunnel-bytes-out": 0,
      "transport-bytes-in": 9674,
      "transport-bytes-out": 11413
    }
  }
}

列表连接

说明

列出所有活跃的 VPN 连接。

摘要

aws-vpn-client list-connections

示例

示例:列出活动连接

以下list-connections示例列出了所有活动的 VPN 连接。

aws-vpn-client list-connections

输出:

[
  {
    "profile-name": "Production-VPN",
    "initiated-by": "jdoe",
    "connection-status": "Connected",
    "last-updated-at": "2026-07-24T15:50:36-07:00"
  }
]

示例:没有活动连接

以下list-connections示例显示了没有活动连接时的输出。

aws-vpn-client list-connections

输出:

[]

看跌偏好

说明

设置全局配置首选项。大多数设置都需要管理员权限。

摘要

aws-vpn-client put-preference --key <PREFERENCE_KEY> --value <PREFERENCE_VALUE>

选项

--key(字符串)

要设置的首选项键的名称。此选项是必需的。

--value(字符串)

要为首选项键设置的值。此选项是必需的。

以下首选项键可用:

enable-telemetry

启用或禁用遥测 (true/false)。

enable-user-profile-management

允许或禁止最终用户导入或删除配置文件 (true/false)。

max-connections

最大并发连接数(整数,1-5)。

示例

示例:设置首选项

以下put-preference示例设置了最大连接数。这需要管理员权限。成功时没有输出。

sudo aws-vpn-client put-preference --key max-connections --value 4

示例:没有管理员权限时出错

以下put-preference示例显示了在没有管理员权限的情况下运行命令时的错误。

aws-vpn-client put-preference --key max-connections --value 4

输出:

{
  "status": "Error",
  "message": "Permission denied: admin privileges required"
}

示例:值无效时出错

以下put-preference示例显示了当您提供无效值时出现的错误。

sudo aws-vpn-client put-preference --key max-connections --value 8

输出:

{
  "status": "Error",
  "message": "Preference value is invalid"
}

列表首选项

说明

显示所有全局配置首选项和当前值。

摘要

aws-vpn-client list-preferences

示例

示例:列出所有首选项

以下list-preferences示例显示所有全局配置首选项及其当前值。

aws-vpn-client list-preferences

输出:

{
  "enable-telemetry": true,
  "enable-user-profile-management": true,
  "max-connections": 1
}

发送诊断日志

说明

收集诊断日志并将其提交给以 AWS 进行故障排除。

摘要

aws-vpn-client send-diagnostic-logs

示例

示例:发送诊断日志

以下send-diagnostic-logs示例收集诊断日志并将其提交到 AWS。

aws-vpn-client send-diagnostic-logs

输出:

{
  "reference-id": "us-west-2:78ff6531-5dc4-c706-7149-e6cfd8adadc7/2026-07-24-16-03-55.zip"
}
注意

报告问题时与 AWS 支持部门分享reference-id价值。

退出码

AWS 客户端 VPN CLI 工具返回以下退出代码。

退出代码 意义
0 成功
1 一般错误
2 命令语法无效