You need:
Step 1: Download the file from Amazon
- Verify that you are logged in to your AWS Management Console and you’re working in the correct region.
- Verify that you have created a tunnel in Amazon.
- Navigate to your VPC service. In the VPC service sidebar, locate the Virtual Private Network menu and select Site-to-Site VPN Connections.

- In the list, select your newly created VPN connection and click Download Configuration.

- Fill in the form and click Download.
- For Vendor, select Cisco Systems, Inc..
- For Platform, select ASA 5500 Series.
- For Software, select ASA 9.x for a policy-based VPN OR ASA 9.7 + VTI for a route-based VPN.

Step 2: Fill in the configuration file
- Open the configuration file in a text editor.
- Replace all placeholders with their respective values.
- Uncomment the following lines. To uncomment, remove
!at the start of the line.access-list amzn-filter extended permit ip ...object- andnat-related configuration at the end of the config file.
- Keep the following line. This ensures the SLA monitor works as expected.
Private-1 network from your IP Plan. If you choose to modify this line, do not configure the <sla_monitor_address> value.
- Change
nat (inside,outside)tonat (Private-1,Outside). - (Optional) Delete the remaining commented lines to clean up the file. Commented lines are indicated by
!at the beginning of the line. - Save your changes.

