Skip to main content
advisory · aws

Cross-region VPC peering connections left in a rejected, expired or failed state

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a cross-region VPC peering connection whose status from `ec2:DescribeVpcPeeringConnections` is a dead state such as `rejected`, `expired` or `failed`. A dead connection carries no charge, so the finding is a $0 hygiene advisory: remove the routes that still point to it, since AWS does not allow deleting a connection in those states.

Signal and threshold

How ZopNight evaluates Cross-region VPC peering connections left in a rejected, expired or failed state.
Field Value
Rule IDsRC-163
Categoryadvisory
Severitylow
Metricnone — pure configuration read
Thresholdpeering not active
SourceZopNight
Permissions usedec2:DescribeVpcPeeringConnections · ec2:DescribeRouteTables

Why dead peering connections are worth tidying

A VPC peering connection goes through a lifecycle: pending-acceptance, provisioning, active, and several end states. The peering lifecycle page describes requests that expire after 7 days if nobody accepts them, requests the accepter rejects, and requests that fail. According to the peering pricing page, there is no charge to create a connection; data transfer is what costs money. A connection that never became active moves no data, so it bills nothing, but it leaves confusing entries behind, and route tables that reference it send traffic nowhere.

Finding inactive peering connections

Filter by status code in each Region you peer from:

Terminal window
aws ec2 describe-vpc-peering-connections \
--filters Name=status-code,Values=rejected,expired,failed \
--query 'VpcPeeringConnections[].[VpcPeeringConnectionId,Status.Code,RequesterVpcInfo.Region,AccepterVpcInfo.Region]' \
--output table

Then look for routes that still target a connection:

Terminal window
aws ec2 describe-route-tables \
--filters Name=route.vpc-peering-connection-id,Values=pcx-0123456789abcdef0 \
--query 'RouteTables[].RouteTableId'

The inactive-state test

The rule reads whether ZopNight’s inventory marks the peering connection as inactive, meaning it reached a dead state such as rejected, expired or failed rather than active. There is no metric and no time window; the state alone decides it. The console link in the finding opens the Region the connection was requested from.

Same-region peerings are out of scope

ZopNight only collects peering connections that cross Regions, because it uses them to draw cross-region links in its network view. An inactive peering between two VPCs in the same Region is therefore never flagged by this rule. Use the CLI filter above in each Region to catch those.

Nothing to save, something to tidy

The finding is fixed at $0 per month. Its value is fewer stale objects and no black-hole routes, not a lower bill.

Cleaning up after a dead peering connection

  1. Confirm whether the request was rejected or simply expired, and whether the two VPCs still need connectivity. If they do, create a fresh request instead.
  2. Delete stale routes that target the connection in both VPCs’ route tables.
  3. Do not try to delete the connection itself. AWS does not allow deleting a connection in the failed or rejected state, and no action can be taken on an expired one; AWS removes it from view on its own, after 2 hours for a failed request and after up to 2 days for expired or rejected ones.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·