cms.teleglobals.com

On-Premises to AWS Migration: Secure Lift-and-Shift Using AWS MGN

Executive Summary 

A company running its entire infrastructure on physical on-premises servers needed to migrate on-premises to AWS. The existing setup was reaching its limits on scalability, availability, and security. Hardware maintenance was consuming resources that could be spent on business growth, and there was no disaster recovery strategy in place. 

Teleglobal planned and executed a rehost (lift-and-shift) migration using AWS Application Migration Service (MGN) with encrypted replication. Application data was transferred using AWS DataSync. The target environment was built inside a secure VPC with production, pre-production, and development workloads running on Amazon EC2 in private subnets. Traffic routing uses Route 53 and Application Load Balancers protected by AWS WAF. This engagement is part of Teleglobal’s cloud migration and modernization services. 

Background 

The client is a company that had been running all of its application workloads, databases, and storage on on-premises servers. The setup included multiple physical servers handling production, pre-production, and development environments, along with local storage for application data and backups. 

The infrastructure had served the company for years, but the limitations were becoming harder to manage. There was no load balancing across servers, no web application firewall, no centralized monitoring, and no structured approach to data encryption or secrets management. Hardware failures posed a real risk to business continuity because there was no automated recovery strategy. 

The company needed to move to AWS without rewriting or modifying its applications. A lift-and-shift migration was the right approach: take the existing workloads as they are and place them on a modern, secure AWS cloud foundation with proper networking, security, monitoring, and backup built in from day one. 

The Challenge 

The company faced four infrastructure problems that created risk for the business and limited growth. 

Hardware Dependency and Scaling Limits 

Physical servers cannot scale on demand. Adding capacity meant buying, configuring, and racking new hardware. The company was spending time and money on infrastructure maintenance instead of product development. Any hardware failure could take critical systems offline with no automated failover. 

No Network Security Architecture 

The on-premises environment had no VPC, no subnet isolation, no WAF, and no structured firewall rules at the application layer. Production and development workloads shared the same network. There was no protection against common web exploits. 

Missing Encryption and Backup Strategy 

Data at rest was not encrypted. Application secrets and credentials were managed manually. There was no automated backup strategy and no defined recovery point or recovery time objectives. A server failure could mean data loss. 

No Centralized Monitoring 

There was no equivalent of CloudWatch for the on-premises setup. No dashboards, no alarms, no metrics. The team discovered problems when users reported them. 

The Solution 

Teleglobal designed the target AWS architecture and executed the full on-premises to AWS migration using a rehost approach. This project was delivered through Teleglobal’s AWS migration services. For a similar project involving a VPS-to-AWS migration with data encryption, see the Contabo to AWS case study on Teleglobal’s website. 

Rehost Migration with AWS MGN and DataSync 

The migration used a rehost (lift-and-shift) approach. AWS Application Migration Service (MGN) handled the server migration with encrypted replication from on-premises to EC2 instances in private subnets. This meant the applications moved to AWS without code changes. AWS DataSync was used to securely transfer application data to Amazon S3, maintaining data integrity throughout the process. 

On Premises to AWS MIgration Architecture

Secure VPC and Network Architecture 

A custom Amazon VPC was provisioned with public and private subnets, route tables, Internet Gateway, and NAT Gateway. All migrated EC2 instances sit in private subnets with no direct internet exposure. Security Groups and Network ACLs restrict traffic to only the ports and services each component needs. 

Load Balancing, DNS, and WAF Protection 

Amazon Route 53 handles DNS routing to Application Load Balancers (ALB) that distribute traffic across EC2 instances in private subnets. AWS WAF protects the ALB from malicious traffic and common web exploits using custom and managed rules. This is a standard part of Teleglobal’s cloud security approach. 

Secure Remote Access with OpenVPN 

An OpenVPN server provides secure administrative and developer access to resources in private subnets. No production workloads are exposed to the public internet. Administrators connect through VPN to reach EC2 instances, storage, and internal services. 

Data Encryption with AWS KMS and Secrets Manager 

AWS KMS was implemented for encryption of data at rest and in transit across Amazon S3 and other AWS resources. AWS Secrets Manager replaced manual credential management. All application secrets, database passwords, API keys, and sensitive configuration data are now stored securely with proper access controls. 

AWS Backup for Data Protection 

AWS Backup was configured to provide automated, policy-based backup protection for EC2 instances and S3 data. This gives the company a structured recovery strategy that did not exist in the on-premises environment. Three Amazon S3 buckets were set up with KMS encryption, IAM-based access controls, and lifecycle policies for application data, backups, and logs. 

CloudWatch Monitoring and Proactive Alerting 

Amazon CloudWatch was configured across all deployed services with logs, metrics, alarms, and dashboards. The team now gets proactive alerts for infrastructure issues. For companies that need ongoing operational monitoring beyond the initial setup, Teleglobal offers cloud managed services

Post Migration AWS Security & Monitoring Architecture

IAM Access Governance 

AWS IAM was configured with users, groups, roles, and policies following least-privilege principles. Fine-grained, role-based permissions control access to EC2, S3, and all other AWS services. 

AWS Services Used 

Category AWS Services 
Migration AWS Application Migration Service (MGN), AWS DataSync 
Compute Amazon EC2 (production, pre-production, development) 
Networking Amazon VPC, Public/Private Subnets, NAT Gateway, Internet Gateway, Route Tables, Security Groups, Network ACLs 
DNS & Load Balancing Amazon Route 53, Application Load Balancer (ALB) 
Security AWS WAF, AWS IAM, OpenVPN 
Encryption & Secrets AWS KMS, AWS Secrets Manager 
Storage Amazon S3 (3 buckets: application data, backups, logs) 
Backup AWS Backup 
Monitoring Amazon CloudWatch (logs, metrics, alarms, dashboards) 

Results 

Area Before (On-Premises) After (AWS) 
Infrastructure Physical servers, manual provisioning EC2 instances in secure VPC with private subnets 
Migration Method N/A Rehost via AWS MGN with encrypted replication, DataSync for data 
Network Security No VPC, shared network, basic firewall Custom VPC, public/private subnets, NAT Gateway, Security Groups, NACLs 
Load Balancing & DNS No load balancer, manual DNS Route 53 with ALB distributing traffic, WAF protection 
Data Encryption No encryption, manual credential management KMS encryption at rest and transit, Secrets Manager for credentials 
Backup & Recovery No automated backup, no DR plan AWS Backup with automated policies for EC2 and S3 
Storage Local server storage, manual backups 3 encrypted S3 buckets with lifecycle policies 
Monitoring No monitoring or alerting CloudWatch dashboards, alarms, and proactive alerting 

What’s Next 

With the on-premises to AWS migration complete, the company has a secure foundation to build on. 

  1. Implement Terraform-based Infrastructure as Code for repeatable, version-controlled deployments 
  1. Add CI/CD pipelines to automate application delivery with security checks in the workflow 
  1. Expand AWS Backup with cross-account replication for disaster recovery 
  1. Set up multi-environment governance using AWS Organizations 
  1. Adopt AWS cost monitoring using Cost Explorer and Budgets 
  1. Build operational runbooks and incident response procedures as the team scales 

About Teleglobal International 

Teleglobal International is an IT consulting company that helps businesses migrate from on-premises infrastructure to production-grade AWS environments. From cloud migration and modernization to AWS infrastructure setup and cloud security, Teleglobal builds cloud platforms that are secure, scalable, and ready for growth. Explore more client success stories.