
Executive Summary
A company running its entire infrastructure on physical on-premises servers needed to migrate on-premises to AWS. The existing setup was reaching its limits on scalability, availability, and security. Hardware maintenance was consuming resources that could be spent on business growth, and there was no disaster recovery strategy in place.
Teleglobal planned and executed a rehost (lift-and-shift) migration using AWS Application Migration Service (MGN) with encrypted replication. Application data was transferred using AWS DataSync. The target environment was built inside a secure VPC with production, pre-production, and development workloads running on Amazon EC2 in private subnets. Traffic routing uses Route 53 and Application Load Balancers protected by AWS WAF. This engagement is part of Teleglobal’s cloud migration and modernization services.
Background
The client is a company that had been running all of its application workloads, databases, and storage on on-premises servers. The setup included multiple physical servers handling production, pre-production, and development environments, along with local storage for application data and backups.
The infrastructure had served the company for years, but the limitations were becoming harder to manage. There was no load balancing across servers, no web application firewall, no centralized monitoring, and no structured approach to data encryption or secrets management. Hardware failures posed a real risk to business continuity because there was no automated recovery strategy.
The company needed to move to AWS without rewriting or modifying its applications. A lift-and-shift migration was the right approach: take the existing workloads as they are and place them on a modern, secure AWS cloud foundation with proper networking, security, monitoring, and backup built in from day one.
The Challenge
The company faced four infrastructure problems that created risk for the business and limited growth.
Hardware Dependency and Scaling Limits
Physical servers cannot scale on demand. Adding capacity meant buying, configuring, and racking new hardware. The company was spending time and money on infrastructure maintenance instead of product development. Any hardware failure could take critical systems offline with no automated failover.
No Network Security Architecture
The on-premises environment had no VPC, no subnet isolation, no WAF, and no structured firewall rules at the application layer. Production and development workloads shared the same network. There was no protection against common web exploits.
Missing Encryption and Backup Strategy
Data at rest was not encrypted. Application secrets and credentials were managed manually. There was no automated backup strategy and no defined recovery point or recovery time objectives. A server failure could mean data loss.
No Centralized Monitoring
There was no equivalent of CloudWatch for the on-premises setup. No dashboards, no alarms, no metrics. The team discovered problems when users reported them.
The Solution
Teleglobal designed the target AWS architecture and executed the full on-premises to AWS migration using a rehost approach. This project was delivered through Teleglobal’s AWS migration services. For a similar project involving a VPS-to-AWS migration with data encryption, see the Contabo to AWS case study on Teleglobal’s website.
Rehost Migration with AWS MGN and DataSync
The migration used a rehost (lift-and-shift) approach. AWS Application Migration Service (MGN) handled the server migration with encrypted replication from on-premises to EC2 instances in private subnets. This meant the applications moved to AWS without code changes. AWS DataSync was used to securely transfer application data to Amazon S3, maintaining data integrity throughout the process.

Secure VPC and Network Architecture
A custom Amazon VPC was provisioned with public and private subnets, route tables, Internet Gateway, and NAT Gateway. All migrated EC2 instances sit in private subnets with no direct internet exposure. Security Groups and Network ACLs restrict traffic to only the ports and services each component needs.
Load Balancing, DNS, and WAF Protection
Amazon Route 53 handles DNS routing to Application Load Balancers (ALB) that distribute traffic across EC2 instances in private subnets. AWS WAF protects the ALB from malicious traffic and common web exploits using custom and managed rules. This is a standard part of Teleglobal’s cloud security approach.
Secure Remote Access with OpenVPN
An OpenVPN server provides secure administrative and developer access to resources in private subnets. No production workloads are exposed to the public internet. Administrators connect through VPN to reach EC2 instances, storage, and internal services.
Data Encryption with AWS KMS and Secrets Manager
AWS KMS was implemented for encryption of data at rest and in transit across Amazon S3 and other AWS resources. AWS Secrets Manager replaced manual credential management. All application secrets, database passwords, API keys, and sensitive configuration data are now stored securely with proper access controls.
AWS Backup for Data Protection
AWS Backup was configured to provide automated, policy-based backup protection for EC2 instances and S3 data. This gives the company a structured recovery strategy that did not exist in the on-premises environment. Three Amazon S3 buckets were set up with KMS encryption, IAM-based access controls, and lifecycle policies for application data, backups, and logs.
CloudWatch Monitoring and Proactive Alerting
Amazon CloudWatch was configured across all deployed services with logs, metrics, alarms, and dashboards. The team now gets proactive alerts for infrastructure issues. For companies that need ongoing operational monitoring beyond the initial setup, Teleglobal offers cloud managed services.

IAM Access Governance
AWS IAM was configured with users, groups, roles, and policies following least-privilege principles. Fine-grained, role-based permissions control access to EC2, S3, and all other AWS services.
AWS Services Used
| Category | AWS Services |
|---|---|
| Migration | AWS Application Migration Service (MGN), AWS DataSync |
| Compute | Amazon EC2 (production, pre-production, development) |
| Networking | Amazon VPC, Public/Private Subnets, NAT Gateway, Internet Gateway, Route Tables, Security Groups, Network ACLs |
| DNS & Load Balancing | Amazon Route 53, Application Load Balancer (ALB) |
| Security | AWS WAF, AWS IAM, OpenVPN |
| Encryption & Secrets | AWS KMS, AWS Secrets Manager |
| Storage | Amazon S3 (3 buckets: application data, backups, logs) |
| Backup | AWS Backup |
| Monitoring | Amazon CloudWatch (logs, metrics, alarms, dashboards) |
Results
| Area | Before (On-Premises) | After (AWS) |
|---|---|---|
| Infrastructure | Physical servers, manual provisioning | EC2 instances in secure VPC with private subnets |
| Migration Method | N/A | Rehost via AWS MGN with encrypted replication, DataSync for data |
| Network Security | No VPC, shared network, basic firewall | Custom VPC, public/private subnets, NAT Gateway, Security Groups, NACLs |
| Load Balancing & DNS | No load balancer, manual DNS | Route 53 with ALB distributing traffic, WAF protection |
| Data Encryption | No encryption, manual credential management | KMS encryption at rest and transit, Secrets Manager for credentials |
| Backup & Recovery | No automated backup, no DR plan | AWS Backup with automated policies for EC2 and S3 |
| Storage | Local server storage, manual backups | 3 encrypted S3 buckets with lifecycle policies |
| Monitoring | No monitoring or alerting | CloudWatch dashboards, alarms, and proactive alerting |
What’s Next
With the on-premises to AWS migration complete, the company has a secure foundation to build on.
- Implement Terraform-based Infrastructure as Code for repeatable, version-controlled deployments
- Add CI/CD pipelines to automate application delivery with security checks in the workflow
- Expand AWS Backup with cross-account replication for disaster recovery
- Set up multi-environment governance using AWS Organizations
- Adopt AWS cost monitoring using Cost Explorer and Budgets
- Build operational runbooks and incident response procedures as the team scales
About Teleglobal International
Teleglobal International is an IT consulting company that helps businesses migrate from on-premises infrastructure to production-grade AWS environments. From cloud migration and modernization to AWS infrastructure setup and cloud security, Teleglobal builds cloud platforms that are secure, scalable, and ready for growth. Explore more client success stories.