AWS Security ChangesHomeSearch

AWS mgn: Reordered and reworded MGN agent FAQ questions

Service: mgn · 2026-09-27 · Documentation low

File: mgn/latest/ug/Agent-Related-FAQ.md

Summary

The MGN agent FAQ page was reorganized: the question list and section order were reshuffled, headings renamed (e.g. 'Agent related FAQs' to 'Agent questions'), and several answers lightly reworded. Security-relevant content (proxy env vars, temporary credentials, sudoers privileges) was moved rather than newly introduced.

Security assessment

The diff is a documentation reorganization of FAQ entries (reordering questions, renaming headings, minor wording tweaks). The proxy/credential/privilege text is relocated existing content, not a new security feature or a fix for a specific vulnerability, so no concrete security issue is addressed.

Evidence

Make sure to set the environment variables `https_proxy`, `http_proxy`, and `no_proxy` (for metadata) according to your environment. The proxy value must end with a trailing forward slash (/).

Diff

diff --git a/mgn/latest/ug/Agent-Related-FAQ.md b/mgn/latest/ug/Agent-Related-FAQ.md
index fe1b5ca85..d89f49e07 100644
--- a//mgn/latest/ug/Agent-Related-FAQ.md
+++ b//mgn/latest/ug/Agent-Related-FAQ.md
@@ -7 +7 @@
-What does the AWS Replication Agent do?What kind of data is transferred between the agent and the AWS Transform MGN?Can a proxy server be used between the source server and the AWS Transform MGN console?What are the prerequisites needed to install the AWS Replication Agent?What ports does the AWS Replication Agent use?What privileges does the AWS Replication Agent require?Is it possible to install the agent on servers running operating systems that are not listed as supported?What kind of resources does the AWS Replication Agent use?Can AWS Transform MGN migrate containers?Does the AWS Replication Agent cache any data to disk?How is communication between the AWS Replication Agent and the AWS Transform MGN secured?Is it possible to change the port the AWS Replication Agent uses from TCP Port 1500 to a different port?How do I manually uninstall the AWS Transform MGN agent from a server?When do I need to reinstall the agent?How much bandwidth does the AWS Replication Agent consume?How many disks can the AWS Replication Agent replicate?Is it possible to add a disk to replication without a complete resync of any disks that have already been replicated?Is the AWS Replication Agent installed on launched test and cutover instances?How do temporary credentials work?Which Windows and Linux OSs support no-rescan upon reboot?
+What does the AWS Replication Agent do?What kind of data is transferred between the agent and the AWS Transform MGN?What kind of resources does the AWS Replication Agent use?How much bandwidth does the AWS Replication Agent consume?What are the prerequisites needed to install the AWS Replication Agent?What privileges does the AWS Replication Agent require?What ports does the AWS Replication Agent use?Can a proxy server be used between the source server and the AWS Transform MGN console?Is it possible to install the agent on servers running operating systems that are not listed as supported?How do temporary credentials work?How is communication between the AWS Replication Agent and the AWS Transform MGN secured?Is it possible to change the port the AWS Replication Agent uses from TCP Port 1500 to a different port?Does the AWS Replication Agent cache any data to disk?Is it possible to add a disk to replication without a complete resync of any disks that have already been replicated?Which Windows and Linux OSs support no-rescan upon reboot?When do I need to reinstall the agent?How do I manually uninstall the AWS Transform MGN agent from a server?Is the AWS Replication Agent installed on launched test and cutover instances?
@@ -11 +11 @@ NEW - You can now accelerate your migration and modernization with AWS Transform
-# Agent related FAQs
+# Agent questions
@@ -21 +21 @@ This section contains answers to questions about the AWS Replication Agent.
-  * Can a proxy server be used between the source server and the AWS Transform MGN console?
+  * What kind of resources does the AWS Replication Agent use?
@@ -23 +23 @@ This section contains answers to questions about the AWS Replication Agent.
-  * What are the prerequisites needed to install the AWS Replication Agent?
+  * How much bandwidth does the AWS Replication Agent consume?
@@ -25 +25 @@ This section contains answers to questions about the AWS Replication Agent.
-  * What ports does the AWS Replication Agent use?
+  * What are the prerequisites needed to install the AWS Replication Agent?
@@ -29 +29 @@ This section contains answers to questions about the AWS Replication Agent.
-  * Is it possible to install the agent on servers running operating systems that are not listed as supported?
+  * What ports does the AWS Replication Agent use?
@@ -31 +31 @@ This section contains answers to questions about the AWS Replication Agent.
-  * What kind of resources does the AWS Replication Agent use?
+  * Can a proxy server be used between the source server and the AWS Transform MGN console?
@@ -33 +33 @@ This section contains answers to questions about the AWS Replication Agent.
-  * Can AWS Transform MGN migrate containers?
+  * Is it possible to install the agent on servers running operating systems that are not listed as supported?
@@ -35 +35 @@ This section contains answers to questions about the AWS Replication Agent.
-  * Does the AWS Replication Agent cache any data to disk?
+  * How do temporary credentials work?
@@ -41 +41 @@ This section contains answers to questions about the AWS Replication Agent.
-  * How do I manually uninstall the AWS Transform MGN agent from a server?
+  * Does the AWS Replication Agent cache any data to disk?
@@ -43 +43 @@ This section contains answers to questions about the AWS Replication Agent.
-  * When do I need to reinstall the agent?
+  * Is it possible to add a disk to replication without a complete resync of any disks that have already been replicated?
@@ -45 +45 @@ This section contains answers to questions about the AWS Replication Agent.
-  * How much bandwidth does the AWS Replication Agent consume?
+  * Which Windows and Linux OSs support no-rescan upon reboot?
@@ -47 +47 @@ This section contains answers to questions about the AWS Replication Agent.
-  * How many disks can the AWS Replication Agent replicate?
+  * When do I need to reinstall the agent?
@@ -49 +49 @@ This section contains answers to questions about the AWS Replication Agent.
-  * Is it possible to add a disk to replication without a complete resync of any disks that have already been replicated?
+  * How do I manually uninstall the AWS Transform MGN agent from a server?
@@ -53,4 +52,0 @@ This section contains answers to questions about the AWS Replication Agent.
-  * How do temporary credentials work?
-
-  * Which Windows and Linux OSs support no-rescan upon reboot?
-
@@ -96,7 +92 @@ When an Agent is installed on a source server, it collects the following informa
-## Can a proxy server be used between the source server and the AWS Transform MGN console?
-
-Yes. The proxy is configured using an environment variable before the install.
-
-https_proxy=https://PROXY:PORT/
-
-For example: https_proxy=https://10.0.0.1:8088/
+## What kind of resources does the AWS Replication Agent use?
@@ -104 +94 @@ For example: https_proxy=https://10.0.0.1:8088/
-Make sure the proxy has a trailing forward slash.
+The AWS Replication Agent is lightweight and nondisruptive. The agent uses approximately 5% CPU and 250 MB of RAM.
@@ -106 +96 @@ Make sure the proxy has a trailing forward slash.
-Ensure that you have allowlisted the [MGN IPs and URLs](./preparing-environments.html#TCP-443) for both SSL Interception and Authentication. 
+## How much bandwidth does the AWS Replication Agent consume?
@@ -108 +98 @@ Ensure that you have allowlisted the [MGN IPs and URLs](./preparing-environments
-###### Note
+The AWS Replication Agent opens up to five connections and attempts to maximize available bandwidth.
@@ -110 +100 @@ Ensure that you have allowlisted the [MGN IPs and URLs](./preparing-environments
-A web proxy cannot be used for communication between the source server and the staging area subnet where replication server launched for replication over TCP Port 1500. To use private routing for data replication, see [Data routing and throttling](./replication-server-settings.html#data-routing).
+Throttling can be activated in the AWS Transform MGN console by either selecting a specific server and choosing the **Replication settings** tab or by changing the **Replication template** (in this case the change only affects newly added servers). 
@@ -116 +106,5 @@ The installation requirements for source server depend on the type of OS that th
-Prerequisites [can be found here](./installation-requirements.html).
+For prerequisites, see [Installation requirements](./installation-requirements.html).
+
+## What privileges does the AWS Replication Agent require?
+
+The AWS Replication Agent installer requires root privileges or the use of the sudo command during installation. It creates an "aws-replication" group and user, and attempts to add the "aws-replication" user to the "sudoers" file to grant necessary permissions. Ensure that the user running the installation has sufficient privileges to modify the "sudoers" file. If the installation fails because of insufficient permissions, you might need to manually add the "aws-replication" user to the "sudoers" file before attempting the installation again.
@@ -120 +114 @@ Prerequisites [can be found here](./installation-requirements.html).
-The Agent uses TCP Port 443 to communicate with the Service Manager of Application Migration Service and TCP Port 1500 for replication to AWS.
+The agent uses TCP Port 443 to communicate with the Service Manager of AWS Transform MGN and TCP Port 1500 for replication to AWS.
@@ -122 +116 @@ The Agent uses TCP Port 443 to communicate with the Service Manager of Applicati
-## What privileges does the AWS Replication Agent require?
+## Can a proxy server be used between the source server and the AWS Transform MGN console?
@@ -124 +118 @@ The Agent uses TCP Port 443 to communicate with the Service Manager of Applicati
-The AWS Replication Agent installer requires root privileges or the use of the sudo command during installation. It creates an "aws-replication" group and user, and attempts to add the "aws-replication" user to the "sudoers" file to grant necessary permissions. Ensure that the user running the installation has sufficient privileges to modify the "sudoers" file. If the installation fails due to insufficient permissions, you may need to manually add the "aws-replication" user to the "sudoers" file before attempting the installation again.
+Yes. The proxy is configured using an environment variable before the install.
@@ -126 +120 @@ The AWS Replication Agent installer requires root privileges or the use of the s
-## Is it possible to install the agent on servers running operating systems that are not listed as supported?
+https_proxy=https://PROXY:PORT/
@@ -128 +122 @@ The AWS Replication Agent installer requires root privileges or the use of the s
-The agent is designed and tested to work on the officially supported operating systems listed in the documentation. Installing the agent on other unsupported operating systems might be possible but is not recommended. Any installation or replication issues encountered when using unsupported operating systems will need to be handled through your own troubleshooting or support channels, as the AWS engineering team will be limited in their ability to assist. We advise using the agent only on supported OS versions to ensure the best experience. Refer to [Supported operating systems](./Supported-Operating-Systems.html).
+For example: https_proxy=https://10.0.0.1:8088/
@@ -130 +124 @@ The agent is designed and tested to work on the officially supported operating s
-## What kind of resources does the AWS Replication Agent use?
+Make sure to set the environment variables `https_proxy`, `http_proxy`, and `no_proxy` (for metadata) according to your environment. The proxy value must end with a trailing forward slash (/).
@@ -132 +126,3 @@ The agent is designed and tested to work on the officially supported operating s
-The AWS Replication Agent is lightweight and nondisruptive. The agent uses approximately 5% CPU and 250 MB of RAM. 
+Ensure that you have allowlisted the [MGN IPs and URLs](./preparing-environments.html#TCP-443) for both SSL Interception and Authentication. 
+
+###### Note
@@ -134 +130 @@ The AWS Replication Agent is lightweight and nondisruptive. The agent uses appro
-## Can AWS Transform MGN migrate containers?
+A web proxy cannot be used for communication between the source server and the staging area subnet where replication server launched for replication over TCP Port 1500. To use private routing for data replication, see [Data routing and throttling](./replication-server-settings.html#data-routing).
@@ -136 +132 @@ The AWS Replication Agent is lightweight and nondisruptive. The agent uses appro
-AWS Transform MGN only supports the replication of full servers. Nevertheless, MGN replicates on a server level and therefore any containers within the selected servers will be replicated.
+## Is it possible to install the agent on servers running operating systems that are not listed as supported?
@@ -138 +134 @@ AWS Transform MGN only supports the replication of full servers. Nevertheless, M
-## Does the AWS Replication Agent cache any data to disk?
+AWS Transform MGN supports the agent only on the operating systems listed in [Supported operating systems](./Supported-Operating-Systems.html). Installing the agent on an unsupported operating system might work, but MGN does not support it, and support for installation or replication issues is limited to the listed operating systems.
@@ -140 +136 @@ AWS Transform MGN only supports the replication of full servers. Nevertheless, M
-AWS Transform MGN does not write any cache or do any sort of journalling to disk. The Agent holds a buffer which is large enough to map all volume's blocks ~250 MB in memory.
+## How do temporary credentials work?
@@ -142 +138 @@ AWS Transform MGN does not write any cache or do any sort of journalling to disk
-The agent then acts as a sort of write filter and will replicate changed blocks directly from memory to the Replication Server. In cases where the data is no longer in memory, the agent will read the block from the volume directly. This is the case where you may see backlog in the AWS Transform MGN console. The cause of this is the volume of change is greater than the bandwidth available.
+The temporary credential mechanism was developed specifically to provide an easy and secure way to install MGN Agents. The main flow of the temporary credentials' creation process relies on generating an x509 certificate per agent and then using this x509 certificate to receive temporary IAM credentials. This process uses a similar mechanism to the one used by [IAM Roles Anywhere](https://docs.aws.amazon.com/rolesanywhere/latest/userguide/introduction.html).
@@ -152,9 +148 @@ No. The AWS Transform MGN Agent can only use TCP Port 1500 for replication.
-## How do I manually uninstall the AWS Transform MGN agent from a server?
-
-Follow the steps in the [Uninstalling the Agent](./uninstalling-agent.html) section.
-
-## When do I need to reinstall the agent?
-
-Typically, you need to reinstall the Agent after any major upgrade to the source server.
-
-**Linux**
+## Does the AWS Replication Agent cache any data to disk?
@@ -162 +150 @@ Typically, you need to reinstall the Agent after any major upgrade to the source
-  * Any kernel upgrade
+AWS Transform MGN does not write any cache or do any sort of journalling to disk. The Agent holds a buffer which is large enough to map all volume's blocks ~250 MB in memory.
@@ -164 +152 @@ Typically, you need to reinstall the Agent after any major upgrade to the source
-  * After adding new volumes
+The agent acts as a write filter and replicates changed blocks directly from memory to the Replication Server. When the data is no longer in memory, the agent reads the block directly from the volume. In this case, you might see backlog in the AWS Transform MGN console, which occurs when the volume of change is greater than the available bandwidth.
@@ -165,0 +154 @@ Typically, you need to reinstall the Agent after any major upgrade to the source
+## Is it possible to add a disk to replication without a complete resync of any disks that have already been replicated?
@@ -166,0 +156 @@ Typically, you need to reinstall the Agent after any major upgrade to the source
+When you add a disk to a source server, AWS Transform MGN does not automatically identify the disk or add it to the **Disk settings** section in the console.
@@ -167,0 +158 @@ Typically, you need to reinstall the Agent after any major upgrade to the source
+To replicate the new disk, reinstall the agent. Before you reinstall, note the current **Total replicated storage** value. After you reinstall the agent, this value changes.
@@ -169 +160 @@ Typically, you need to reinstall the Agent after any major upgrade to the source
-**Windows**
+An additional progress bar also appears, which indicates that MGN is rescanning the original volumes. This is a scan, not a resync: it verifies that the blocks on the source still match the blocks on the replication side. The scan is significantly faster than a resync because MGN transfers block data only where a difference exists. The scan is required because reinstalling the agent unloads and resets the driver that performs the I/O tracking, so the sync status can no longer be guaranteed. While the original volumes are rescanned, the agent completes the initial sync of the new volume in parallel.
@@ -171 +162 @@ Typically, you need to reinstall the Agent after any major upgrade to the source
-  * Any OS upgrade (for example, Windows Server 2012 to Windows Server 2016)
+## Which Windows and Linux OSs support no-rescan upon reboot?
@@ -173 +164 @@ Typically, you need to reinstall the Agent after any major upgrade to the source
-###### Note
+When you shut down a supported Linux or Windows source server (from the OS menu or CLI) and then restart it, MGN resumes replication without a rescan.
@@ -175 +166 @@ Typically, you need to reinstall the Agent after any major upgrade to the source
-If you [upgrade using a post-launch action](./predefined-post-launch-actions.html#predefined-windows-upgrade), an agent upgrade is not required.
+A rescan means that the agent on the source server rereads all blocks on all replicated disks and transmits blocks that are different from the previously replicated data. A rescan is similar to the initial sync but is faster because only blocks that are different need to be transmitted.
@@ -177 +168 @@ If you [upgrade using a post-launch action](./predefined-post-launch-actions.htm
-  * After adding new volumes
+Rescans can still happen following a hard reboot, crashes, or when you add or remove disks to or from the source server.
@@ -178,0 +170 @@ If you [upgrade using a post-launch action](./predefined-post-launch-actions.htm
+Supported OSs include:
@@ -179,0 +172 @@ If you [upgrade using a post-launch action](./predefined-post-launch-actions.htm
+**Windows**
@@ -180,0 +174 @@ If you [upgrade using a post-launch action](./predefined-post-launch-actions.htm
+  * Windows Server 2012r1
@@ -182 +176 @@ If you [upgrade using a post-launch action](./predefined-post-launch-actions.htm
-## How much bandwidth does the AWS Replication Agent consume?
+  * Windows Server 2012r2
@@ -184 +178 @@ If you [upgrade using a post-launch action](./predefined-post-launch-actions.htm
-The AWS Replication Agent opens up to five connections and will attempt to maximize available bandwidth.
+  * Windows Server 2016
@@ -186 +180 @@ The AWS Replication Agent opens up to five connections and will attempt to maxim
-Throttling can be activated via the AWS Transform MGN console by either selecting a specific server and choosing the **Replication settings** tab or by changing the **Replication template** (in this case the change will only affect newly added servers). 
+  * Windows Server 2019
@@ -188 +182 @@ Throttling can be activated via the AWS Transform MGN console by either selectin
-## How many disks can the AWS Replication Agent replicate?
+  * Windows Server 2022
@@ -190 +184 @@ Throttling can be activated via the AWS Transform MGN console by either selectin
-The agent can replicate up to 50 disks from a single server. Ensure that the replication server instance type supports at least the number of disks being replicated.
+  * Windows Server 2025
@@ -192 +186 @@ The agent can replicate up to 50 disks from a single server. Ensure that the rep
-## Is it possible to add a disk to replication without a complete resync of any disks that have already been replicated?
+  * Windows 11
@@ -194 +187,0 @@ The agent can replicate up to 50 disks from a single server. Ensure that the rep
-When you are adding a disk to a source server, AWS Transform MGN will not automatically identify this disk and add it to the **Disk settings** section in the console.
@@ -196 +188,0 @@ When you are adding a disk to a source server, AWS Transform MGN will not automa
-The only way to get this disk to replicate is to reinstall the agent. Before reinstalling, you can note the current **Total replicated storage**. When you reinstall the agent, you will notice the value of replicated storage changes.
@@ -198 +189,0 @@ The only way to get this disk to replicate is to reinstall the agent. Before rei
-You will also notice an additional progress bar appear, which indicates that we are rescanning the original volumes. This is not a resync, but a scan, to verify that all the blocks on the source still match the blocks on the replication side. This process is significantly quicker than a resync, as there is no actual block data transferred, unless there is a difference. This is needed, as a reinstall results in the driver which performs the IO tracking being unloaded and reset, so we have no way of being certain of the sync status. While the rescan on the original volumes is happening, the agent is also ensuring that the initial sync of the new volume is being completed in parallel. 
@@ -200 +191 @@ You will also notice an additional progress bar appear, which indicates that we
-## Is the AWS Replication Agent installed on launched test and cutover instances?
+**Linux**
@@ -202 +193 @@ You will also notice an additional progress bar appear, which indicates that we
-During the launch process, either upon test or cutover instance launch, the AWS Replication agent is removed from the test or cutover instance, and will not run on it.
+  * CentOS 6–8, Stream 9, Stream 10 
@@ -204 +195 @@ During the launch process, either upon test or cutover instance launch, the AWS
-## How do temporary credentials work?
+  * Oracle 6–8 
@@ -206 +197 @@ During the launch process, either upon test or cutover instance launch, the AWS
-The temporary credential mechanism was developed specifically to provide an easy and secure way to install MGN Agents. The main flow of the temporary credentials' creation process relies on generating an x509 certificate per agent and then using this x509 certificate to receive temporary IAM credentials. This process uses a similar mechanism to the one used by [IAM Roles Anywhere](https://docs.aws.amazon.com/rolesanywhere/latest/userguide/introduction.html).
+  * RHEL 6–9.8, 10, 10.1, 10.2 
@@ -208 +199 @@ The temporary credential mechanism was developed specifically to provide an easy
-## Which Windows and Linux OSs support no-rescan upon reboot?
+  * Rocky Linux 8–9.8, 10, 10.1, 10.2