AWS mgn: MGN FAQ reorganized; adds VPC endpoint, monitoring, encryption notes
Summary
FAQ topics are reordered (several existing Q&As moved, including the "What data is stored on and transmitted through MGN service?" answer stating MGN data is held in an encrypted database and encrypted in transit). New sections were added covering Interface VPC Endpoints/AWS PrivateLink for private connectivity to MGN, and CloudWatch/EventBridge monitoring of MGN metrics and events. The "Which post-launch scripts does MGN support?" section (including the note that Windows post-launch scripts run as Local System and Linux scripts run as root, plus the VMTools uninstall script) was removed from this page, and minor wording edits were made to the custom-DNS security-group guidance and quota descriptions.
Security assessment
The newly added Interface VPC Endpoint/PrivateLink text documents private (non-public-internet) connectivity to MGN and notes that IAM policies can control access to service resources, which is security-hardening guidance rather than a fix for a specific flaw. The file also retains the encryption statement ('This data is kept in an encrypted database... All data in transit is encrypted.') moved to a new location. No CVE, incident, or specific vulnerability is referenced anywhere in the diff, so security_issue_related is false; the removal of the post-launch script note about root/Local System execution context is a loss of privilege-relevant guidance but is not tied to a reported vulnerability.
Evidence
+If you use Amazon Virtual Private Cloud (Amazon VPC) to host your AWS resources, you can establish a private connection between your VPC and AWS Transform MGN. You can use this connection to allow AWS Transform MGN to communicate with your resources on your VPC without going through the public internet.
Diff
diff --git a/mgn/latest/ug/General-Questions-FAQ.md b/mgn/latest/ug/General-Questions-FAQ.md index 0b8b0d092..00493a865 100644 --- a//mgn/latest/ug/General-Questions-FAQ.md +++ b//mgn/latest/ug/General-Questions-FAQ.md @@ -7 +7 @@ -Why was AWS Application Migration Service renamed to AWS Transform MGN?Can MGN protect or migrate physical servers?What data is stored on and transmitted through MGN service?What should I consider when replicating Active Directory?Does AWS Transform MGN work with LVM and RAID configurations?What is there to note regarding SAN/NAS support?Does AWS Transform MGN support Windows License migration?Can you perform an OS (Operating System) upgrade with AWS Transform MGN?What are the AWS Transform MGN quota limits?What are the Private APIs used by MGN to define actions in the IAM Policy?Which post-launch scripts does MGN support?What happens if I use a custom DNS?Can I use AWS Transform MGN to migrate servers from VMware Cloud on AWS (VMC) to Amazon EC2?When should I use AWS Elastic Disaster Recovery (AWS DRS) for migration? +Why was AWS Application Migration Service renamed to AWS Transform MGN?What data is stored on and transmitted through MGN service?Can MGN protect or migrate physical servers?What is there to note regarding SAN/NAS support?What should I consider when replicating Active Directory?Does AWS Transform MGN support Windows License migration?Can you perform an OS (Operating System) upgrade with AWS Transform MGN?Can I use AWS Transform MGN to migrate servers from VMware Cloud on AWS (VMC) to Amazon EC2?When should I use AWS Elastic Disaster Recovery (AWS DRS) for migration?What are the AWS Transform MGN quota limits?What are the Private APIs used by MGN to define actions in the IAM Policy?How does AWS Transform MGN interact with Interface VPC Endpoints?How do I use MGN with CloudWatch and EventBridge dashboards?What happens if I use a custom DNS? @@ -19,2 +18,0 @@ This section contains answers to general questions about AWS Transform MGN. - * Can MGN protect or migrate physical servers? - @@ -23,3 +21 @@ This section contains answers to general questions about AWS Transform MGN. - * What should I consider when replicating Active Directory? - - * Does AWS Transform MGN work with LVM and RAID configurations? + * Can MGN protect or migrate physical servers? @@ -28,0 +25,2 @@ This section contains answers to general questions about AWS Transform MGN. + * What should I consider when replicating Active Directory? + @@ -32,0 +31,4 @@ This section contains answers to general questions about AWS Transform MGN. + * Can I use AWS Transform MGN to migrate servers from VMware Cloud on AWS (VMC) to Amazon EC2? + + * When should I use AWS Elastic Disaster Recovery (AWS DRS) for migration? + @@ -37,3 +39 @@ This section contains answers to general questions about AWS Transform MGN. - * Which post-launch scripts does MGN support? - - * What happens if I use a custom DNS? + * How does AWS Transform MGN interact with Interface VPC Endpoints? @@ -41 +41 @@ This section contains answers to general questions about AWS Transform MGN. - * Can I use AWS Transform MGN to migrate servers from VMware Cloud on AWS (VMC) to Amazon EC2? + * How do I use MGN with CloudWatch and EventBridge dashboards? @@ -43 +43 @@ This section contains answers to general questions about AWS Transform MGN. - * When should I use AWS Elastic Disaster Recovery (AWS DRS) for migration? + * What happens if I use a custom DNS? @@ -63 +63,5 @@ At the rehosting stage, you can continue with the agentic workflow or switch to -AWS Transform is also available through Kiro, Claude, Cursor, and Codex via the AWS Transform MCP server. +AWS Transform is also available through Kiro, Claude, Cursor, and Codex through the AWS Transform MCP server. + +## What data is stored on and transmitted through MGN service? + +MGN stores only configuration and log data. This data is kept in an encrypted database. Your replicated data stays in your own VPC. All data in transit is encrypted. @@ -69 +73 @@ Yes. MGN can migrate both virtual and physical servers. The replication process -## What data is stored on and transmitted through MGN service? +## What is there to note regarding SAN/NAS support? @@ -71 +75,3 @@ Yes. MGN can migrate both virtual and physical servers. The replication process -MGN stores only configuration and log data. This data is kept in an encrypted database. Your replicated data stays in your own VPC. All data in transit is encrypted. +If the disks are represented as block devices on the machine, as most SAN are, AWS Transform MGN replicates them transparently, just like actual local disks. + +If the disks are mounted over the network, such as an NFS share, as most NAS implementations are, the AWS Replication Agent would need to be installed on the actual NFS server to replicate the disk. @@ -79 +85 @@ There are two main approaches when it comes to migrating Active Directory or dom - 2. Leaving the AD server(s) in the source environment – in this approach, the test or cutover instances will communicate back to the AD server in the source environment and will take the source server's place in the AD automatically. + 2. Leaving the AD server(s) in the source environment – in this approach, the test or cutover instances communicate back to the AD server in the source environment and take the source server's place in the AD automatically. @@ -86 +92 @@ In this case, it is important to conduct any tests using an isolated subnet in t -## Does AWS Transform MGN work with LVM and RAID configurations? +## Does AWS Transform MGN support Windows License migration? @@ -88 +94 @@ In this case, it is important to conduct any tests using an isolated subnet in t -Yes, AWS Transform MGN works with any such configuration. +AWS Transform MGN conforms to the [Microsoft Licensing on AWS](https://aws.amazon.com/windows/resources/licensing/) guidelines. @@ -90 +96 @@ Yes, AWS Transform MGN works with any such configuration. -## What is there to note regarding SAN/NAS support? +## Can you perform an OS (Operating System) upgrade with AWS Transform MGN? @@ -92 +98 @@ Yes, AWS Transform MGN works with any such configuration. -If the disks are represented as block devices on the machine, as most SAN are, AWS Transform MGN will replicate them transparently, just like actual local disks. +Yes. AWS Transform MGN allows you to [perform an OS upgrade](./predefined-post-launch-actions.html#predefined-windows-upgrade) using a predefined action. The action clones your machine and upgrades the clone. After the upgrade, verify that the cloned machine is working well, and then you can begin using it. @@ -94 +100 @@ If the disks are represented as block devices on the machine, as most SAN are, A -If the disks are mounted over the network, such as an NFS share, as most NAS implementations are, the AWS Replication Agent would need to be installed on the actual NFS server to replicate the disk. +## Can I use AWS Transform MGN to migrate servers from VMware Cloud on AWS (VMC) to Amazon EC2? @@ -96 +102 @@ If the disks are mounted over the network, such as an NFS share, as most NAS imp -## Does AWS Transform MGN support Windows License migration? +Yes, you can. For migrations of source servers from [VMC](https://aws.amazon.com/vmware/) to EC2 you have two options. You can install the agentless appliance in your VMC environment, and migrate your servers using [agentless replication](./agentless-mgn.html), or install the [AWS replication agent](./agent-installation.html) on each of your source servers, and use agent-based replication for your migration. @@ -98 +104 @@ If the disks are mounted over the network, such as an NFS share, as most NAS imp -AWS Transform MGN conforms to the [Microsoft Licensing on AWS](https://aws.amazon.com/windows/resources/licensing/) guidelines. +## When should I use AWS Elastic Disaster Recovery (AWS DRS) for migration? @@ -100 +106,3 @@ AWS Transform MGN conforms to the [Microsoft Licensing on AWS](https://aws.amazo -## Can you perform an OS (Operating System) upgrade with AWS Transform MGN? +In cases that DRS supports a feature that does not exist in MGN, DRS can be used for migration. You can install the DRS replication agent on your source servers. Following replication, you can launch recovery instances in your target environment, to complete the migration. + +DRS can be used for migration, as the DRS and MGN services use shared technology for performing block level replication. Both MGN and DRS have a replication agent, for replicating servers into a staging area in AWS. MGN supports launching test and cutover instances from the staging area. DRS supports launching recovery instances from the staging area. The technology used by both of these services for launching instances in AWS is very similar. DRS also has the capability to failback to the source environment, after the source environment has recovered. This capability does not exist in MGN. @@ -102 +110,3 @@ AWS Transform MGN conforms to the [Microsoft Licensing on AWS](https://aws.amazo -Yes. AWS Transform MGN allows you to [perform an OS upgrade](./predefined-post-launch-actions.html#predefined-windows-upgrade) using a predefined action. The action will clone your machine and upgrade the clone. After the upgrade, verify that the cloned machine is working well, and then you can begin using it. +Note that you cannot install the DRS and MGN agents on the same server at the same time. If you already installed the MGN agent on a server, and want to use DRS for migration, you must uninstall the MGN agent before installing the DRS agent. + +Note that there are costs associated with using the DRS service. For DRS pricing information see [AWS Elastic Disaster Recovery pricing](https://aws.amazon.com/disaster-recovery/pricing/). @@ -110 +120 @@ Name | Default | Description -Concurrent jobs in progress | Each supported AWS Region: 20 | Launching a test or cutover instance, or a cleanup action is considered a "job". Multiple servers launched together count as a single job. This parameter is the maximum number of Jobs that can be run concurrently. Jobs that are **Completed** are not counted against this quota. +Concurrent jobs in progress | Each supported AWS Region: 20 | Launching a test or cutover instance, or a cleanup action is considered a job. Multiple servers launched together count as a single job. This parameter is the maximum number of Jobs that can be run concurrently. Jobs that are **Completed** are not counted against this quota. @@ -113,2 +123,2 @@ Max non-archived source servers | Each supported AWS Region: 4,000 | This param -Max source servers in a single job | Each supported AWS Region: 200 | Launching a test or cutover instance, or a cleanup action is considered a "Job". If you select multiple servers, and perform one of these actions, they are grouped into a single job. This is the maximum number of servers that can be grouped into a single Job. -Max source servers in all jobs | Each supported AWS Region: 200 | Launching a test or cutover instance, or a cleanup action is considered a "Job". This is the maximum total number of servers that can be configured in all active Jobs. Jobs that are **Completed** are not counted against this quota. +Max source servers in a single job | Each supported AWS Region: 200 | Launching a test or cutover instance, or a cleanup action is considered a job. If you select multiple servers, and perform one of these actions, they are grouped into a single job. This is the maximum number of servers that can be grouped into a single Job. +Max source servers in all jobs | Each supported AWS Region: 200 | Launching a test or cutover instance, or a cleanup action is considered a job. This is the maximum total number of servers that can be configured in all active Jobs. Jobs that are **Completed** are not counted against this quota. @@ -116 +126 @@ Max total source servers per AWS account | Each supported AWS Region: 50,000 | -Max concurrent jobs per source server | Each supported AWS Region: 1 | Launching a test or cutover instance, or a cleanup action is considered a "Job". This is the maximum number of active Jobs, that can be configured per server. Jobs that are **Completed** are not counted against this quota. +Max concurrent jobs per source server | Each supported AWS Region: 1 | Launching a test or cutover instance, or a cleanup action is considered a job. This is the maximum number of active Jobs, that can be configured per server. Jobs that are **Completed** are not counted against this quota. @@ -193,11 +203 @@ MGN uses the following Private API resources as actions in the IAM Policy. [Lear -## Which post-launch scripts does MGN support? - -MGN can run scripts on a launched test or cutover instance. This is done by creating the following folder on the source server and placing the scripts within that folder. - -**Linux** : /boot/post_launch (any files that are marked as executable) - -**Windows** : C:\Program Files (x86)\AWS Replication Agent\post_launch\ (any .exe, .cmd, or .bat files) - -Once you put these scripts in the above folders on the source server, the folder will be replicated to the test or cutover instance and be executed once after the instance boots for the first time. - -###### Note +## How does AWS Transform MGN interact with Interface VPC Endpoints? @@ -205 +205 @@ Once you put these scripts in the above folders on the source server, the folder -Post-launch scripts on Windows run under the Local System context. Post-launch scripts on Linux run under the 'root' user. +If you use Amazon Virtual Private Cloud (Amazon VPC) to host your AWS resources, you can establish a private connection between your VPC and AWS Transform MGN. You can use this connection to allow AWS Transform MGN to communicate with your resources on your VPC without going through the public internet. @@ -207 +207 @@ Post-launch scripts on Windows run under the Local System context. Post-launch s -### Uninstalling VMTools from Windows +Amazon VPC is an AWS service that you can use to launch AWS resources in a virtual network that you define. With a VPC, you have control over your network settings, such as the IP address range, subnets, route tables, and network gateways. With VPC endpoints, the routing between the VPC and AWS services is handled by the AWS network, and you can use IAM policies to control access to service resources. @@ -209 +209 @@ Post-launch scripts on Windows run under the Local System context. Post-launch s -The following script can be utilized to uninstall VMTools post migration from Windows. This is a powershell script. It needs to be wrapped by a .CMD file, as powershell scripts are not run automatically by the post_launch. +To connect your VPC to AWS Transform MGN, you define an _interface VPC endpoint_ for AWS Transform MGN. An interface endpoint is an elastic network interface with a private IP address that serves as an entry point for traffic destined to a supported AWS service. The endpoint provides reliable, scalable connectivity to AWS Transform MGN without requiring an internet gateway, network address translation (NAT) instance, or VPN connection. For more information, see [What is Amazon VPC](https://docs.aws.amazon.com/vpc/latest/userguide/) in the _Amazon VPC User Guide_. @@ -210,0 +211 @@ The following script can be utilized to uninstall VMTools post migration from Wi +Interface VPC endpoints are powered by AWS PrivateLink, an AWS technology that allows private communication between AWS services using an elastic network interface with private IP addresses. For more information, see [AWS PrivateLink](https://aws.amazon.com/privatelink/). @@ -212 +213 @@ The following script can be utilized to uninstall VMTools post migration from Wi - $regpath = "HKLM:\Software\Microsoft\Windows\CurrentVersion\uninstall" +For more information, see [Getting Started](https://docs.aws.amazon.com/vpc/latest/userguide/GetStarted.html) in the _Amazon VPC User Guide_. @@ -214 +215 @@ The following script can be utilized to uninstall VMTools post migration from Wi - Get-childItem $regpath | % { +## How do I use MGN with CloudWatch and EventBridge dashboards? @@ -216 +217 @@ The following script can be utilized to uninstall VMTools post migration from Wi - $keypath = $_.pschildname +You can monitor AWS Transform MGN using CloudWatch, which collects raw data and processes it into readable, near real-time metrics. AWS Transform MGN sends events to Amazon EventBridge whenever a source server launch has completed, a source server reaches the READY_FOR_TEST lifecycle state for the first time, and when the data replication state becomes stalled or when the data replication state is no longer Stalled. You can use EventBridge and these events to write rules that take actions, such as notifying you, when a relevant event occurs. @@ -218 +219 @@ The following script can be utilized to uninstall VMTools post migration from Wi - $key = Get-Itemproperty $regpath\$keypath +You can see MGN in CloudWatch automatic dashboards: @@ -220 +221 @@ The following script can be utilized to uninstall VMTools post migration from Wi - if ($key.DisplayName -match "VMware Tools") { + @@ -222 +223 @@ The following script can be utilized to uninstall VMTools post migration from Wi - $VMwareToolsGUID = $keypath + @@ -224 +225 @@ The following script can be utilized to uninstall VMTools post migration from Wi - } +MGN events can be selected when defining a rule from the EventBridge console: @@ -226,3 +227 @@ The following script can be utilized to uninstall VMTools post migration from Wi - MsiExec.exe /x $VMwareToolsGUID /qn /norestart - - } + @@ -229,0 +229 @@ The following script can be utilized to uninstall VMTools post migration from Wi +[Learn more about monitoring MGN](./monitoring-overview.html). @@ -235,15 +235 @@ Custom DNS settings can cause issues in the replication servers. -Therefore, if you are using a custom DNS, you will need to add a TCP port 53 to the security group outbound rules, for replication and conversion servers. - -## Can I use AWS Transform MGN to migrate servers from VMware Cloud on AWS (VMC) to Amazon EC2? - -Yes, you can. For migrations of source servers from [VMC](https://aws.amazon.com/vmware/) to EC2 you have two options. You can install the agentless appliance in your VMC environment, and migrate your servers using [agentless replication](./agentless-mgn.html), or install the [AWS replication agent](./agent-installation.html) on each of your source servers, and use agent-based replication for your migration. - -## When should I use AWS Elastic Disaster Recovery (AWS DRS) for migration? - -In cases that DRS supports a feature that does not exist in MGN, DRS can be used for migration. You can install the DRS replication agent on your source servers. Following replication, you can launch recovery instances in your target environment, to complete the migration. - -DRS can be used for migration, as the DRS and MGN services use shared technology for performing block level replication. Both MGN and DRS have a replication agent, for replicating servers into a staging area in AWS. MGN supports launching test and cutover instances from the staging area. DRS supports launching recovery instances from the staging area. The technology used by both of these services for launching instances in AWS is very similar. DRS also has the capability to failback to the source environment, after the source environment has recovered. This capability does not exist in MGN. - -Note that you cannot install the DRS and MGN agents on the same server at the same time. If you already installed the MGN agent on a server, and want to use DRS for migration, you must uninstall the MGN agent before installing the DRS agent. - -Note that there are costs associated with using the DRS service. For DRS pricing information see [AWS Elastic Disaster Recovery pricing](https://aws.amazon.com/disaster-recovery/pricing/). +Therefore, if you are using a custom DNS, you need to add a TCP port 53 to the security group outbound rules, for replication and conversion servers. @@ -259 +245 @@ FAQ -Agent related +Agent questions