AWS Security ChangesHomeSearch

AWS mgn: MGN replication FAQ reorganized; adds EBS encryption & CloudTrail guidance

Service: mgn · 2026-09-27 · Documentation medium

File: mgn/latest/ug/Replication-Related-FAQ.md · Type: encryption

Summary

Reorders and rewrites the AWS Transform MGN replication FAQ (renamed 'Replication questions', TOC and section ordering updated, wording modernized). Substantive additions include a new section on how base snapshot encryption is governed by the region's default EBS encryption setting, including steps to encrypt an existing unencrypted base snapshot; a reworded CloudTrail logging answer; notes on the inbound TCP 1500 security group, bandwidth throttling, disk replication limits, crash consistency, and AL2023 server migration with its new S3 repo dependency and DNS/endpoint policy considerations.

Security assessment

The diff adds new security-relevant documentation: an explanation that MGN base snapshot encryption depends on the region's default EBS encryption setting, with remediation steps (delete unencrypted snapshot, enable default EBS encryption, re-run migration), plus restated guidance that MGN API calls are visible in CloudTrail and that the staging-area security group opens inbound TCP 1500 that can be limited via ACLs/network controls. No CVE, incident, or specific vulnerability is referenced—this is best-practice/feature documentation rather than a fix, so it is security documentation of medium impact rather than a patched vulnerability.

Evidence

The encryption status of AWS Transform MGN base snapshots is determined by the default EBS (Elastic Block Store) encryption setting for the respective AWS region. Encryption Scenarios:

Diff

diff --git a/mgn/latest/ug/Replication-Related-FAQ.md b/mgn/latest/ug/Replication-Related-FAQ.md
index 62a26d17d..6966e46a3 100644
--- a//mgn/latest/ug/Replication-Related-FAQ.md
+++ b//mgn/latest/ug/Replication-Related-FAQ.md
@@ -7 +7 @@
-What is the lifecycle of the snapshots and volumes automatically created during migration?What do Lag and Backlog mean during replication?What is Continuous, Block level data replication?What are the Replication initiation Steps?Is the replicated data encrypted?How is the Replication Server provisioned and managed in the Staging Area?What type of replication server is utilized in the AWS Transform MGN staging area?Can we set specific IP addresses for the replication server or conversion server in the AWS Transform MGN staging area?Does AWS Transform MGN compress data during replication?Are events that are generated by the AWS Transform MGN servers logged in Cloudtrail in AWS?How many snapshots does AWS Transform MGN create?Does AWS Transform MGN delete snapshots?How much capacity is allocated to the staging area?Why is 0.0.0.0:1500 added to inbound rules in the staging area?Can AWS Transform MGN replicate Oracle ASM?How long does a rescan take?How can I control the bandwidth used for replication?Are migrations performed by Application Migration Service crash consistent?How can I perform an SSL connectivity and bandwidth test?Why are MGN replication and conversion servers changing to Amazon Linux 2023?
+What is Continuous, Block level data replication?What are the Replication initiation Steps?What do Lag and Backlog mean during replication?How long does a rescan take?Is the replicated data encrypted?Does AWS Transform MGN compress data during replication?Are migrations performed by AWS Transform MGN crash consistent?How is the Replication Server provisioned and managed in the Staging Area?What type of replication server is used in the AWS Transform MGN staging area?What are the differences between conversion servers and replication servers?Why are MGN replication and conversion servers changing to Amazon Linux 2023?Can we set specific IP addresses for the replication server or conversion server in the AWS Transform MGN staging area?How much capacity is allocated to the staging area?How many disks can the AWS Replication Agent replicate?What is the lifecycle of the snapshots and volumes automatically created during migration?How many snapshots does AWS Transform MGN create?Does AWS Transform MGN delete snapshots?How can we encrypt an unencrypted AWS Transform MGN base snapshot?Why is 0.0.0.0:1500 added to inbound rules in the staging area?How can I control the bandwidth used for replication?How can I perform an SSL connectivity and bandwidth test?Can AWS Transform MGN replicate Oracle ASM?Are events generated by the AWS Transform MGN servers logged in CloudTrail?
@@ -11 +11 @@ NEW - You can now accelerate your migration and modernization with AWS Transform
-# Replication related FAQs
+# Replication questions
@@ -17,4 +16,0 @@ This section contains answers to questions about data replication.
-  * What is the lifecycle of the snapshots and volumes automatically created during migration?
-
-  * What do Lag and Backlog mean during replication?
-
@@ -25,3 +21 @@ This section contains answers to questions about data replication.
-  * Is the replicated data encrypted?
-
-  * How is the Replication Server provisioned and managed in the Staging Area?
+  * What do Lag and Backlog mean during replication?
@@ -29 +23 @@ This section contains answers to questions about data replication.
-  * What type of replication server is utilized in the AWS Transform MGN staging area?
+  * How long does a rescan take?
@@ -31 +25 @@ This section contains answers to questions about data replication.
-  * Can we set specific IP addresses for the replication server or conversion server in the AWS Transform MGN staging area?
+  * Is the replicated data encrypted?
@@ -35,9 +29 @@ This section contains answers to questions about data replication.
-  * Are events that are generated by the AWS Transform MGN servers logged in Cloudtrail in AWS?
-
-  * How many snapshots does AWS Transform MGN create?
-
-  * Does AWS Transform MGN delete snapshots?
-
-  * How much capacity is allocated to the staging area?
-
-  * Why is 0.0.0.0:1500 added to inbound rules in the staging area?
+  * Are migrations performed by AWS Transform MGN crash consistent?
@@ -45,5 +31 @@ This section contains answers to questions about data replication.
-  * Can AWS Transform MGN replicate Oracle ASM?
-
-  * How long does a rescan take?
-
-  * How can I control the bandwidth used for replication?
+  * How is the Replication Server provisioned and managed in the Staging Area?
@@ -51 +33 @@ This section contains answers to questions about data replication.
-  * Are migrations performed by Application Migration Service crash consistent?
+  * What type of replication server is used in the AWS Transform MGN staging area?
@@ -53 +35 @@ This section contains answers to questions about data replication.
-  * How can I perform an SSL connectivity and bandwidth test?
+  * What are the differences between conversion servers and replication servers?
@@ -56,0 +39 @@ This section contains answers to questions about data replication.
+  * Can we set specific IP addresses for the replication server or conversion server in the AWS Transform MGN staging area?
@@ -57,0 +41 @@ This section contains answers to questions about data replication.
+  * How much capacity is allocated to the staging area?
@@ -58,0 +43 @@ This section contains answers to questions about data replication.
+  * How many disks can the AWS Replication Agent replicate?
@@ -60 +45 @@ This section contains answers to questions about data replication.
-## What is the lifecycle of the snapshots and volumes automatically created during migration?
+  * What is the lifecycle of the snapshots and volumes automatically created during migration?
@@ -62 +47 @@ This section contains answers to questions about data replication.
-For each source block device, MGN creates a corresponding EBS volume. If the agent on the source machine cannot send data to a volume, MGN creates a replacement volume. The old volume might remain for approximately 10 minutes after the replacement volume comes online. Volume replacement occurs only when there is an agent communication failure, which typically results from an unstable network connection.
+  * How many snapshots does AWS Transform MGN create?
@@ -64 +49 @@ For each source block device, MGN creates a corresponding EBS volume. If the age
-MGN takes regular EBS snapshots to use incremental snapshot capabilities. Frequent snapshots reduce the time required to create each snapshot, which means that test or cutover instance launches are not delayed while waiting for EBS snapshots to complete. MGN retains 5–6 snapshots per volume to ensure that at least one completed snapshot is available at launch time. EBS snapshot creation has no SLA and can be delayed. Snapshot creation can also fail independently of the API call. MGN retains multiple snapshots to provide redundancy if the most recent snapshot fails.
+  * Does AWS Transform MGN delete snapshots?
@@ -66 +51 @@ MGN takes regular EBS snapshots to use incremental snapshot capabilities. Freque
-## What do Lag and Backlog mean during replication?
+  * How can we encrypt an unencrypted AWS Transform MGN base snapshot?
@@ -68 +53 @@ MGN takes regular EBS snapshots to use incremental snapshot capabilities. Freque
-During replication you may see a server falls out of Continuous Data Protection (CDP) mode. This may occur for various reasons, typically related to the network throughput or interruption.
+  * Why is 0.0.0.0:1500 added to inbound rules in the staging area?
@@ -70 +55 @@ During replication you may see a server falls out of Continuous Data Protection
-  * **Lag** – The amount of time since the server was last in CDP mode.
+  * How can I control the bandwidth used for replication?
@@ -72 +57 @@ During replication you may see a server falls out of Continuous Data Protection
-  * **Backlog** – The amount of data that was written to the disk and still needs to be replicated to reach CDP mode.
+  * How can I perform an SSL connectivity and bandwidth test?
@@ -74 +59,3 @@ During replication you may see a server falls out of Continuous Data Protection
-  * **ETA** – The estimated time remaining to return to CDP.
+  * Can AWS Transform MGN replicate Oracle ASM?
+
+  * Are events generated by the AWS Transform MGN servers logged in CloudTrail?
@@ -87 +74 @@ The following replication steps are involved in the automatic creation of the re
-  * Create security groups - Creating EC2 security groups with inbound TCP port 1500 allowed. This security group will be attached to replication server.
+  * Create security groups - Creating EC2 security groups with inbound TCP port 1500 allowed. This security group is attached to the replication server.
@@ -91 +78 @@ The following replication steps are involved in the automatic creation of the re
-  * Boot Replication Server - The EC2 instance completes boot process which will now function as a replication server.
+  * Boot Replication Server - The EC2 instance completes boot process which now functions as a replication server.
@@ -93 +80 @@ The following replication steps are involved in the automatic creation of the re
-  * Authenticate with service - Using the user data scripts and the EC2 instance configuration, the instance (replication server) will authenticate with AWS Transform MGN using service/vpc endpoint. 
+  * Authenticate with service - Using the user data scripts and the EC2 instance configuration, the instance (replication server) authenticates with AWS Transform MGN using service/vpc endpoint. 
@@ -95 +82 @@ The following replication steps are involved in the automatic creation of the re
-  * Download replication software - The Replication Server downloads replication software from S3. This replication software will write the incoming replicated data to the Replication Server disks.
+  * Download replication software - The Replication Server downloads replication software from S3. This replication software writes the incoming replicated data to the Replication Server disks.
@@ -111,0 +99,17 @@ The following replication steps are involved in the automatic creation of the re
+## What do Lag and Backlog mean during replication?
+
+During replication you might see a server falls out of Continuous Data Protection (CDP) mode. This might occur for various reasons, typically related to the network throughput or interruption.
+
+  * **Lag** – The amount of time since the server was last in CDP mode.
+
+  * **Backlog** – The amount of data that was written to the disk and still needs to be replicated to reach CDP mode.
+
+  * **ETA** – The estimated time remaining to return to CDP.
+
+
+
+
+## How long does a rescan take?
+
+The rescan time varies depending on the size of the source disks. The time depends on the performance of the disks (linear read), the staging area disk performance, and the rate of write operations on the source server (which are sent in parallel with the rescan). A rescan is progressing normally as long as its completion percentage continues to advance.
+
@@ -115,0 +120,8 @@ AWS Transform MGN encrypts all the data in transit.
+## Does AWS Transform MGN compress data during replication?
+
+Yes, AWS Transform MGN uses LZ4 compression during transit resulting in 60–70% compression depending on the type of data.
+
+## Are migrations performed by AWS Transform MGN crash consistent?
+
+Yes. MGN migrations are crash consistent. The data that MGN retrieves when the server becomes available is the data on the server at the moment before it shut down.
+
@@ -120 +132 @@ AWS Transform MGN provisions the Replication Server(s) and automatically manages
-## What type of replication server is utilized in the AWS Transform MGN staging area?
+## What type of replication server is used in the AWS Transform MGN staging area?
@@ -123,0 +136,36 @@ AWS Transform MGN provisions a t3.Small server. The typical ratio of volumes to
+## What are the differences between conversion servers and replication servers?
+
+Replication servers run on Linux and conversion servers (for Windows machines) run on Windows. 
+
+The conversion is done by AWS Transform MGN automatically bringing up a vanilla Windows conversion server machines in the same subnet with the replication servers as part of the launch job. 
+
+Both conversion and replication servers have public IPs.
+
+The conversion servers use the same security groups as the Replication Server.
+
+The conversion server must be able to access the MGN's service manager. 
+
+The conversion server machines, just like the Replication servers are managed automatically by AWS Transform MGN. Any attempt to disrupt their automated functionality results in failed conversions.
+
+## Why are MGN replication and conversion servers changing to Amazon Linux 2023?
+
+Beginning August 15, 2026, MGN will use Amazon Linux 2023 (AL2023) for its replication and conversion servers because [Amazon Linux 2 (AL2) reaches end of support on June 30, 2026](https://aws.amazon.com/amazon-linux-2/faqs/).
+
+**What happens to in-progress jobs:** If you have a replication or conversion job in progress on August 15, 2026, your existing AL2 instance continues running until the end of its 30-day lifecycle, and MGN replaces it automatically. If you have no job running on August 15, 2026, the next job you start immediately uses AL2023.
+
+**New S3 bucket dependency:** AL2023 introduces a new S3 bucket dependency for package management that was not required by AL2-based servers. MGN replication and conversion servers connect to the following AL2023 package repository. In the following URL, replace `region` with the AWS Region code where your staging area is configured (for example, `us-east-1`).
+    
+    
+    https://al2023-repos-region-de612dc2.s3.dualstack.region.amazonaws.com
+
+**Review your configuration before August 15, 2026** if any of the following apply:
+
+  1. **Route 53 DNS Firewall, network-level blocklists, or outbound DNS restrictions**. Verify that `al2023-repos-`region`-de612dc2.s3.dualstack.`region`.amazonaws.com` is not blocked. If you use a blocklist approach, check for wildcard rules (for example, `*.s3.dualstack.`region`.amazonaws.com`) that may catch this domain. If you use an allowlist approach, add this domain explicitly. For more information, see [Required connectivity settings](./preparing-environments.html#Network-Requirements) and [AL2023 repository configuration](https://docs.aws.amazon.com/linux/al2023/ug/managing-repos-os-updates.html#dnf-repo-addition).
+
+  2. **Isolated subnets with a restrictive S3 VPC Gateway Endpoint policy**. Add `arn:aws:s3:::al2023-repos-`region`-de612dc2/*` to your endpoint policy to allow the replication server to download AL2023 packages.
+
+  3. **Security or compliance policies that require pre-approval of new operating systems**. If your policy requires explicit approval of new operating systems or AMI IDs before they run in your account (for example, OS allowlisting, change management controls, or regulatory requirements), plan accordingly before August 15, 2026.
+
+
+
+
@@ -128 +176 @@ No, you cannot specify or assign static IP addresses for the replication server
-## Does AWS Transform MGN compress data during replication?
+## How much capacity is allocated to the staging area?
@@ -130 +178,9 @@ No, you cannot specify or assign static IP addresses for the replication server
-Yes, AWS Transform MGN uses LZ4 compression during transit resulting in 60–70% compression depending on the type of data.
+A volume is created for each volume in the source infrastructure of the same size.
+
+## How many disks can the AWS Replication Agent replicate?
+
+The agent can replicate up to 63 disks from a single server. Ensure that the replication server instance type supports at least the number of disks being replicated.
+
+###### Note
+
+To replicate more than 50 disks, you must use a 24xlarge or larger instance size from an instance family that supports dedicated Amazon EBS volume attachments (for example, m7i, c7i, or r7i). Smaller sizes support fewer replicated disks. For the number of volumes that each instance type supports, see [Amazon EBS volume limits for Amazon EC2 instances](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/volume_limits.html) in the _Amazon EC2 User Guide_.
@@ -132 +188 @@ Yes, AWS Transform MGN uses LZ4 compression during transit resulting in 60–70%
-## Are events that are generated by the AWS Transform MGN servers logged in Cloudtrail in AWS?
+## What is the lifecycle of the snapshots and volumes automatically created during migration?
@@ -134 +190,3 @@ Yes, AWS Transform MGN uses LZ4 compression during transit resulting in 60–70%
-Yes, AWS Transform MGN generates standard AWS API calls that are visible in CloudTrail.
+For each source block device, MGN creates a corresponding EBS volume. If the agent on the source machine cannot send data to a volume, MGN creates a replacement volume. The old volume might remain for approximately 10 minutes after the replacement volume comes online. Volume replacement occurs only when there is an agent communication failure, which typically results from an unstable network connection.
+
+MGN takes regular EBS snapshots to use incremental snapshot capabilities. Frequent snapshots reduce the time required to create each snapshot, which means that test or cutover instance launches are not delayed while waiting for EBS snapshots to complete. MGN retains 5–6 snapshots per volume to ensure that at least one completed snapshot is available at launch time. EBS snapshot creation has no SLA and can be delayed. Snapshot creation can also fail independently of the API call. MGN retains multiple snapshots to provide redundancy if the most recent snapshot fails.
@@ -138 +196 @@ Yes, AWS Transform MGN generates standard AWS API calls that are visible in Clou
-5–7 for each disk. Frequency and exact number depend on various factors, such as change rate on the source server and network stability.
+MGN creates 5–7 snapshots for each disk. The frequency and exact number depend on factors such as the change rate on the source server and network stability.
@@ -140 +198 @@ Yes, AWS Transform MGN generates standard AWS API calls that are visible in Clou
-There is currently no mechanism for users to adjust the frequency and number of snapshots.
+You cannot adjust the frequency or number of snapshots.
@@ -146 +204 @@ AWS Transform MGN automatically deletes snapshots that are no longer used (such
-## How much capacity is allocated to the staging area?
+## How can we encrypt an unencrypted AWS Transform MGN base snapshot?
@@ -148 +206 @@ AWS Transform MGN automatically deletes snapshots that are no longer used (such
-A volume is created for each volume in the source infrastructure of the same size.
+The encryption status of AWS Transform MGN base snapshots is determined by the default EBS (Elastic Block Store) encryption setting for the respective AWS region. Encryption Scenarios:
@@ -150 +208 @@ A volume is created for each volume in the source infrastructure of the same siz
-## Why is 0.0.0.0:1500 added to inbound rules in the staging area?
+  * Default EBS Encryption Enabled:
@@ -152 +210 @@ A volume is created for each volume in the source infrastructure of the same siz
-AWS Transform MGN uses TCP Port 1500 for replication between the Source Agents and the replication server. The connection is open for all IPs and can be managed by ACLs or networks controls to limit inbound IPs.