Forum Discussion
What is the best way to handle networking during a long-running cloud migration?
You are trying to keep AWS and Azure communicating reliably while applications and their dependencies move at different times. I would use a controlled hybrid network, not flatten both clouds into one unrestricted domain. First map application dependencies, address ranges, DNS names, and latency requirements; resolve overlapping subnets before connecting networks. Establish redundant site-to-site VPN connectivity as a baseline, then assess paired AWS Direct Connect and Azure ExpressRoute circuits if measured throughput, consistency, or migration volume justifies them. An Azure hub can centralize gateways, firewall inspection, and DNS forwarding while workload spokes remain separated. Advertise only required prefixes through BGP and allow necessary application ports explicitly. Configure conditional DNS forwarding and test resolution from both clouds. Move chatty application/database dependencies together where possible. Monitor tunnel health, latency, transferred bytes, and cross-cloud charges, and test backup-path failover before each migration wave.