Forum Discussion

VishwaSanthosh's avatar
VishwaSanthosh
Copper Contributor
Oct 08, 2026

What is the best way to handle networking during a long-running cloud migration?

Hi everyone,

 

I'd like to get some opinions from people who have worked on large-scale cloud migrations.

 

Consider a migration where workloads are gradually moved from AWS to Azure over several weeks or months rather than being migrated in a single cutover.

 

During the migration period, both environments need to remain operational.

 

A simplified architecture could look like:

 

AWS workloads

|

| Existing connectivity

|

AWS Network

|

| Inter-cloud connectivity

|

Azure Network

|

|

Azure workloads

 

The challenge is that applications may temporarily become distributed across both clouds.

 

For example:

 

• Application servers may still be running in AWS.

• New application components may already be deployed in Azure.

• Databases or shared services may remain in AWS temporarily.

• DNS and routing may need to support both environments.

• Migration tools may require connectivity to source and target environments.

• Some workloads may be migrated much earlier than their dependent services.

 

For a long-running migration like this, what architecture would you recommend?

 

Some options I have been considering are:

 

1. Site-to-site VPN between AWS and Azure

2. Dedicated connectivity such as AWS Direct Connect + Azure ExpressRoute

3. A combination of dedicated connectivity and VPN for backup

4. A hub-and-spoke architecture in Azure with controlled connectivity back to AWS

5. Application-level connectivity rather than relying heavily on network-level connectivity

 

Another question is how you would handle routing.

 

Would you prefer to:

 

• Keep AWS and Azure routing domains mostly independent?

• Use a centralized hub for cross-cloud traffic?

• Advertise routes dynamically using BGP?

• Restrict cross-cloud communication to only the application dependencies that require it?

 

For a migration lasting several months, what approach have you found to be the most reliable and easiest to operate?

 

I'm particularly interested in lessons learned around:

 

• Routing

• DNS

• Security

• Latency

• Failover

• Monitoring

• Avoiding unexpected cross-cloud traffic costs

 

Would appreciate experiences from anyone who has handled a production AWS-to-Azure or Azure-to-AWS migration.

1 Reply

  • You are trying to keep AWS and Azure communicating reliably while applications and their dependencies move at different times. I would use a controlled hybrid network, not flatten both clouds into one unrestricted domain. First map application dependencies, address ranges, DNS names, and latency requirements; resolve overlapping subnets before connecting networks. Establish redundant site-to-site VPN connectivity as a baseline, then assess paired AWS Direct Connect and Azure ExpressRoute circuits if measured throughput, consistency, or migration volume justifies them. An Azure hub can centralize gateways, firewall inspection, and DNS forwarding while workload spokes remain separated. Advertise only required prefixes through BGP and allow necessary application ports explicitly. Configure conditional DNS forwarding and test resolution from both clouds. Move chatty application/database dependencies together where possible. Monitor tunnel health, latency, transferred bytes, and cross-cloud charges, and test backup-path failover before each migration wave.