On this page
Overview
A financial-services organization needed an AWS landing zone, server migration, Windows file services and a tested disaster-recovery capability. The engagement extended from discovery and foundation build through migration waves, data transfer, permission remediation and recovery drills.
Challenge
A third-party managed firewall controlled both internet and internal traffic, so the AWS design had to fit an existing vendor-operated network model. File migration also changed course after the initial transfer method failed, and migrated permissions needed remediation before users could rely on the new file service.
My role
I led discovery, authored the landing-zone and disaster-recovery designs, deployed the AWS foundation, ran MGN migration waves, designed and built FSx for Windows, coordinated the file-data migration, corrected permissions and led customer failover and failback sessions.
Architecture & approach
Key components: AWS Control Tower, AWS Organizations, AWS Application Migration Service, Amazon EC2, Amazon FSx for Windows, AWS DataSync, Robocopy, Active Directory, AWS Elastic Disaster Recovery, Terraform.
What I implemented
- Deployed the AWS landing zone and integrated it with the managed firewall architecture.
- Troubleshot domain-controller connectivity and later reconfigured east-west traffic paths.
- Executed MGN test and cutover waves, including off-hours migration bridges.
- Built Amazon FSx for Windows and replaced the initial file system after a throughput issue.
- Changed the data-transfer method from DataSync to Robocopy from an EC2 host when the original approach did not work.
- Remediated file permissions and produced the disaster-recovery design and operating documentation.
- Led failover and failback disaster-recovery drills with the customer.
Key decisions
- Changed the file-migration method based on observed failure rather than continuing with an unsuitable tool.
- Treated the managed firewall vendor as part of the operating model and validated internet, domain and east-west flows explicitly.
- Paired recovery design with customer-run exercises so the runbook reflected actual behavior.
Security & reliability
The implementation used a governed AWS foundation, controlled network paths, managed Windows file services and documented recovery procedures. Migration and DR activities were tested with customer participants and updated based on the results.
Technologies
Outcome
The organization received a working AWS foundation, migrated workloads, production file services with corrected permissions, and a tested failover and failback process.
Lessons & takeaways
Key takeaway
The file-services work reinforced the need to validate throughput, transfer behavior and permissions early. A successful copy is not a complete migration until access and operational performance are confirmed.