AWS Transform now modernizes networks during migrations
Instant network modernization and CIDR conflict detection before provisioning replaces days of manual review in VMware migrations.
View original announcement →Visual Summary
What's New
AWS Transform has added two new capabilities to its network migration tooling: a modernization engine that automatically analyzes and optimizes network designs before provisioning, and a universal file ingestion capability that accepts network configuration files in any format from any vendor or tool. The modernization engine surfaces CIDR conflicts, security risks, and structural inefficiencies instantly, replacing what previously required days of manual review. Together, these features allow network teams to arrive at a deployment-ready, AWS-optimized network design faster and with full visibility and control over every decision.
How It Works
- Universal file ingestion: Teams upload network configuration files in any format — VMware NSX exports, Cisco ACI configs, Palo Alto/Fortinet firewall exports, RVTools files, or any other format — and AWS Transform automatically converts them into AWS-compatible network resource definitions (VPCs, subnets, security groups, route tables, NAT gateways, transit gateways, etc.).
- Modernization engine analysis: Once ingested, the engine analyzes the mapped network and generates a set of optimization recommendations covering naming conventions, CIDR sizing, workload tier segmentation, hardware-constraint consolidation, security group rules, and out-of-scope resource removal.
- CIDR conflict detection: The engine cross-references mapped VPC address spaces against VPCs already deployed in the target AWS account(s), identifies conflicts, proposes resolution paths, and implements the customer's chosen resolution before any provisioning begins.
- Human-in-the-loop review: Before deployment, teams review all recommendations in the AWS Transform console, accepting them directly or manually editing any mapped VPC or subnet to retain full control over the final design.
- IaC output options: After review and optimization, teams can deploy directly via AWS Transform or export the final configuration as AWS CDK, Landing Zone Accelerator (LZA), or HashiCorp Terraform for self-managed deployment.
- Multi-account support: For multi-account migrations, the service integrates with AWS Organizations and requires cross-account IAM roles and trusted access to be configured, enabling conflict detection and deployment across multiple target accounts simultaneously.
Why It's Important
- Eliminates the manual review bottleneck: Network design review previously consumed days of specialist time; instant automated analysis compresses this to minutes, directly accelerating migration timelines.
- Shifts conflict discovery left: CIDR conflicts and security misconfigurations are caught before a single resource is provisioned, avoiding costly rollbacks, re-architecture work, and deployment failures that previously surfaced only at deployment time.
- Removes tool and vendor lock-in from the intake process: Accepting any configuration file format means teams are not forced to re-export or reformat data from their existing tools, reducing friction at the start of the migration process.
- Improves cloud-native network hygiene: Recommendations to right-size CIDRs, segment workload tiers, and flag unrestricted security groups mean migrated networks are not just lifted-and-shifted but actively improved during the migration process.
- Preserves team autonomy: Every recommendation is reviewable and overridable, ensuring that automated guidance augments rather than replaces network engineering judgment, which is critical for regulated or complex enterprise environments.
- Accelerates VMware exit timelines: For organizations under pressure to exit VMware licensing agreements, compressing the network migration phase directly reduces the critical path to full workload migration.
How It's Different
- Beyond mapping to modernization: Most migration tools stop at translating source constructs to AWS equivalents one-to-one; AWS Transform's modernization engine actively recommends structural improvements such as tier segmentation and CIDR consolidation that a direct mapping would miss.
- Pre-provisioning conflict resolution: Unlike approaches where CIDR conflicts are discovered during or after deployment, AWS Transform identifies and resolves address space conflicts against live target account VPCs before any infrastructure is created.
- Format-agnostic ingestion: Competing tools typically require specific export formats from specific vendors; AWS Transform accepts any configuration file and performs automatic format conversion, removing a common early-stage migration blocker.
- Agentic AI orchestration: AWS Transform is positioned as the first agentic AI service for VMware migration, meaning it orchestrates multi-step analysis and recommendation workflows autonomously rather than requiring engineers to run discrete, manual tooling steps.
- Integrated end-to-end pipeline: Network modernization is embedded within the same service that handles discovery, dependency mapping, wave planning, and server rehost, providing a unified workflow rather than requiring separate point tools for each migration phase.
- IaC flexibility at output: Teams can choose between direct deployment or exporting to CDK, LZA, or Terraform, accommodating organizations with existing IaC governance requirements without forcing a specific deployment model.
When to Prefer It
- Large-scale VMware migrations with complex network topologies: When migrating hundreds of workloads with intricate on-premises network segmentation, the automated modernization engine provides structured guidance that would be impractical to produce manually at scale.
- Environments with existing AWS VPCs in target accounts: When target accounts already contain deployed VPCs, the CIDR conflict detection capability is essential to prevent address space collisions that would block connectivity or require post-deployment re-addressing.
- Multi-vendor or heterogeneous source environments: When source network configurations span VMware NSX, Cisco ACI, Palo Alto, Fortinet, or other tools, the format-agnostic ingestion eliminates the need to normalize data before migration can begin.
- Organizations under time pressure to exit VMware: When licensing renewal deadlines or cost pressures create urgency, compressing the network design and review phase from days to minutes directly shortens the overall migration timeline.
- Teams seeking cloud network best practices during migration: When the goal is not just to replicate the on-premises network in AWS but to improve security posture, address space efficiency, and naming consistency as part of the migration.
- Enterprises with strict governance requiring human approval: When network changes must be reviewed and approved by engineering teams before deployment, the human-in-the-loop review step with full edit capability satisfies governance requirements while still benefiting from automation.
- Multi-account AWS Organizations deployments: When workloads are distributed across multiple target AWS accounts, the cross-account conflict detection and Organizations integration make AWS Transform the appropriate choice over single-account migration tooling.
Availability
- General Availability: These network modernization capabilities are generally available as of May 20, 2026, as part of the AWS Transform service.
- Supported regions: Available in all AWS Transform Target Regions; the specific region list is maintained in the AWS Transform documentation at the Connect Target Accounts page.
- Pricing: Pricing details are available on the AWS Transform for VMware pricing page; no specific pricing changes for the new capabilities were announced in this release.
- Prerequisite — multi-account deployments: Multi-account migrations require pre-configuration of cross-account IAM roles and trusted access for AWS Organizations before network migration can begin.
- MAP integration: Migrations that are part of the AWS Migration Acceleration Program (MAP 2.0) can provide an MPE ID during connector setup to ensure MAP tags are applied to all resources created during network migration, landing zone, and server rehost stages.
- Format conversion latency: Automatic conversion of unsupported configuration file formats can take up to two hours depending on file size and complexity, which should be factored into migration planning timelines.