Data transfer
Choosing between DataSync, Transfer Family, Snowball Edge, S3 Transfer Acceleration, Direct Connect, VPN and Storage Gateway by data size, bandwidth, deadline and pattern.
Exam tasks: 4.2 (select the appropriate data transfer service and migration strategy, apply the appropriate security methods to migration tools)
The decision: how much data, how much usable bandwidth, how long until the deadline, and is this a one-time move or a flow that keeps running afterwards?
Choosing a service
How long will the network take?
Transfer time in days is roughly bytes × 8 ÷ (bits per second × utilization) ÷ 86,400. The table assumes you can
sustain 80% of the link for the transfer, which is optimistic if the link also carries production traffic.
| Data | 100 Mbps | 1 Gbps | 10 Gbps |
|---|---|---|---|
| 1 TB | about 28 hours | about 3 hours | about 17 minutes |
| 10 TB | about 12 days | about 28 hours | about 3 hours |
| 100 TB | about 116 days | about 12 days | about 28 hours |
| 1 PB | about 3 years | about 116 days | about 12 days |
Do the arithmetic
Many transfer questions are solved by a quick calculation. If the network needs more than about a week and the deadline is close, or the link is shared with production, look for an offline option. If the network finishes comfortably, online is simpler and avoids shipping logistics.
Online options
| Service | Best for | What to know |
|---|---|---|
| DataSync | Bulk or recurring copies of NFS, SMB, HDFS or object stores into S3, EFS or any FSx file system | Agent VM on premises. Incremental, verifies integrity, preserves metadata, can throttle bandwidth, runs on a schedule. Also copies between AWS storage services and other clouds |
| Transfer Family | Partners or legacy systems that push files over SFTP, FTPS, FTP or AS2 | Managed endpoint in front of S3 or EFS. Keeps partners' existing clients and scripts unchanged. Identity from service-managed users, Directory Service or a custom Lambda provider |
| S3 Transfer Acceleration | Uploads to one bucket from clients far from its Region | Routes through CloudFront edge locations over the AWS backbone. Uses a separate accelerate endpoint. You pay only when it's faster |
| Direct Connect | Large, steady transfers and a private, consistent path | Dedicated connections from 1 Gbps up, or smaller hosted connections through a partner. Not encrypted by itself: add MACsec or a VPN over it |
| Site-to-Site VPN | Quick encrypted connectivity over the internet | Up in minutes, but internet throughput and latency vary |
Transfer Acceleration for a data center move
Transfer Acceleration speeds up long-distance uploads to S3. It doesn't add bandwidth: if the data center's internet link is the bottleneck, it won't help. It also only targets S3, so it's wrong for moving an NFS share into EFS.
FTP and encryption
Transfer Family supports plain FTP only on endpoints inside a VPC, never on public ones, because FTP sends credentials in cleartext. If a question requires encryption in transit, pick SFTP or FTPS.
For network details see hybrid connectivity.
Offline: Snowball Edge
An AWS-owned, ruggedized device shipped to your site. You copy data locally, ship it back, and AWS imports it into S3.
- Storage Optimized devices are for bulk migration. Compute Optimized devices add more vCPUs for edge processing at disconnected sites.
- Data is encrypted with KMS keys you control, and the device is erased after import.
- Order several devices in parallel for petabyte-scale moves. The end-to-end cycle, including shipping, takes days to weeks per device.
- Pair it with an ongoing method, like DataSync or DMS CDC, to catch changes made after the copy.
2025 availability change
Snowball Edge stopped accepting new customers on November 7, 2025. AWS now points new customers to DataSync for online transfer and AWS Data Transfer Terminal, physical sites where you bring your own storage and upload at high speed. The exam still tests Snowball Edge as the offline answer.
Legacy: use Snowball Edge, or Data Transfer Terminal instead
Snowmobile, a shipping container for exabyte-scale moves, has been retired. Snowcone, the small 8 TB and 14 TB device, has been discontinued. Older material may still use them as answers.
Hybrid and ongoing: Storage Gateway
Storage Gateway runs as a VM or hardware appliance on premises. It gives local applications a familiar protocol and a local cache, and stores the data in AWS.
| Gateway | Protocol on premises | Data lands in | Use for |
|---|---|---|---|
| S3 File Gateway | NFS or SMB | S3 objects, one file per object | File shares backed by S3, feeding data lakes, tiering old files to cheaper S3 classes |
| FSx File Gateway | SMB | FSx for Windows File Server | Low-latency local access to a cloud Windows file share |
| Volume Gateway, cached | iSCSI | S3, primary data in AWS with a local cache | Extending block storage into AWS |
| Volume Gateway, stored | iSCSI | Local primary copy, async backup to AWS as EBS snapshots | Keeping all data local with cloud backup and DR |
| Tape Gateway | iSCSI virtual tape library | S3, archived to S3 Glacier Flexible Retrieval or Deep Archive | Replacing physical tape with existing backup software |
Legacy: use FSx for Windows File Server accessed directly, or S3 File Gateway instead
FSx File Gateway stopped accepting new customers in October 2024. It still appears in exam questions about caching an FSx for Windows share locally.
Migration or hybrid?
DataSync moves data and you're done. Storage Gateway is for when applications keep running on premises and keep using NFS, SMB, iSCSI or tape. If a question says the application stays on premises, it's usually a gateway.
Scenarios
At best, 1 Gbps moves about 8.6 TB a day, so 400 TB would take well over 6 weeks even with the link to itself. Transfer Acceleration can't add bandwidth. A new Direct Connect usually takes weeks to provision, which uses up the deadline. A File Gateway still sends everything over the same link. Several Snowball Edge devices in parallel avoid the network entirely.
Transfer Family keeps SFTP, and moving the hostname means partners' clients and scripts don't change. DataSync agents at partner sites and IAM access keys both force partners to change their process. Plain FTP isn't allowed on public endpoints, and it would drop encryption anyway.
The application stays on premises, uses SMB, and wants files stored as S3 objects with a local cache: that is S3 File Gateway. DataSync copies data but doesn't give the app a cached share. Volume Gateway exposes iSCSI block volumes, not SMB files, and Transfer Family is for file transfer protocols, not a mounted share.
Further reading
Assessment and the 7 Rs
Picking a migration strategy per application, building the business case, discovering servers and dependencies, and planning waves.
Server migration
Rehosting servers with Application Migration Service, one-off image imports with VM Import/Export, and the options for VMware estates.