PartnersTrust CenterInvestorsCareers

CAELION Insights

Customer Brief: Industrial Manufacturer — A Global Core Network on AWS Cloud WAN

An industrial manufacturer's global network had become something nobody could fully explain: an accreted mesh of Transit Gateway attachments, route tables, and site links carrying both corporate IT and operational technology traffic. CAELION's Cloud WAN professional services engagement replaced it with a segmented, policy-driven core network — migrated attachment by attachment with zero downtime, and delivered entirely as parameterized infrastructure as code.

The organization

The client is an industrial manufacturer operating production plants, distribution sites, and corporate offices across multiple regions. Its estate is split in the way that defines the sector: an IT side of enterprise applications, cloud workloads, and corporate connectivity, and an OT side of plant-floor systems, industrial control networks, and the site infrastructure that keeps production lines running. Both rode the same global network — a Transit Gateway-centered architecture connecting AWS regions, data centers, and factory sites.

The challenge

The network worked, in the sense that packets flowed. But it had grown by accretion rather than design. Route tables encoded years of one-off decisions; attachments had been added under project pressure and never revisited; and the segmentation between IT and OT traffic existed as convention and firewall rules rather than as an enforced property of the network itself. When engineers needed to answer basic questions — what can reach this plant network? what happens if this attachment fails? — the answer required archaeology, not architecture.

For a manufacturer, this is more than untidiness. IT/OT convergence without enforced segmentation means a compromise on the corporate side has a routable path toward production systems. And a network nobody can reason about is a network nobody can confidently change — which is why it had accreted in the first place. The client needed a global core network that was segmented by design, migrated from the existing Transit Gateway estate without interrupting production, and operable by its own team afterward.

The deployment

CAELION delivered the engagement as a professional services program in three movements.

First, core network design on AWS Cloud WAN. CAELION designed a global core network with segmentation as a first-class construct: distinct segments for IT and OT traffic, with inter-segment reachability defined explicitly in policy rather than emerging implicitly from route tables. The design encodes intent — which classes of traffic may meet, where, and under what inspection — in a form the network itself enforces.

Second, a sequenced Transit Gateway migration. Rather than a cutover event, CAELION planned and executed the migration attachment by attachment. Each attachment was moved in a defined sequence with validated routing state before and after, rollback prepared at every step, and production traffic — including live plant connectivity — never interrupted. The migration completed with zero downtime across the estate.

Third, hybrid connectivity, unified. The manufacturer's Direct Connect circuits and SD-WAN overlay for factory sites were integrated into the same core network and the same segmentation model, so a plant reaching AWS and a data center reaching a partner traverse one coherent, policy-governed fabric rather than parallel arrangements with separate rules.

Everything shipped as parameterized infrastructure as code. The core network policy, segments, attachments, and hybrid integrations exist as versioned, reviewable templates the client's team owns — not as console state reconstructed from memory, and not as a diagram in a handover deck.

The results

DimensionBeforeAfter
IT/OT segmentationConvention and firewall rulesEnforced by core network policy
Migration downtimeZero, sequenced attachment by attachment
Hybrid connectivityParallel Direct Connect and SD-WAN arrangementsOne policy-governed fabric
Network definitionAccreted console state and tribal knowledgeParameterized, versioned IaC
OperabilityChange by archaeologyChange by reviewed code

The headline result is the one the operations team names first: they can reason about the network for the first time. Reachability questions are answered by reading policy, not by tracing route tables across accounts. Proposed changes are pull requests with diffs and reviews, not console edits with hope. New sites and new attachments are instantiated from the same parameterized templates, so the network grows by design going forward rather than by accretion.

Segmentation between IT and OT is now a property the network enforces, materially narrowing the paths an IT-side compromise could take toward production systems. And the migration itself — the part that keeps network leads awake — completed without a minute of downtime for plants or corporate sites.

Why it worked

The engagement worked because it treated migration as a sequence of small, reversible, validated steps rather than a cutover to be survived. It worked because segmentation was designed into the core network's policy rather than bolted on around it, which is the only version of IT/OT separation that holds under change. And it worked because the deliverable was code, not a diagram: the client's team inherited an operable system they can read, review, and extend, rather than a dependency on the consultants who built it.

If your global network has become something your team operates but cannot explain, CAELION's Cloud WAN professional services team can walk you through the design and migration approach in a private briefing.

Client identity withheld by agreement. Figures anonymized and rounded from engagement reporting.

Related

Continue reading

Networking

Migrating from Transit Gateway to AWS Cloud WAN Without Downtime

June 16, 2026

Engineering

Remediation as Code: Why Findings Should Ship as Runnable Infrastructure

March 24, 2026

Cloud Operations

AWS Well-Architected Reviews That Actually Change Something

April 7, 2026