How a NAT Gateway is charged
A NAT Gateway has two charges:
- An hourly charge for every hour it exists, whether or not traffic flows through it.
- A data processing charge for every gigabyte that passes through it, in either direction.
The hourly charge is predictable. The processing charge is what grows: every gigabyte a private workload sends to the internet, to another AWS service’s public endpoint, or back from them, is processed by the gateway. Normal data transfer charges apply on top.
Find the traffic behind the cost
- Confirm it is processing, not hours. In Cost Explorer, group by usage type and look for NAT Gateway bytes versus NAT Gateway hours.
- Find the busiest gateway. The
BytesOutToDestinationandBytesInFromDestinationCloudWatch metrics show traffic per gateway. - Find the destinations. Turn on VPC Flow Logs for the gateway’s network interface and group by destination address. In most environments, a large share goes to Amazon S3, Amazon ECR or another AWS service.
The fixes, in the order to try them
1. Gateway endpoints for S3 and DynamoDB
Gateway VPC endpoints route traffic to Amazon S3 and Amazon DynamoDB privately, and AWS charges nothing for them: no hourly charge and no processing charge. If your workloads pull container layers, read files or write logs to S3 through a NAT Gateway, this is usually the biggest and cheapest win.
resource "aws_vpc_endpoint" "s3" { vpc_id = aws_vpc.main.id service_name = "com.amazonaws.ap-southeast-2.s3" vpc_endpoint_type = "Gateway" route_table_ids = aws_route_table.private[*].id }
2. Interface endpoints, where the numbers work
Other services, such as Amazon ECR, AWS Secrets Manager and Amazon CloudWatch Logs, need interface endpoints. These are not free: each is charged per hour in every Availability Zone it runs in, plus a per-gigabyte charge. They pay off for services with heavy, steady traffic, and cost more than they save for services you call occasionally. Do the sum per service before adding them.
3. Keep traffic in its Availability Zone
Run one NAT Gateway per Availability Zone and route each private subnet to the gateway in its own zone. Sending traffic to a gateway in another zone adds cross-zone data transfer charges, and makes that zone a single point of failure.
4. Question the traffic itself
Large, repeated downloads (the same container images, packages or datasets on every deploy) are often better cached, or pulled once into your own registry or bucket.
What not to do
Don’t replace NAT Gateways with public IP addresses on workloads just to save money. It removes a layer of protection, and AWS charges for every public IPv4 address anyway. Keep workloads private, and reduce what they send through the gateway.
Sources
See also Lower cloud costs and AWS data transfer costs, explained.
Next step
Want a second pair of eyes on your bill?
On a 30-minute call we’ll look at where your networking costs come from and which fixes apply.