1. Home
  2. Articles
  3. Guide

Guide

Why is my AWS NAT Gateway bill so high?

NAT Gateways are one of the most common surprises on an AWS bill. Here is how they are charged, how to find the traffic behind the cost, and the fixes that usually work.

  • By Anwar Alawad
  • Updated 1 October 2026
  • Read 6 min
01 · Pricing

How a NAT Gateway is charged

A NAT Gateway has two charges:

  • An hourly charge for every hour it exists, whether or not traffic flows through it.
  • A data processing charge for every gigabyte that passes through it, in either direction.

The hourly charge is predictable. The processing charge is what grows: every gigabyte a private workload sends to the internet, to another AWS service’s public endpoint, or back from them, is processed by the gateway. Normal data transfer charges apply on top.

02 · Diagnosis

Find the traffic behind the cost

  1. Confirm it is processing, not hours. In Cost Explorer, group by usage type and look for NAT Gateway bytes versus NAT Gateway hours.
  2. Find the busiest gateway. The BytesOutToDestination and BytesInFromDestination CloudWatch metrics show traffic per gateway.
  3. Find the destinations. Turn on VPC Flow Logs for the gateway’s network interface and group by destination address. In most environments, a large share goes to Amazon S3, Amazon ECR or another AWS service.
03 · Fixes

The fixes, in the order to try them

1. Gateway endpoints for S3 and DynamoDB

Gateway VPC endpoints route traffic to Amazon S3 and Amazon DynamoDB privately, and AWS charges nothing for them: no hourly charge and no processing charge. If your workloads pull container layers, read files or write logs to S3 through a NAT Gateway, this is usually the biggest and cheapest win.

endpoints.tf
resource "aws_vpc_endpoint" "s3" {
  vpc_id            = aws_vpc.main.id
  service_name      = "com.amazonaws.ap-southeast-2.s3"
  vpc_endpoint_type = "Gateway"
  route_table_ids   = aws_route_table.private[*].id
}

2. Interface endpoints, where the numbers work

Other services, such as Amazon ECR, AWS Secrets Manager and Amazon CloudWatch Logs, need interface endpoints. These are not free: each is charged per hour in every Availability Zone it runs in, plus a per-gigabyte charge. They pay off for services with heavy, steady traffic, and cost more than they save for services you call occasionally. Do the sum per service before adding them.

3. Keep traffic in its Availability Zone

Run one NAT Gateway per Availability Zone and route each private subnet to the gateway in its own zone. Sending traffic to a gateway in another zone adds cross-zone data transfer charges, and makes that zone a single point of failure.

4. Question the traffic itself

Large, repeated downloads (the same container images, packages or datasets on every deploy) are often better cached, or pulled once into your own registry or bucket.

04 · Caution

What not to do

Don’t replace NAT Gateways with public IP addresses on workloads just to save money. It removes a layer of protection, and AWS charges for every public IPv4 address anyway. Keep workloads private, and reduce what they send through the gateway.

05 · Sources

Sources

See also Lower cloud costs and AWS data transfer costs, explained.

Next step

Want a second pair of eyes on your bill?

On a 30-minute call we’ll look at where your networking costs come from and which fixes apply.