Skip to main content

AI & assistant-friendly summary

This section provides structured content for AI assistants and search engines. You can cite or summarize it when referencing this page.

Summary

An idle NAT Gateway in us-east-1 costs $36.50/month before any traffic: $32.85 in hours plus $3.65 for the public IPv4. A Regional NAT Gateway across three AZs still bills three hours, $109.50 idle.

Key Facts

  • •An idle NAT Gateway in us-east-1 costs $36.50/month before any traffic: $32.85 in hours plus $3.65 for the public IPv4
  • •A Regional NAT Gateway across three AZs still bills three hours, $109.50 idle
  • •As of 9 October 2026, the AWS price list charges a NAT Gateway in us-east-1 $0.045 per hour and $0.045 per GB processed
  • •Add the public IPv4 at $0.005 per hour and an idle gateway is $36.50 per month before a single packet
  • •Three Availability Zones, whether you deploy three zonal gateways or one Regional NAT Gateway active in all three, are $109.50 idle

Entity Definitions

Lambda
Lambda is an AWS service discussed in this article.
EC2
EC2 is an AWS service discussed in this article.
S3
S3 is an AWS service discussed in this article.
DynamoDB
DynamoDB is an AWS service discussed in this article.
CloudWatch
CloudWatch is an AWS service discussed in this article.
VPC
VPC is an AWS service discussed in this article.
Amazon VPC
Amazon VPC is an AWS service discussed in this article.
SQS
SQS is an AWS service discussed in this article.

AWS NAT Gateway Billing: Why You Are Paying for Ghost Infrastructure

Quick summary: An idle NAT Gateway in us-east-1 costs $36.50/month before any traffic: $32.85 in hours plus $3.65 for the public IPv4. A Regional NAT Gateway across three AZs still bills three hours, $109.50 idle.

Key Takeaways

  • An idle NAT Gateway in us-east-1 costs $36.50/month before any traffic: $32.85 in hours plus $3.65 for the public IPv4
  • A Regional NAT Gateway across three AZs still bills three hours, $109.50 idle
  • As of 9 October 2026, the AWS price list charges a NAT Gateway in us-east-1 $0.045 per hour and $0.045 per GB processed
  • Add the public IPv4 at $0.005 per hour and an idle gateway is $36.50 per month before a single packet
  • Three Availability Zones, whether you deploy three zonal gateways or one Regional NAT Gateway active in all three, are $109.50 idle
AWS NAT Gateway Billing: Why You Are Paying for Ghost Infrastructure
Table of Contents

As of 9 October 2026, the AWS price list charges a NAT Gateway in us-east-1 $0.045 per hour and $0.045 per GB processed. Add the public IPv4 at $0.005 per hour and an idle gateway is $36.50 per month before a single packet. Three Availability Zones, whether you deploy three zonal gateways or one Regional NAT Gateway active in all three, are $109.50 idle.

A startup architect still deploys that three-AZ layout for high availability, then leaves it processing nothing. Compute Optimizer can find the unused ones. The bill math below is what to run before you add the next gateway. Price this VPC in the NAT Gateway calculator. Size a NAT instance with the EC2 pricing calculator before you swap the managed gateway for one.

The detection tooling is real and newer than the rate card. In November 2025, AWS Compute Optimizer launched unused NAT Gateway recommendations. In February 2026, Trusted Advisor picked up the same signals. June 2026: the free 32-day lookback catches gateways that only spike during a month-end batch. When Cost Explorer surfaces the line, Analyze with Amazon Q narrates the drivers (Cost Explorer guide).


The five-line NAT bill

AWS bills five charges. Hours and the public IPv4 accrue while the gateway exists. The other three follow the bytes. Figures below use a 730-hour month (8,760 hours a year ÷ 12). Each partial NAT Gateway-hour is billed as a full hour. Rates: Amazon VPC pricing.

Gateway hours. $0.045 per hour in us-east-1. One gateway is $0.045 × 730 = $32.85.

Public IPv4. $0.005 per hour for the address on the gateway, the same rate in every commercial region since February 2024. One address is $0.005 × 730 = $3.65.

Data processing. $0.045 per GB in us-east-1 for every gigabyte that passes through the gateway, in either direction. Return traffic from the internet is processed. General data transfer into AWS has no charge of its own. The NAT processing fee still applies to those bytes.

Cross-AZ transfer. $0.01 per GB in each direction when the workload and the gateway sit in different Availability Zones. That is $0.02 per GB of one-way payload. A NAT Gateway in the same AZ as the workload avoids this line.

Data transfer out. $0.09 per GB for the first 10 TB that leaves the VPC for the internet in us-east-1, on top of processing. AWS includes 100 GB per month of data transfer out to the internet, aggregated across services and regions except China and GovCloud. The tables below show the gross egress charge. That allowance can cover a small NAT egress line only when the rest of the account has not already used it.

At 10 GB processed and no cross-AZ traffic, fixed charges are about 99% of the NAT bill: $36.50 of the $36.95 total. The 10 GB of processing adds $0.45. Under about 50 GB a month, deleting an unused gateway beats tuning the per-GB rate.

us-east-1, hours + public IPv4 + processing. Egress is the extra column if that entire GB volume is outbound. Processing counts both directions, so a real bill’s outbound GB is smaller than processed GB.

Monthly GB processed1 AZ2 AZsGross egress if all of that GB leaves AWS
0$36.50$73.00$0
10$36.95$73.45$0.90
500$59.00$95.50$45.00
1,000$81.50$118.50$90.00

Worked 500 GB, one AZ, no cross-AZ: $32.85 hours + $3.65 IPv4 + (500 × $0.045) processing = $59.00. Two AZs double the hours and the addresses, not the processing, when the GB figure is the total through both gateways.

Three idle AZs are $109.50. That is three times $36.50, zonal or Regional.

Hourly and per-GB rates from the AWS price list published 9 October 2026. Public IPv4 is $0.005 per hour in each region. Idle month = (hourly × 730) + $3.65.

RegionPer hour and per GBIdle, 1 AZ
us-east-1 (N. Virginia)$0.045$36.50
eu-west-1 (Ireland)$0.048$38.69
eu-west-2 (London)$0.050$40.15
eu-central-1 (Frankfurt)$0.052$41.61

When the gateway exists for a partner allowlist

Lambda outside your VPC does not keep a stable outbound address, so a partner API that allowlists one IP pushes the function into a VPC with a NAT Gateway. At 10 GB a month that gateway still costs $36.50 in us-east-1 before processing. The address is the product. The hour is the tax.

For that low-volume HTTPS allowlist, a NAT instance or fck-nat on a t4g.nano is about $4 in instance hours, plus the same $3.65 public IPv4, plus the same internet egress, and no per-GB NAT processing fee. You patch the instance. There is no NAT Gateway SLA. Failover is a route-table update, often 30–60 seconds. Dev and test, and production teams who accept that window, are the fit. A whole VPC that moves hundreds of gigabytes to the internet still belongs on the managed gateway.

Reproduce this — NAT Gateway pricing calculator. Set the region, the gateway count (one per active AZ), processed GB, one-way cross-AZ GB, and outbound GB. Idle us-east-1, one gateway, zeros everywhere, is $36.50. Ten GB processed, no cross-AZ, no egress, is $36.95.


Why Idle NAT Gateways Accumulate

Idle NAT Gateways are not accidents—they are the result of predictable patterns in how infrastructure evolves:

Dev and test environments never cleaned up. A developer spins up a VPC with a NAT Gateway to test an application. The project gets shelved. The VPC is abandoned. The NAT Gateway remains, billing the account at $36.50/month in us-east-1 until someone audits the infrastructure.

Disaster recovery standby gateways. A 3-AZ production setup deploys with route tables pre-configured to fail over to a secondary NAT Gateway in a different AZ. That secondary gateway sits idle almost all the time, yet it costs $36.50/month to exist.

Orphaned VPC peering. An application originally required cross-region communication through a NAT Gateway for compliance reasons. The requirement changed, the traffic stopped, but the gateway was never deleted.

“Just in case” infrastructure. Architects deploying to a new region provision a full 3-AZ NAT Gateway setup with the standard architecture, then discover the application never needed it.

Each of these follows from reasonable decision-making at the time. The problem is that idle NAT Gateways generate no alarms, no alerts, and no visible cost signals. They silently bill each month, month after month, year after year.


AWS Compute Optimizer: Finding Idle NAT Gateways

In November 2025, AWS added the capability many wished for years earlier: automated detection of unused NAT Gateways.

How it works: AWS Compute Optimizer analyzes 32 days of CloudWatch metrics for each NAT Gateway. It flags a gateway as unused if it meets all three conditions:

  • Zero active connections over the 32-day period
  • Zero incoming packets from source (your resources)
  • Zero incoming packets from destination (remote systems)

The 32-day window is long enough to capture normal traffic patterns; gateways used only occasionally will not be flagged.

Smart enough to avoid false positives: Compute Optimizer checks route table associations. If a gateway is associated with a route table but not actively handling traffic, it avoids flagging failover-only standby gateways—those pre-configured to take traffic only during disaster recovery when an application swaps route tables dynamically.

How to use it:

  1. Open AWS Compute Optimizer in the AWS Console
  2. Navigate to NAT Gateways and opt in to recommendations
  3. Within 24 hours, recommendations appear with detailed cost savings estimates
  4. Cross-reference with AWS Cost Optimization Hub for a centralized view alongside other cost-reduction actions
  5. In February 2026, AWS enhanced Trusted Advisor with the same signals; activate Trusted Advisor checks to surface unused gateway recommendations

The catch: Compute Optimizer gives you detection and a recommendation to delete. It does not tell you whether deleting that gateway will break a failover process, a legacy application, or an undocumented dependency. Always verify before deleting.


Tier 1: Free Alternatives — VPC Endpoints

The best alternative is often free.

VPC Gateway Endpoints for S3 and DynamoDB eliminate the need for NAT Gateway for those specific services entirely. Instead of routing traffic through a NAT Gateway to the public AWS API, you configure a gateway endpoint, and traffic stays within the VPC and AWS network. Cost: $0.00.

This is the first optimization to make. If your application talks to S3 or DynamoDB from private subnets, configuring a gateway endpoint removes that traffic from the NAT Gateway entirely and eliminates NAT Gateway charges for that portion of your data transfer.

VPC Interface Endpoints (PrivateLink) extend the concept to nearly every AWS service: ECR, CloudWatch, Secrets Manager, SSM, SQS, SNS, and hundreds more. Instead of routing through NAT Gateway to a public API endpoint, traffic stays private within the VPC.

Cost: $0.01/hour per endpoint + $0.01/GB of data processed. For most services, this is significantly cheaper than NAT Gateway ($0.045/hr + $0.045/GB).

Real-world example: A team using Datadog logs from private subnets. All log traffic went through NAT Gateway at $0.045/GB processing + $0.09/GB egress = $0.135/GB. Switching to a Datadog VPC Interface Endpoint costs $0.01/GB. For 500GB/month: NAT Gateway cost $67.50, VPC endpoint cost $5.00. Savings: $62.50/month, $750/year, with zero application code changes.

Egress-Only Internet Gateway serves IPv6 traffic without requiring a NAT Gateway. Cost: $0.00, AWS-managed with 99.99% SLA. This is the future-forward option for applications moving to IPv6.


Tier 2: 90% Savings — fck-nat and NAT Instances

For workloads requiring general internet access (not just AWS service calls), fck-nat is the production-ready alternative that saves 90% on NAT infrastructure costs.

fck-nat is a modern, actively maintained open-source project that runs a NAT instance on a t4g.nano or t4g.micro EC2 instance. It handles IP masquerading and connection tracking, delivering NAT functionality without paying AWS’s managed NAT Gateway premium.

Cost breakdown:

  • t4g.nano base cost: ~$3.00/month
  • No per-GB data processing fee (unlike NAT Gateway at $0.045/GB)
  • Data egress still charged at $0.09/GB (same as any EC2-based egress)
  • Total for light traffic: about $4/month in instance hours, plus the same $3.65 public IPv4, versus $36.50 idle for a managed gateway in us-east-1

Trade-offs:

  • No AWS SLA (managed NAT Gateway has 99.99% availability)
  • Failover is manual—if the EC2 instance fails, you must update route tables to point to a secondary NAT instance (can take 30–60 seconds vs. AWS’s automatic failover)
  • You own the EC2 instance: patching, monitoring, troubleshooting

Best for: Dev/test environments, cost-sensitive production teams comfortable managing the EC2 instance, startups where the operational trade-off is worth the 90% savings.

The DIY NAT Instance: If fck-nat feels like adding a new dependency, the DIY approach is simpler than it sounds. Launch a t4g.nano EC2 instance with Amazon Linux, disable source/destination checking, and run iptables -t nat -A POSTROUTING -j MASQUERADE to enable IP masquerading. Cost is identical (~$3.81/month base), but you manage the configuration yourself.

Terraform modules are available for both fck-nat and DIY NAT instances if you want infrastructure-as-code setup.


Tier 3: Regional NAT Gateway

AWS offers a Regional NAT Gateway that expands and contracts with the Availability Zones your workloads use, and it simplifies route tables. The hourly charge stays one NAT Gateway-hour per Availability Zone the gateway is active in.

From the VPC pricing page: you are charged for each hour the NAT Gateway is configured in each Availability Zone. A regional gateway running in three AZs for one hour is three NAT Gateway-hours. In us-east-1 that is $0.045 × 3 = $0.135 per hour, $98.55 per month in hours, plus $3.65 per public IPv4. With one address per active AZ the idle total is $109.50, the same base as three zonal gateways. When the gateway drops an AZ, billing for that AZ stops.

Data processing and internet egress stay per GB. Cross-AZ transfer still applies when a workload and the gateway’s path are in different AZs.

Use it when you want the managed SLA and automatic AZ coverage, and you have priced one hour per AZ you will actually run. Keep fck-nat or a NAT instance when the traffic is a low-volume allowlist and you will own patching and failover.


Optimization Without Changing Gateway Type

If you keep NAT Gateways, minimize their cost with these patterns:

Same-AZ traffic routing: Route each subnet through a NAT Gateway in the same Availability Zone. Cross-AZ transfer is $0.01 per GB in each direction, so $0.02 per GB of one-way payload. One terabyte of one-way traffic from the other AZ is $20 per month. Same-AZ routing removes that line.

Audit traffic with VPC Flow Logs and CloudWatch Logs Insights. Identify which traffic actually needs NAT Gateway vs. which is calling AWS services that could use free VPC endpoints. Often 50%+ of NAT Gateway traffic can be redirected to VPC endpoints with zero code changes.

Transit Gateway centralization: For organizations with multiple VPCs, consolidating NAT Gateways via Transit Gateway reduces duplication and improves visibility.


Decision Framework: Which Alternative to Use

Use CaseApproachCostTrade-offs
S3/DynamoDB from private subnetVPC Gateway EndpointFreeNone—use this first
AWS service APIs (ECR, CloudWatch, SSM, etc.)VPC Interface Endpoint$7–15One endpoint per service
General internet, dev/test environmentfck-nat or NAT instance~$4No AWS SLA, manual failover
General internet, production, cost-sensitivefck-nat with hot standby~$8Failover: 30–60 sec window
General internet, production, SLA requiredNAT Gateway, one per active AZ$36.50 per AZ idle in us-east-1Regional NAT bills the same per active AZ
General internet, several regionsNAT per region you serve$36.50–$41.61 per AZ idleFrankfurt is the high end of this set


Start Here

If you have NAT Gateways, your action list is:

  1. Opt into AWS Compute Optimizer if you have not already (free)
  2. Review unused NAT Gateway recommendations — Compute Optimizer will find the obvious candidates
  3. Audit traffic with VPC Flow Logs — Identify which traffic could be redirected to VPC endpoints
  4. Implement VPC Gateway Endpoints for S3 and DynamoDB first — instant savings, zero code changes
  5. Implement VPC Interface Endpoints for other AWS services your application uses
  6. Re-count the gateways. One hour per active AZ, including a Regional NAT Gateway. If the only job is a partner allowlist at a few gigabytes, price fck-nat or a NAT instance against the $36.50 idle line.

Gateway Endpoints for S3 and DynamoDB remove that traffic at no charge. A NAT instance removes the NAT hourly and per-GB processing charges and leaves you with the instance, the public IPv4, and internet egress.

Price this VPC, then book a cost audit if the NAT line is still one of the top rows in Cost Explorer.

Frequently asked questions

How much does an idle NAT Gateway cost per month?
In us-east-1, as of 9 October 2026, one gateway is $32.85 in hours ($0.045 × 730) plus $3.65 for its public IPv4 ($0.005 × 730), so $36.50 with zero traffic. Three Availability Zones, zonal or Regional, are $109.50 before any bytes. Processing, cross-AZ transfer, and internet egress sit on top.
Does a Regional NAT Gateway cost less than one gateway per Availability Zone?
The hourly bill does not drop. AWS charges one NAT Gateway-hour for each Availability Zone a Regional NAT Gateway is active in. Three active AZs in us-east-1 is $0.135 per hour, the same hourly charge as three zonal gateways. What changes is route-table setup, and billing stops for an AZ when the gateway drops that AZ.
Does a NAT Gateway charge for traffic coming back from the internet?
Yes. Data processing applies to every gigabyte that passes through the gateway, in either direction. General data transfer into AWS from the internet has no charge. The NAT processing fee still applies to those return bytes.
What is the cheapest alternative to AWS NAT Gateway?
For S3 and DynamoDB traffic: VPC Gateway Endpoints (free). For other AWS service traffic: VPC Interface Endpoints ($0.01/hr + $0.01/GB). For a low-volume internet allowlist: fck-nat or a NAT instance, about $4 in instance hours plus the same $3.65 public IPv4, against $36.50 idle for a managed gateway in us-east-1. For dev/test: public subnets with strict security groups.
How does AWS Compute Optimizer find idle NAT Gateways?
It analyzes 32 days of CloudWatch metrics — checking for zero active connections, zero incoming packets from source, and zero incoming packets from destination. It also checks route table associations to avoid flagging failover-only standby gateways (used only during DR scenarios).
Is fck-nat safe to use in production?
fck-nat is actively maintained open-source software used in production by many teams. The trade-off vs managed NAT Gateway: no AWS SLA, failover requires route table updates (can take 30–60 seconds), and you manage the EC2 instance. For cost-sensitive teams comfortable with the operational trade-off, it saves 90%+ on NAT infrastructure costs.
Should I replace NAT Gateway with a NAT instance?
For dev/test, often yes. You trade the NAT hourly and per-GB processing charges for an EC2 instance you patch, and you still pay the public IPv4 and internet egress. For production, the question is whether a 30–60 second route-table failover is acceptable. A Regional NAT Gateway keeps the AWS SLA and still bills one hour per active Availability Zone. It does not cut a three-AZ design down to one hour.
Palaniappan P
Palaniappan P

AWS Cloud Architect & AI Expert

AWS-certified cloud architect and AI expert with deep expertise in cloud migrations, cost optimization, and generative AI on AWS.

AWS ArchitectureCloud MigrationGenAI on AWSCost OptimizationDevOps

Recommended Reading

Explore All Articles »
4 min

Post-Migration Optimization and the FinOps Handoff (2026): The First 30 Days After Cutover Decide Your Run-Rate

A lift-and-shift migration copies on-prem specs sized for peak plus headroom, then the migration partner rolls off and nobody owns the bill. The waste is predictable: 30–60% of cost untagged, over-provisioned EC2/RDS, idle NAT Gateways and orphaned EBS, and commitments bought on top of all of it. This is the explicit migration→FinOps handoff — owner first, visibility second, right-size before you commit — with a 30-day checklist and an optimization-backlog CSV.

7 min

Amazon VPC Pricing: The VPC Is Free — Everything Around It Bills

The VPC itself, subnets, security groups, and route tables are free. The bill comes from what you attach: public IPv4 at $3.60/month per address (since Feb 2024), Interface VPC Endpoints at $0.01/hour per AZ, Transit Gateway at $0.05/hour per attachment, VPN at $0.05/hour, and inter-AZ data transfer at $0.01/GB each way. A modest production VPC easily lands at $500–$2,000/month.