Updated October 3, 2026

Guides · Networking

Why your NAT Gateway bill is so high, and how to cut it

A NAT gateway bills twice: once for every hour it exists and once for every gigabyte it processes. In US East (N. Virginia), both are $0.045. The per-GB charge applies even when the traffic only goes to Amazon S3 in the same region. Traffic to S3 and DynamoDB can skip the NAT gateway through a gateway VPC endpoint, which has no charge.

The two charges

Chargeus-east-1 priceExamplePer month
NAT gateway hours$0.045 / hourOne gateway, all month (730 hours)$32.85
One gateway in each of three Availability Zones$98.55
Data processed$0.045 / GB1,000 GB through the gateway$45.00
5,000 GB through the gateway$225.00

AWS's own pricing example: an instance behind a NAT gateway sends 1 GB to an S3 bucket in the same region. There's no data transfer charge from EC2 to S3 in the same region, but the NAT gateway still charges $0.045 to process that 1 GB. AWS adds that a gateway VPC endpoint would avoid the processing charge, and that gateway endpoints have no hourly or data processing charges.

What a gateway endpoint saves

Gateway endpoints exist for two services: Amazon S3 and DynamoDB. When one is attached to a subnet's route table, traffic to that service in the same region goes through the endpoint instead of the NAT gateway.

Anything in a private subnet that reads or writes S3, such as backups or log shipping, sends that traffic through the NAT gateway unless an endpoint exists. Many other AWS services can be reached through interface endpoints instead. Those aren't free: they have their own hourly charge and $0.01 per GB processed in us-east-1. Check AWS PrivateLink pricing before assuming they save money.

Check it yourself

1. How much are you paying? Billing and Cost Management → Cost Explorer. Set Group by to Usage type and look for usage types containing NatGateway-Hours and NatGateway-Bytes. In us-east-1 they have no prefix; in other regions they start with a region code. With the CLI (each Cost Explorer API request costs $0.01):

aws ce get-cost-and-usage --time-period Start=2026-09-01,End=2026-10-01 \
  --granularity MONTHLY --metrics UnblendedCost UsageQuantity \
  --group-by Type=DIMENSION,Key=USAGE_TYPE \
  --query "ResultsByTime[].Groups[?contains(Keys[0], 'NatGateway')]"

2. Which gateways exist?

aws ec2 describe-nat-gateways --region us-east-1 \
  --query 'NatGateways[?State==`available`].[NatGatewayId,VpcId,SubnetId]' --output table

3. Do those VPCs have S3 and DynamoDB gateway endpoints? VPC console → Endpoints, or:

aws ec2 describe-vpc-endpoints --region us-east-1 \
  --query "VpcEndpoints[?VpcEndpointType=='Gateway'].[VpcId,ServiceName,State]" --output table

Any VPC with a NAT gateway but no com.amazonaws.<region>.s3 gateway endpoint is sending its S3 traffic through the NAT.

4. How much traffic goes through each gateway? In CloudWatch, the AWS/NATGateway namespace has per-gateway byte counts such as BytesOutToDestination and BytesInFromDestination:

aws cloudwatch get-metric-statistics --region us-east-1 --namespace AWS/NATGateway \
  --metric-name BytesOutToDestination --dimensions Name=NatGatewayId,Value=nat-0123456789abcdef0 \
  --start-time 2026-09-19T00:00:00Z --end-time 2026-10-03T00:00:00Z \
  --period 86400 --statistics Sum

5. Where is it going? Metrics don't show destinations. For that, turn on VPC Flow Logs for a few days and group the records by destination address. Flow logs are billed as vended logs (data ingestion and storage), so switch them off once you have your answer.

How to fix it

  1. Create a gateway endpoint for S3, and for DynamoDB if you use it, in each VPC with a NAT gateway. VPC console → Endpoints → Create endpoint. Select the private subnets' route tables. AWS adds the routes automatically.
  2. Endpoints only cover the service in the same region. Traffic to a bucket in another region still goes through the NAT gateway.
  3. Check that security groups and network ACLs allow outbound traffic to the service. Security groups can reference the service's prefix list; network ACLs need its address ranges.
  4. If traffic often crosses Availability Zones to reach a NAT gateway, AWS suggests keeping resources in the same zone as their gateway, or running a gateway in each zone. Each extra gateway adds $32.85 a month in hourly charges, so weigh that against the traffic it saves.

The free checkup finds this and 20 other kinds of issues automatically. It reads last month's NAT gateway hours and data processing from Cost Explorer. It lists every VPC with a NAT gateway but no S3 or DynamoDB gateway endpoint. It can't see your traffic's destinations, so it estimates the saving as 30% of your NAT data processing cost and marks the estimate low-confidence. Flow logs give the real share.

Run a free checkup

Sources

Prices are AWS on-demand list prices for US East (N. Virginia), checked October 3, 2026. Other regions differ.