Guides · Networking
A NAT gateway bills twice: once for every hour it exists and once for every gigabyte it processes. In US East (N. Virginia), both are $0.045. The per-GB charge applies even when the traffic only goes to Amazon S3 in the same region. Traffic to S3 and DynamoDB can skip the NAT gateway through a gateway VPC endpoint, which has no charge.
| Charge | us-east-1 price | Example | Per month |
|---|---|---|---|
| NAT gateway hours | $0.045 / hour | One gateway, all month (730 hours) | $32.85 |
| One gateway in each of three Availability Zones | $98.55 | ||
| Data processed | $0.045 / GB | 1,000 GB through the gateway | $45.00 |
| 5,000 GB through the gateway | $225.00 |
AWS's own pricing example: an instance behind a NAT gateway sends 1 GB to an S3 bucket in the same region. There's no data transfer charge from EC2 to S3 in the same region, but the NAT gateway still charges $0.045 to process that 1 GB. AWS adds that a gateway VPC endpoint would avoid the processing charge, and that gateway endpoints have no hourly or data processing charges.
Gateway endpoints exist for two services: Amazon S3 and DynamoDB. When one is attached to a subnet's route table, traffic to that service in the same region goes through the endpoint instead of the NAT gateway.
Anything in a private subnet that reads or writes S3, such as backups or log shipping, sends that traffic through the NAT gateway unless an endpoint exists. Many other AWS services can be reached through interface endpoints instead. Those aren't free: they have their own hourly charge and $0.01 per GB processed in us-east-1. Check AWS PrivateLink pricing before assuming they save money.
1. How much are you paying? Billing and Cost Management → Cost Explorer. Set Group by to Usage type and look for usage types containing NatGateway-Hours and NatGateway-Bytes. In us-east-1 they have no prefix; in other regions they start with a region code. With the CLI (each Cost Explorer API request costs $0.01):
aws ce get-cost-and-usage --time-period Start=2026-09-01,End=2026-10-01 \
--granularity MONTHLY --metrics UnblendedCost UsageQuantity \
--group-by Type=DIMENSION,Key=USAGE_TYPE \
--query "ResultsByTime[].Groups[?contains(Keys[0], 'NatGateway')]"
2. Which gateways exist?
aws ec2 describe-nat-gateways --region us-east-1 \
--query 'NatGateways[?State==`available`].[NatGatewayId,VpcId,SubnetId]' --output table
3. Do those VPCs have S3 and DynamoDB gateway endpoints? VPC console → Endpoints, or:
aws ec2 describe-vpc-endpoints --region us-east-1 \
--query "VpcEndpoints[?VpcEndpointType=='Gateway'].[VpcId,ServiceName,State]" --output table
Any VPC with a NAT gateway but no com.amazonaws.<region>.s3 gateway endpoint is sending its S3 traffic through the NAT.
4. How much traffic goes through each gateway? In CloudWatch, the AWS/NATGateway namespace has per-gateway byte counts such as BytesOutToDestination and BytesInFromDestination:
aws cloudwatch get-metric-statistics --region us-east-1 --namespace AWS/NATGateway \
--metric-name BytesOutToDestination --dimensions Name=NatGatewayId,Value=nat-0123456789abcdef0 \
--start-time 2026-09-19T00:00:00Z --end-time 2026-10-03T00:00:00Z \
--period 86400 --statistics Sum
5. Where is it going? Metrics don't show destinations. For that, turn on VPC Flow Logs for a few days and group the records by destination address. Flow logs are billed as vended logs (data ingestion and storage), so switch them off once you have your answer.
The free checkup finds this and 20 other kinds of issues automatically. It reads last month's NAT gateway hours and data processing from Cost Explorer. It lists every VPC with a NAT gateway but no S3 or DynamoDB gateway endpoint. It can't see your traffic's destinations, so it estimates the saving as 30% of your NAT data processing cost and marks the estimate low-confidence. Flow logs give the real share.
NatGateway-Hours $0.045/hour, NatGateway-Bytes $0.045/GB.Prices are AWS on-demand list prices for US East (N. Virginia), checked October 3, 2026. Other regions differ.