AWS NAT Gateway pricing: why an idle gateway still costs $32.85 a month
An AWS NAT gateway bills $0.045 an hour even when idle, plus $0.045 per GB it processes. What it costs in us-east-1, and how to cut it.

Key takeaways
- A NAT gateway costs $0.045 an hour in us-east-1 while it exists: $32.85 a month, even if nothing uses it.
- Every GB it processes adds $0.045, whatever the destination, on top of normal data transfer charges.
- Traffic to S3 and DynamoDB doesn’t need the NAT gateway. Gateway endpoints for both are free.
- Before deleting one, check that no route table points to it and that it had zero active connections.
On this page
A NAT gateway is how servers in a private subnet reach the internet. It’s also one of the easiest lines on an AWS bill to overpay, because it charges for existing and for every byte that passes through it, whether that traffic needed it or not.
01How is an AWS NAT gateway billed?
Two charges, both $0.045 in us-east-1: one per hour the gateway is available, and one per GB of data it processes. AWS applies the data charge regardless of where the traffic is going, and normal data transfer charges still apply on top.
| Setup | How it adds up | Per month |
|---|---|---|
| Idle, no traffic | 730 h × $0.045 | $32.85 |
| 1,000 GB processed | $32.85 + 1,000 GB × $0.045 | $77.85 |
| One per AZ, 3 AZs, idle | 3 × $32.85 | $98.55 |
02Why does an idle NAT gateway still cost money?
The hourly charge isn’t for traffic, it’s for the gateway being there. A test VPC nobody tore down, a staging environment that moved, a template that creates one gateway per Availability Zone by default: each keeps billing $32.85 a month with nothing going through it.
03Why does S3 traffic through a NAT gateway cost extra?
Without an endpoint, a private server reaches S3 and DynamoDB through the NAT gateway, so every GB pays the $0.045 processing charge. Pull 2,000 GB a month from S3, for backups, data jobs or container images, and that’s $90.00 a month in NAT processing alone.
A gateway endpoint for S3 or DynamoDB sends that traffic straight to the service instead. AWS’s own documentation says there is no additional charge for gateway endpoints, so the same 2,000 GB costs $0.00 in NAT processing.
04When is an interface endpoint cheaper than the NAT gateway?
Most other AWS services, ECR and CloudWatch among them, use interface endpoints instead, and those aren’t free: $0.01 an hour in each Availability Zone you put them in ($7.30 a month per AZ), plus $0.01 per GB. That’s $0.035 per GB less than the NAT gateway, so one interface endpoint in one AZ pays for itself above about 209 GB a month of traffic to that service. Below that, the NAT gateway is cheaper.
05Does it matter which Availability Zone the NAT gateway is in?
Yes. A server in one AZ that uses a NAT gateway in another AZ also pays regional data transfer, $0.01 per GB, on top of NAT processing. AWS’s advice for heavy cross-AZ traffic is to keep resources in the same AZ as their NAT gateway, or to run one gateway per AZ. That only pays off when there’s real traffic: three idle gateways cost $98.55 a month.
06How do you check your own NAT gateways?
In the console: VPC → NAT gateways, open each one and look at its Monitoring tab. An ActiveConnectionCount of zero for a week and almost no BytesOutToDestination means nothing is using it. Or with the AWS CLI:
# NAT gateways that exist (and bill)
aws ec2 describe-nat-gateways --filter Name=state,Values=available
# Peak connections per day for one gateway over a week
aws cloudwatch get-metric-statistics --namespace AWS/NATGateway \
--metric-name ActiveConnectionCount \
--dimensions Name=NatGatewayId,Value=nat-0123456789abcdef0 \
--start-time 2026-09-29T00:00:00Z --end-time 2026-10-06T00:00:00Z \
--period 86400 --statistics Maximum
# Route tables that still send traffic to it
aws ec2 describe-route-tables --filters Name=route.nat-gateway-id,Values=nat-0123456789abcdef0
# Gateway endpoints already in place (look for S3 and DynamoDB)
aws ec2 describe-vpc-endpoints --filters Name=vpc-endpoint-type,Values=GatewayZero connections for a week, and no route table pointing at it? It’s a strong candidate to delete. If a route does still point at it, update that route first: after the gateway is deleted, the route turns into a blackhole and drops the traffic. Deleting the gateway also doesn’t release its Elastic IP, which keeps billing $3.65 a month until you release it. Run these per region: each command only looks at the region your CLI is set to.
Frequently asked questions
How much does an AWS NAT gateway cost per month?
In us-east-1, $0.045 per hour, which is $32.85 for a 730-hour month, plus $0.045 for every GB of data it processes.
Does a NAT gateway cost money if nothing uses it?
Yes. The hourly charge runs for every hour the gateway is provisioned and available, whether or not any traffic goes through it.
How do I stop paying NAT charges for S3 traffic?
Add a gateway VPC endpoint for S3 and associate it with the private subnets’ route tables. AWS makes no additional charge for gateway endpoints, and S3 traffic then skips the NAT gateway.
Does deleting a NAT gateway release its Elastic IP?
No. The Elastic IP is disassociated but stays allocated to your account, and AWS charges $0.005 an hour for every public IPv4 address, in use or idle. Release it if you no longer need it.
Sources
- AWS Price List API, us-east-1: NAT gateway hours and data processed, VPC endpoint hours and data processed, regional data transfer, public IPv4
- Amazon VPC pricing page: NAT gateway billing
- AWS PrivateLink user guide: gateway endpoints pricing
- AWS PrivateLink pricing page: interface endpoint billing per Availability Zone

