Skip to main content
resource · aws

NAT Gateway

live rule families
1
schedulable
no
category
networking-services

Does ZopNight manage NAT Gateway?

A NAT gateway bills 2 meters: a fixed hourly charge from the moment it exists and a per-GB charge on every byte it processes. ZopNight tracks 90 days of NATGateway namespace metrics and flags gateways passing no traffic, plus S3 or DynamoDB traffic that a free gateway endpoint could carry.

Rules that fire on NAT Gateway

At a glance

NAT Gateway coverage facts.
Field Value
Scheduling notesdiscovery, metrics, cost tracking, and recommendations only.

A NAT gateway lets private-subnet resources reach the internet, billed per hour plus per GB processed. NAT gateways are one of the most commonly overlooked network charges: each one costs money every hour, even when nothing flows through it.

An existence fee plus a traffic fee

The hourly charge accrues from creation until deletion, independent of traffic. The per-GB data processing charge applies to every byte in either direction, and it stacks on top of whatever ordinary data transfer charges the traffic already incurs. Multi-AZ architectures multiply the fixed part: one gateway per availability zone means three gateways in a standard 3-AZ template, each with its own hourly meter.

The two expensive mistakes

First, the idle gateway, usually a per-AZ gateway in a development VPC where nothing routes through two of the three. Its full cost is recoverable, because an unused gateway has no partial value. Second, routing S3 or DynamoDB traffic through NAT: both services accept gateway VPC endpoints, which cost nothing per hour and nothing per GB, making every gigabyte of S3 backup traffic that crosses a NAT gateway a pure surcharge.

What ZopNight measures

Gateways are discovered on the 6-hour cycle, with hourly CloudWatch metrics from the NATGateway namespace (the four byte-direction counters plus active connections) kept over a 90-day lookback. Per-gateway cost comes from Cost Explorer or CUR 2.0, and recommendations flag idle gateways and endpoint-eligible traffic. A NAT gateway cannot be stopped, so remediation means deleting it or rerouting the traffic, after checking the route tables that point at it, because removing a gateway with a live route blackholes the subnet’s outbound path.

Verifying a gateway is earning its fee

VPC console, then NAT gateways. Cross-check a gateway’s Monitoring tab against the hourly fee you know it charges. Byte charts flat at zero mean the fee is buying nothing, and the attached Elastic IP will keep billing on its own after deletion unless it is also released.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·