Skip to main content
rightsizing · aws

Load balancers with cross-zone load balancing enabled, priced on the inter-AZ transfer it causes

rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight checks the `load_balancing.cross_zone.enabled` attribute on each Elastic Load Balancing v2 load balancer and would price turning it off at the inter-AZ data transfer that load balancer generates. AWS billing has no per-load-balancer split of that transfer, so ZopNight raises no finding today rather than guess at a share of the bill.

Signal and threshold

How ZopNight evaluates Load balancers with cross-zone load balancing enabled, priced on the inter-AZ transfer it causes.
Field Value
Rule IDsRC-1509
Categoryrightsizing
Severitylow
Metricnone — pure configuration read
Thresholdload_balancing.cross_zone.enabled = true
SourceZopNight
Permissions usedelasticloadbalancing:DescribeLoadBalancers · elasticloadbalancing:DescribeLoadBalancerAttributes · elasticloadbalancing:DescribeTargetGroupAttributes

Cross-zone routing sends requests over Availability Zone boundaries

Each load balancer node sits in one Availability Zone. With cross-zone load balancing on, a node spreads traffic across the registered targets in every enabled zone; with it off, a node only uses targets in its own zone. AWS’s own example has two targets in zone A and eight in zone B: with cross-zone on, each target takes 10% of requests, and with it off the two targets in zone A take 25% each.

The defaults differ by type. Application Load Balancers always have cross-zone on at the load balancer level, though you can turn it off per target group. Network and Gateway Load Balancers start with it off. For Network Load Balancers, AWS states that EC2 data transfer charges apply when cross-zone load balancing is enabled, because traffic then crosses zones inside the Region.

Checking the setting on your load balancers

List load balancers, then read the attribute on each one and on its target groups. The target group value overrides the load balancer value:

Terminal window
aws elbv2 describe-load-balancers \
--query 'LoadBalancers[].[LoadBalancerName,Type,LoadBalancerArn]' --output table
aws elbv2 describe-load-balancer-attributes --load-balancer-arn LOAD_BALANCER_ARN \
--query "Attributes[?Key=='load_balancing.cross_zone.enabled']"
aws elbv2 describe-target-groups --load-balancer-arn LOAD_BALANCER_ARN \
--query 'TargetGroups[].TargetGroupArn'
aws elbv2 describe-target-group-attributes --target-group-arn TARGET_GROUP_ARN \
--query "Attributes[?Key=='load_balancing.cross_zone.enabled']"

The two things ZopNight needs before it would fire

  1. The load balancer’s cross-zone attribute reads true. If ZopNight could not read the attribute, it treats the setting as unknown and does nothing.
  2. A billed dollar amount for the inter-AZ data transfer that this specific load balancer causes.

Why no finding is raised today

The second input does not exist yet. AWS reports regional data transfer as a usage type for the whole account, and the load balancer’s processed-bytes figure counts all traffic, not the part that crossed a zone. Taking a percentage of the load balancer bill would be a guess, so the rule stays silent once it confirms cross-zone is on. ZopNight does not price cross-AZ transfer at the account level either; the DataTransfer-Regional-Bytes usage types in Cost Explorer show it directly.

What the saving will be once per-LB transfer cost exists

Terminal window
saving = billed inter-AZ data transfer attributable to this load balancer
cost after change = 0 for that line item

Turning cross-zone off removes the transfer it causes, so the whole line item is the saving. There is no fixed fraction involved.

Turning cross-zone off without starving a zone

  1. Confirm each enabled zone has enough healthy targets to carry its share alone. Uneven target counts are the main reason to keep cross-zone on.
  2. For a Network Load Balancer, set the load balancer attribute: aws elbv2 modify-load-balancer-attributes --load-balancer-arn LOAD_BALANCER_ARN --attributes Key=load_balancing.cross_zone.enabled,Value=false
  3. For an Application Load Balancer, change it on the target group instead with aws elbv2 modify-target-group-attributes and the same key.
  4. Watch target health and p95 latency per zone for a day before touching the next one.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·