NAT gateways with zero connections and zero bytes in every direction for 30 days
What does ZopNight detect here?
ZopNight flags `available` NAT gateways whose `ActiveConnectionCount` and all four byte counters, `BytesInFromSource`, `BytesOutToDestination`, `BytesInFromDestination` and `BytesOutToSource`, are zero for 30 days. A NAT gateway is charged for every hour it is provisioned, $0.045 an hour in US East (Ohio), so deleting it recovers the full monthly cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-011 |
| Category | idle |
| Severity | medium |
| Metric | ActiveConnectionCount |
| Threshold | zero connections and bytes |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | ec2:DescribeNatGateways · ec2:DescribeRouteTables · cloudwatch:GetMetricStatistics |
Where it applies
The hourly NAT charge runs from creation to deletion
VPC pricing charges for each NAT gateway-hour that a gateway is provisioned and available, with each partial hour billed as a full hour, plus a per-gigabyte processing charge. AWS’s worked example for US East (Ohio) uses $0.045 an hour, which “will always apply once the NAT gateway is provisioned and available”. Over a 730-hour month that is about $32.85 before a single byte is processed.
NAT gateways are easy to orphan: a VPC template creates one per Availability Zone, the workloads move, and the gateways stay.
Checking whether any traffic passes through
The NAT gateway metrics
cover both TCP connections and bytes in each direction; AWS notes that an ActiveConnectionCount
of zero means there are no active connections through the gateway.
aws ec2 describe-nat-gateways --filter Name=state,Values=available \ --query 'NatGateways[].[NatGatewayId,VpcId,SubnetId]'
aws cloudwatch get-metric-statistics --namespace AWS/NATGateway --metric-name BytesOutToDestination \ --dimensions Name=NatGatewayId,Value=nat-0123456789abcdef0 \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics Sum
aws ec2 describe-route-tables --filters Name=route.nat-gateway-id,Values=nat-0123456789abcdef0Five counters, all at zero
The gateway must be available, and all five metrics must be present and zero on both average and
maximum over 30 days: ActiveConnectionCount for TCP, plus the two request-path byte counters and
the two return-path byte counters. The byte counters catch UDP and ICMP traffic that a TCP
connection count would miss, and the return path catches a gateway still relaying responses.
Why a gateway might not be flagged
If any one of the five metrics is missing, ZopNight does not guess; an incomplete picture never produces a delete recommendation. Any non-zero value at any point clears the gateway. A gateway that carries a lot of traffic to S3 or DynamoDB is a different story, covered by NAT Gateway Processing S3 Traffic.
Pricing the deletion
saving = full monthly cost of the NAT gatewaycost after deletion = 0Deleting an idle NAT gateway
- Find route tables that still send
0.0.0.0/0to it, using the route table filter above. - Confirm no private subnet still needs outbound internet access, or replace that access with VPC endpoints.
- Delete it:
aws ec2 delete-nat-gateway --nat-gateway-id nat-0123456789abcdef0 - Remove the dead routes, then release the Elastic IP:
aws ec2 release-address --allocation-id eipalloc-0123456789abcdef0