Site-to-Site VPN connections with no tunnel up and no data for 30 days
What does ZopNight detect here?
ZopNight flags an available AWS Site-to-Site VPN connection when `TunnelState` never rose above 0 in 30 days and the combined peak of `TunnelDataIn` and `TunnelDataOut` stayed at or below 1 MiB. AWS bills each VPN connection-hour while the connection is provisioned, so the saving is the connection's full hourly fee.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-162 |
| Category | idle |
| Severity | medium |
| Metric | TunnelState, TunnelDataIn, TunnelDataOut |
| Threshold | TunnelState peak 0; data peak at most 1 MiB |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | ec2:DescribeVpnConnections · cloudwatch:GetMetricStatistics |
Where it applies
A VPN bills while provisioned, not while connected
AWS Site-to-Site VPN pricing charges for each VPN connection-hour that the connection is provisioned and available, with partial hours billed as full hours. Data transfer is charged on top. The page’s example for US East (Ohio) is $0.05 an hour, or $36.00 a month in connection fees. Whether the tunnels are up does not change that fee.
Connections to closed offices, retired colocation sites or a partner network that moved to PrivateLink tend to stay in place because nobody is sure what else depends on them.
Checking tunnel status and traffic
describe-vpn-connections shows the current status of each tunnel in VgwTelemetry, and
CloudWatch holds the history. The
VPN metrics page
defines TunnelState as 1 for up (or BGP established) and 0 otherwise, with values between 0 and 1
meaning at least one tunnel is not up:
aws ec2 describe-vpn-connections \ --query 'VpnConnections[].[VpnConnectionId,State,VgwTelemetry[].[OutsideIpAddress,Status,LastStatusChange]]'
aws cloudwatch get-metric-statistics \ --namespace AWS/VPN --metric-name TunnelState \ --dimensions Name=VpnId,Value=vpn-0123456789abcdef0 \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics MaximumThe gate: never up, practically no bytes
The connection must be in the available state. All three metrics, TunnelState, TunnelDataIn
and TunnelDataOut, must be present with 30 days of coverage. The peak TunnelState over the
window must be 0, meaning no tunnel came up at any point. The combined peak of the two data metrics
must be at or below 1 MiB; that small allowance covers keep-alive and dead-peer-detection traffic,
and it is a per-sample peak, not a monthly total.
When ZopNight stays quiet
A connection in any state other than available is outside this check. If any of the three metrics
is missing or covers less than 30 days, nothing is raised; ZopNight does not fall back on the
point-in-time tunnel status, because one snapshot says nothing about a month. Any tunnel up at any
point in the window ends it, as does an unpriced connection.
The connection fee is the saving
saving = VPN connection-hour rate x hours per monthcost after fix = 0Deleting a dead connection
- Confirm in CloudWatch that no tunnel has been up in 30 days or more.
- Check with the network team that the customer gateway site is really gone.
- Delete it with
aws ec2 delete-vpn-connection --vpn-connection-id vpn-0123456789abcdef0. - If the virtual private gateway has no other connections, detach it with
aws ec2 detach-vpn-gatewayand delete it withaws ec2 delete-vpn-gateway.