# Azure Flow Log on a Gateway Subnet

> Flags flow logs on a GatewaySubnet when an unfiltered VNet flow log already records the same network, priced at their full cost.

Source: https://zop.dev/integrations/azure/recommendations/azure-flow-log-on-a-gateway-subnet

---

## Why gateway subnet logging is expensive and incomplete

Traffic that enters or leaves a network through its VPN or ExpressRoute gateway passes through the
`GatewaySubnet`, so a log there collects all of it, and flow logs are billed per GB collected.
It also has a documented blind spot. Microsoft's
[VNet flow logs overview](https://learn.microsoft.com/en-us/azure/network-watcher/vnet-flow-logs-overview)
states that outbound flows from VMs to an ExpressRoute circuit are not recorded when flow logging
is enabled on the ExpressRoute gateway subnet, and that with FastPath enabled traffic bypasses the
gateway and is not recorded there either. Those flows must be recorded at the VM's subnet or NIC.

The same `GatewaySubnet` name is used for VPN gateways, so the FastPath point applies only when the
gateway is ExpressRoute. The cost argument applies to both.

## Spotting gateway subnet logs

```bash
az network watcher flow-log list --location <region> \
  --query "[?contains(targetResourceId, 'GatewaySubnet')].{name:name, enabled:enabled, target:targetResourceId}" \
  -o table
```

For each result, strip the `/subnets/GatewaySubnet` suffix from the target to get the owning virtual
network, and check whether that network has its own enabled flow log.

## The redundancy test ZopNight applies

1. The flow log is enabled and its target is a gateway subnet.
2. The owning virtual network is derived from the subnet's resource ID.
3. Another enabled flow log targets that virtual network as a whole.
4. That covering log is proven to have no filtering criteria, since a filtered log records only
   matching flows and is not full coverage.
5. The gateway subnet log has a positive price.

## When it stays quiet

If no network-level log covers the network, there is no finding, even though the gateway subnet
log may still be poor value. Moving collection to the VM subnets is not automatically a saving:
you would pay to collect those same flows somewhere else, and the net change is unknown. Only proven
redundancy makes the whole figure defensible. NSG-level duplicates are handled by
<a href="https://zop.dev/integrations/azure/recommendations/azure-duplicate-flow-logging">Azure Duplicate Flow Logging</a>.

## What removing it recovers

```text
saving = full monthly cost of the gateway subnet flow log
cost after fix = 0
```

The network-level log keeps recording every subnet and interface in the network, gateway traffic
included, so no visibility is lost.

## Consolidating onto the network-level log

1. Confirm the covering VNet flow log is healthy and delivering data to its storage account.
2. If traffic analytics was enabled on the gateway subnet log, enable it on the network-level log.
3. Delete the gateway subnet log:
   `az network watcher flow-log delete --location <region> --name <flow-log>`.
4. If gateway traffic must be audited separately, capture it at the VM subnets or NICs rather than on
   the gateway subnet, as Microsoft advises for ExpressRoute.
