Azure NAT gateways that processed almost no traffic for 30 days
What does ZopNight detect here?
Azure NAT Gateway bills an hourly resource charge whether or not any subnet or public IP is attached. ZopNight flags a gateway when its `ByteCount` metric stays below 1,024 bytes on both average and peak across 30 days, and reports the full priced gateway cost as the saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1383 |
| Category | idle |
| Severity | medium |
| Metric | ByteCount |
| Threshold | average and peak below 1,024 bytes |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.Insights/Metrics/Read |
Where it applies
The hourly charge that outlives the workload
NAT Gateway has two meters: resource hours and data processed. The NAT Gateway pricing FAQ answers the key question plainly: the hourly rate is charged regardless of the NAT gateway having subnets or public IPs attached, and a partial hour is billed as a full hour. So a gateway left behind after its virtual machines were retired keeps billing every hour, with nothing flowing through it.
Finding quiet gateways with the CLI
List the gateways and how many subnets each one still serves:
az network nat gateway list \ --query "[].{name:name, group:resourceGroup, subnets:subnets[].id}" -o jsonThen read the traffic it actually processed over the last month. ByteCount is the total bytes
transmitted in each interval:
az monitor metrics list \ --resource /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/natGateways/<gateway> \ --metric ByteCount --aggregation Average Maximum --interval PT1H --offset 30dFour checks, in order
- The gateway’s provisioning state is healthy. A gateway that is updating, failed or being deleted is skipped, so no delete advice lands on a resource mid-change.
- A
ByteCountseries exists for the gateway. If the metric is missing, perhaps because of a permission gap, there is no finding rather than a guess. - Both the average and the maximum over the 30-day window are below 1,024 bytes. One real burst of traffic in the month counts as use and keeps the gateway off the list.
- The gateway has a positive monthly price.
Traffic that clears a gateway
Because the peak must also stay under 1 KB, a gateway that handles a nightly batch download or a weekly patch run is not reported, even if it is quiet the rest of the time. The rule does not look at which subnets reference the gateway, so a gateway attached to subnets whose machines never call out is reported just like an unattached one; both cost the same.
What deleting it saves
saving = full monthly cost of the NAT gatewaycost after fix = 0The public IP addresses attached to the gateway bill separately. If they are no longer needed, releasing them is covered by Azure Public IP Not Associated.
Removing an unused NAT gateway
- Check each subnet still associated with the gateway. Removing the gateway changes how those subnets reach the internet, so confirm nothing relies on its outbound IPs (partner allowlists are the usual dependency).
- Detach it from every subnet:
az network vnet subnet update --resource-group <rg> --vnet-name <vnet> --name <subnet> --remove natGateway. - Delete the gateway with
az network nat gateway delete --resource-group <rg> --name <gateway>. - Release the public IPs or prefixes it used if nothing else needs them.