The packet path
A typical public NAT gateway setup contains four pieces:- A workload runs in a private subnet.
- The private subnet route table sends
0.0.0.0/0to a NAT gateway. - The NAT gateway sits in a public subnet and has an Elastic IP address.
- The public subnet sends internet traffic to an internet gateway attached to the VPC.
A NAT gateway does not replace security groups. Security groups still decide which outbound and return traffic a resource can use.
Availability Zone design
A NAT gateway is created in one subnet and therefore in one Availability Zone. AWS manages its capacity and resilience within that zone, but your route design still matters. A common highly available design creates one NAT gateway per Availability Zone and routes each private subnet to the gateway in the same zone. This avoids making workloads in one zone depend on a gateway in another zone. A cheaper design may share one NAT gateway across zones. That reduces hourly gateway charges, but it creates a cross-zone dependency and can add regional data-transfer charges. If the gateway’s Availability Zone has a problem, private workloads in other zones may also lose that egress path.Why NAT gateways become expensive
A NAT gateway has an hourly charge and a per-gigabyte data-processing charge. The surrounding path can add more charges, including cross-Availability Zone transfer and internet data transfer. Traffic volume often matters more than the number of workloads. Container image pulls, operating-system updates, large third-party API responses, and repeated artifact downloads can all pass through the gateway.Reduce unnecessary NAT traffic
You do not need to send every AWS service call through a NAT gateway.- Use gateway VPC endpoints for S3 and DynamoDB when appropriate.
- Use interface VPC endpoints for supported AWS services when their fixed hourly and data costs beat the NAT path.
- Keep large artifacts in the same region where possible.
- Cache package and image downloads when the operational complexity is justified.
- Check whether a workload actually needs a private subnet. A public IP with strict security groups can be a valid design for some stateless services.
NAT gateway, NAT instance, or no NAT
A NAT instance gives you more control and may cost less at small scale, but you own patching, scaling, failover, and throughput. A managed NAT gateway removes most of that operational work. Some architectures need no general internet egress. Workloads can use VPC endpoints, private APIs, and controlled proxies instead. This can improve security, but it also increases the number of dependencies you must configure. The right choice follows the workload:- Prefer a NAT gateway when reliable managed egress is worth the price.
- Consider a NAT instance when traffic is small and you can operate it safely.
- Prefer endpoints when traffic stays on supported AWS services and the cost model fits.
- Remove general egress when the workload does not need it.
Frequently asked questions
Does an AWS NAT gateway allow inbound traffic?
Does an AWS NAT gateway allow inbound traffic?
A public NAT gateway allows private resources to start outbound IPv4 connections and receive return traffic for those flows. It does not let an internet host initiate a new connection to a private workload. Use a load balancer or another explicit ingress path for inbound traffic.
Do I need one NAT gateway per Availability Zone?
Do I need one NAT gateway per Availability Zone?
One NAT gateway per Availability Zone avoids cross-zone dependency and keeps each private subnet’s egress local to its zone. A shared gateway costs less at low traffic but can add cross-zone charges and expands the impact of a zonal failure.
How can I reduce AWS NAT gateway costs?
How can I reduce AWS NAT gateway costs?
Reduce NAT gateway cost by keeping traffic in-zone, using appropriate S3 or DynamoDB gateway endpoints, evaluating interface endpoints for high-volume AWS API traffic, removing unnecessary downloads, and measuring processed bytes. Compare endpoint hourly charges with the complete NAT path before changing architecture.