The network your resources live in · Chapter 3 of 3
How NAT and endpoints connect private networks
Keeping database instances private keeps them secure, but routing their traffic through NAT gateways or free endpoints determines whether your design is cost-effective.
FoundationsBuilds the idea from nothing. No prior AWS assumed.
Outbound routing using NAT Gateways
How do you allow private instances to reach the internet without exposing them to inbound connections?
App instances in private subnets require internet access but must remain secure from external attack.
- 01
The directionality of NAT
A Network Address Translation Gateway allows resources in private subnets to send outbound requests to the internet. However, it blocks any inbound connections from initiating a session with those resources. The NAT Gateway must be launched in a public subnet to function.
- 02
The expensive route
NAT Gateways charge by the hour and also for every gigabyte of data that passes through them. If an application downloads large datasets from an S3 bucket in the same Region through a NAT Gateway, you will pay high data transfer fees for traffic that never left the AWS network.
- 03
Bypassing the gateway
To avoid NAT charges, you can provision a Gateway Endpoint. Gateway Endpoints are free resources that route traffic directly to S3 and DynamoDB inside the AWS backbone network. This traffic bypasses the internet path entirely, reducing both costs and latency.
Check yourself
Why must a NAT Gateway be launched into a public subnet rather than a private subnet?
Under the hoodThe same thing from underneath: limits, failure modes, numbers.
The costs and performance ceilings of network routing
What are the performance limits and costs associated with NAT Gateways and VPC Endpoints?
App instances in private subnets require internet access but must remain secure from external attack.
- 01
NAT Gateway billing components
NAT Gateway pricing consists of an hourly running cost plus a data processing fee per gigabyte. This double charging mechanism means a NAT Gateway that sits idle in three Availability Zones will still cost over one hundred dollars per month without transferring any data.
- 02
Gateway endpoints are free route table entries
Gateway Endpoints do not have hourly fees or processing charges. They work by modifying the subnet route table to direct S3 or DynamoDB prefix lists to the endpoint. Interface Endpoints, which support other AWS services, are different: they use private IPs and charge an hourly fee.
- 03
NAT Gateway bandwidth limits
A NAT Gateway scales automatically to support high volumes of concurrent traffic. However, it has a set bandwidth limit per gateway. If your workload exceeds this limit, traffic is throttled, and you must split your subnets across multiple gateways to scale.
The numbers
- NAT Gateway hourly price
- $0.045 per hourApplies to each NAT Gateway provisioned in the VPC.
- NAT Gateway processing fee
- $0.045 per GBCharged for all data sent or received through the gateway.
- Gateway Endpoint cost
- FreeNo hourly fee or data charges for S3 and DynamoDB traffic.
- Interface Endpoint hourly price
- $0.01 per hourPlus data processing fees, unlike Gateway Endpoints.
- NAT Gateway bandwidth ceiling
- 100 GbpsScales automatically up to this limit before requiring multiple gateways.
Check yourself
Which of the following endpoint types charges no hourly fees or data processing fees for routing traffic to Amazon S3?
Official references & further reading
These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.
Report an error or suggest a clearer explanation →