AWS NAT Gateway pricing starts before your first request. You deploy a Lambda function that calls a partner API, and the partner asks for a fixed IP to add to its allowlist. So you put the function in a VPC with a NAT gateway in Frankfurt. With zero traffic, that gateway and its IP already charge you monthly.
The bill grows from there. AWS charges for every GB the gateway processes in both directions, every public IPv4 address, traffic between Availability Zones, and data sent out to the internet. Add a second gateway for high availability, and the fixed monthly cost doubles.
This article breaks down each charge with exact rates for European regions and us-east-1. It also compares the totals with OutboundGateway and gives you a free calculator to run your own numbers.
Key Takeaways
- A NAT gateway bill has five parts: gateway hours, a public IPv4 address, data processing, cross-AZ transfer, and data transfer out to the internet.
- AWS charges the data processing fee on every GB that passes through the gateway, in both directions.
- Switching to a static IP proxy removes the NAT gateway charges, but data transfer out stays on your AWS bill.
- If a static IP is the only reason you run a NAT gateway, OutboundGateway's €19 Starter plan costs less than any NAT setup at 10 GB a month.
Table of Contents
- How AWS NAT Gateway pricing works
- AWS NAT Gateway pricing by region
- NAT Gateway cost calculations by traffic volume
- The full monthly bill: NAT gateway, IP, and traffic together
- When you only need a NAT gateway for a static IP
- AWS NAT Gateway vs OutboundGateway: the cost comparison
- Free AWS NAT Gateway cost calculator
- A cheaper alternative to NAT gateways
- Frequently asked questions
How AWS NAT Gateway pricing works
AWS Network Address Translation (NAT) Gateway billing has five components: an hourly charge, a per-gigabyte (GB) data processing charge, a public IPv4 address charge, cross-Availability Zone (AZ) transfer when workloads sit in another AZ, and standard data transfer out to the internet.
The hourly and per-GB processing rates vary by region ($0.045 in us-east-1, $0.052 in Frankfurt). Public IPv4 is the same in all commercial regions. Cross-AZ and data transfer out rates vary by region and volume tier. Here’s an overview of Amazon VPC (Virtual Private Cloud) pricing as retrieved from the official Amazon VPC pricing page as of October 6, 2026:
| Charge | Rate | Unit | The trap |
|---|---|---|---|
| Hourly charge | $0.045 (us-east-1), $0.052 (Frankfurt) | per gateway, per hour | One gateway per AZ for full resilience; AWS bills each gateway for every full hour, or partial hour even with zero traffic. |
| Data processing | Varies by region ($0.045/GB in us-east-1, $0.052/GB in Frankfurt). | per GB | AWS charges for all traffic the NAT Gateway processes, in both directions (outbound and return) |
| Public IPv4 | $0.005/hour | per IP, per hour ($3.65/month) | This applies to every public IPv4 address in use, including those attached to NAT Gateways |
| Cross-AZ transfer | $0.01/GB (varies by region and direction) | per GB | This applies when private workloads are in a different AZ from the NAT Gateway |
| Data transfer out to the internet | $0.09/GB for first 10 TB in us-east-1 (varies by region and volume tier) | per GB, first 10 TB | AWS charges for egress from your VPC to the internet; the general 100 GB/month EC2 data transfer out free tier may partially offset it |
The Regional NAT Gateway expands across AZs as your workloads do. It simplifies the setup but does not remove the per-AZ cost. AWS bills the same hourly rate for each AZ the gateway is active in, so a three-AZ Regional NAT Gateway at $0.045 costs $0.135 an hour before any traffic.
AWS NAT Gateway pricing by region
| Region | Country | In the EU? | NAT per hour | NAT per GB | Public IPv4 per hour | Baseline monthly cost |
|---|---|---|---|---|---|---|
| eu-central-1 (Frankfurt) | Germany | yes | $0.052 | $0.052 | $0.005 | $41.61 |
| eu-west-1 (Ireland) | Ireland | yes | $0.048 | $0.048 | $0.005 | $38.69 |
| eu-west-3 (Paris) | France | yes | $0.05 | $0.05 | $0.005 | $40.15 |
| eu-north-1 (Stockholm) | Sweden | yes | $0.046 | $0.046 | $0.005 | $37.23 |
| eu-south-1 (Milan) | Italy | yes | $0.05 | $0.05 | $0.005 | $40.15 |
| eu-south-2 (Spain) | Spain | yes | $0.048 | $0.048 | $0.005 | $38.69 |
| eu-west-2 (London) | UK | yes | $0.05 | $0.05 | $0.005 | $40.15 |
| eu-central-2 (Zurich) | Switzerland | yes | $0.0572 | $0.0572 | $0.005 | $45.41 |
| us-east-1 (N. Virginia) | United States | no | $0.045 | $0.045 | $0.005 | $36.50 |
Source: Amazon's VPC pricing page
Across the EU regions listed, the NAT Gateway rates sit between $0.046 and $0.0572 per hour and per GB. The European Sovereign Cloud uses different infrastructure, has its own separate pricing, and it’s aimed at regulated organizations.
NAT Gateway cost calculations by traffic volume
A NAT gateway's monthly billing is the sum of five components. These include:
- Hourly charge per gateway (per AZ)
- Public IPv4 address charge
- Data processing per GB
- Cross‑AZ data transfer
- Internet data transfer out (egress)
Here is the formula that sums them up:
Monthly cost = (gateways × hourly rate × 730) + (public IPs × $0.005 × 730) + (GB processed × per-GB rate) + (GB crossing AZs × cross-AZ rate) + (GB sent out above 100 × $0.09 )
Where:
- Gateways: the number of NAT gateways.
- Hourly rate: Region-specific NAT gateway hourly charge, for example, $0.052 in Frankfurt and $0.045 in us-east-1.
- 730: the average hours per month (8,760 hours a year ÷ 12).
- Public IPs: the number of public IPv4 addresses you attach (typically one per NAT gateway).
- $0.005: the public IPv4 price per hour, the same for all commercial regions
- GB processed: Total GB that pass through the NAT Gateway, in both directions (outbound and return). AWS charges it at the per-GB processing rate.
- Per-GB rate: the data processing rate, which equals the hourly rate in both regions.
- GB crossing AZs: the GB that cross between AZs. AWS bills this traffic at $0.01 out plus $0.01 in, so $0.02 per GB.
- GB sent out above 100: GB of data transferred from your VPC to the internet beyond the general 100 GB/month EC2 data transfer out free tier. AWS charges this data at the region’s internet egress rate of $0.09/GB.
The table below applies the formula above but excludes internet data transfer out and assumes no cross‑AZ traffic.
| Monthly traffic | Frankfurt, 1 AZ | Frankfurt, 2 AZ | us-east-1, 1 AZ |
|---|---|---|---|
| 0 GB | $41.61 | $83.22 | $36.50 |
| 10 GB | $42.13 | $83.74 | $36.95 |
| 50 GB | $44.21 | $85.82 | $38.75 |
| 500 GB | $67.61 | $109.22 | $59.00 |
| 1000 GB | $93.61 | $135.22 | $81.50 |
At 10 GB, fixed charges are about 99% of the bill. In Frankfurt with one gateway, $41.61 of the $42.13 total is the gateway and its IP, and the 10 GB of processing adds only $0.52.
Here is a breakdown of the 500 GB billing in Frankfurt, 1 AZ:
- Gateway hours: 1 × $0.052 × 730 = $37.96
- Public IPv4: 1 × $0.005 × 730 = $3.65
- Data processing: 500 GB × $0.052 = $26.00
- Cross-AZ transfer: 0 GB × $0.02 = $0.00
Total: $37.96 + $3.65 + $26.00 = $67.61
Using the same method gives $59.00 for us-east-1, 1 AZ ($32.85 + $3.65 + $22.50) and $109.22 for Frankfurt with two AZs.
Single AZ vs high availability
Deploying one NAT Gateway in each of two AZs doubles the fixed charges, from $41.61 to $83.22 a month in Frankfurt. If it sits idle for a year, that is $499.32 for one AZ and $998.64 for two.
An alternative is to use one NAT gateway to serve workloads in two AZs, which charges $0.02 per GB for traffic from the other AZ. If half of 1,000 GB comes from that AZ, it adds 500 GB × $0.02 = $10.00. It also means every AZ loses internet access if the gateway's AZ fails. These figures leave out data transfer out.
The full monthly bill: NAT gateway, IP, and traffic together
The table below focuses on Frankfurt, a top choice for an Availability Zone (AZ) and data center hub due to its unmatched internet connectivity, central European location, and compliance with EU data laws. We use us-east-1 only as a low-cost US benchmark.
Frankfurt, 1 NAT gateway in 1 AZ
| Monthly Traffic | Gateway hours | Public IPv4 (1 IP) | Data Processing | Data Transfer Out | Total |
|---|---|---|---|---|---|
| 10GB | $37.96 | $3.65 | $0.52 | $0.00 | $42.13 |
| 50GB | $37.96 | $3.65 | $2.60 | $0.00 | $44.21 |
| 500GB | $37.96 | $3.65 | $26.00 | $13.50 | $81.11 |
| 1000GB | $37.96 | $3.65 | $52.00 | $36.00 | $129.61 |
US East (N. Virginia), 1 NAT gateway in 1 AZ
| Monthly Traffic | Gateway hours | Public IPv4 (1 IP) | Data Processing | Data Transfer Out | Total |
|---|---|---|---|---|---|
| 10GB | $32.85 | $3.65 | $0.45 | $0.00 | $36.95 |
| 50GB | $32.85 | $3.65 | $2.25 | $0.00 | $38.75 |
| 500GB | $32.85 | $3.65 | $22.50 | $13.50 | $72.50 |
| 1000GB | $32.85 | $3.65 | $45.00 | $36.00 | $117.50 |
Calculating the columns
The table below works through the bill for 10 GB of monthly traffic:
| Charge | How to calculate it | Frankfurt | US East (N. Virginia) |
|---|---|---|---|
| Gateway hours | Hourly rate × 730 hours × number of gateways | $0.052 × 730 × 1 = $37.96 | $0.045 × 730 × 1 = $32.85 |
| Public IPv4 | $0.005 × 730 hours × number of IPs | $0.005 × 730 × 1 = $3.65 | $0.005 × 730 × 1 = $3.65 |
| Data processing | GB processed × per-GB rate | 10 GB × $0.052 = $0.52 | 10 GB × $0.045 = $0.45 |
| Data transfer out | (Outbound GB − 100 GB free tier) × $0.09 | 5 GB outbound, under the free tier = $0.00 | 5 GB outbound, under the free tier = $0.00 |
| Total | Add the four charges | $42.13 | $36.95 |
Note: 730 is the average number of hours in a month (8,760 hours a year ÷ 12). AWS bills each partial NAT Gateway-hour as a full hour.
When you only need a NAT gateway for a static IP
A Lambda function may need to call a partner API that allowlists a single IP address. Lambda's outbound IPs are not fixed and can change as the service scales, so they are not suitable for partner allowlisting.
The fix is a VPC with public and private subnets, an internet gateway, Elastic IPs, and NAT Gateways. Most of these VPC components are free. The NAT Gateway and its public IPv4 address, however, bill continuously.

An alternative is OutboundGateway, an EU-based static outbound IP proxy that gives your workload fixed IPs. You configure it via environment variables instead of building a custom network.
It is worth noting that workloads in private subnets still need a route out. A static IP proxy provides fixed outbound IPs only for the traffic you route through it, such as calls to a partner API, but the workload must already have internet access. It can remove the need for a NAT gateway only when the workload can reach the proxy without one.
For example, a Lambda function that is not connected to your own VPC. A standard VPC-connected Lambda function still needs an outbound network path, usually a NAT gateway for IPv4 traffic; connecting it to a public subnet does not give it a public IPv4 address or direct IPv4 internet access.
An EC2 instance in a public subnet can reach the proxy directly if it has a public IPv4 address, including an Elastic IP, a route to an internet gateway, and security rules that allow the connection. An AWS-provided public IPv4 address carries a standard charge of $0.005 per hour. OutboundGateway is HTTPS-only, so it’s suitable for API calls and webhooks but won’t carry other protocols.
AWS NAT Gateway vs OutboundGateway: the cost comparison
What OutboundGateway is and what it costs
OutboundGateway is an EU static outbound IP proxy for IP whitelisting, so you route only the traffic that needs a fixed IP. It gives you static EU IPs with failover, TLS passthrough, EU data residency and compliance.
OutboundGateway has the following plans as of October 6, 2026:
- Starter: €19, 10 GB, 20,000 requests
- Business: €59, 50 GB, 100,000 requests
- Enterprise: €220, 1 TB, 1,000,000 requests, dedicated IPs
OutboundGateway counts bandwidth in both directions, similar to how AWS counts NAT Gateway data processing. It is important to note that this comparison excludes AWS data transfer out (egress).
| Monthly traffic | NAT, 1 AZ excluding egress | NAT, 2 AZ excluding egress | OutboundGateway pricing (€1 = $1.14) |
|---|---|---|---|
| 10 GB | $42.13 | $83.74 | Starter €19 = $21.66 |
| 50 GB | $44.21 | $85.82 | Business €59 = $67.26 |
| 500 GB | $67.61 | $109.22 | Enterprise €220 = $250.80 |
| 1000 GB | $93.61 | $135.22 | Enterprise €220 = $250.80 |
NAT figures include Frankfurt gateway hours, IP, and processing. This comparison excludes data transfer out because you pay it either way.
Note: Exchange rates are subject to market fluctuation.
Where a NAT gateway is cheaper
For the bandwidth and request volumes covered by the business and enterprise plans, a single‑AZ NAT Gateway in Frankfurt is cheaper in pure infrastructure cost. At 500 GB and 1 TB, even a 2‑AZ NAT setup is cheaper than the enterprise plan.
Where OutboundGateway is cheaper
The Starter plan (€19 = $21.66) is cheaper than any NAT Gateway setup at low volumes. At 10 GB, a single-AZ gateway in Frankfurt already runs $42.13, and a 2-AZ setup hits $83.74.
At 50 GB, the Business plan ($67.26) is cheaper than a 2-AZ NAT setup in Frankfurt ($85.82) because two AZs already cost $83.22 a month idle. This fits low‑volume, allowlisted HTTPS traffic that needs failover and fixed IPs.
Quotas: According to OutboundGateway’s pricing model, bandwidth and request quotas are treated as soft limits; exceeding them triggers an upgrade prompt rather than an automatic overage charge. A NAT Gateway, by contrast, bills every extra GB automatically. 100,000 requests a month is about 2.3 requests per minute, so for sustained, high‑frequency traffic the next plan up is the real price.
Free AWS NAT Gateway cost calculator
Use this calculator to run the formula above on your own setup. Pick a region, then enter the number of NAT gateways, your monthly traffic, the share sent out to the internet, and any traffic that crosses AZs. The video gives the same answer as the worked example shown in the full monthly bill section:
Fork the calculator code on GitHub to run it locally and update the rates when AWS prices change. Simply open index.html and input your values to use the calculator locally. The result section updates in real time as you input your values.
It returns each line of your NAT gateway bill, the total with and without data transfer out, and the OutboundGateway plan that covers the same traffic. It uses the same rates and assumptions as this article.
A cheaper alternative to NAT gateways
A NAT gateway makes sense when a whole VPC needs internet access, and your traffic runs into hundreds of gigabytes. When your workload requires a fixed IP for only a few partner APIs, gateway hours and the IP fee make up most of the bill.
OutboundGateway gives your workload static EU IPs for the calls that need them. You route those calls through the proxy and add the IPs to your partner's allowlist.
Start a 7-day trial with OutboundGateway and check how it compares with your NAT gateway bill.
Built with ❤️ for EU businesses who care about privacy and sovereignty.
Frequently asked questions
Does a NAT gateway charge for inbound traffic?
Yes. A NAT Gateway charges for inbound traffic processing. Inbound traffic means data coming from the internet into your AWS resources. AWS does not charge for data entering AWS from the internet as general data ingress. However, a NAT Gateway charges for every GB of data it processes, including data returning from the internet. So the inbound data is free as general ingress, but you still pay the NAT Gateway’s per-GB processing charge for it.
Is there a free tier for AWS NAT Gateway?
No. AWS NAT Gateway is not free. AWS charges for every hour the NAT Gateway is running, and for every GB of data it processes. However, with the AWS Free Tier, you get 100 GB of free data transfer out (DTO) per month from AWS Regions to the internet, which AWS aggregates across all AWS services and Regions (except China and GovCloud).
Can one NAT gateway serve several Availability Zones (AZs)?
Yes. Several AZs can share one NAT gateway, but you pay cross-AZ data transfer fees on traffic from the other AZs. If the gateway's AZ goes down, the other AZs lose internet access. A Regional NAT Gateway spreads across AZs automatically to avoid this, but you still pay the hourly rate for each AZ it's active in.
Is a NAT instance cheaper than a NAT gateway?
Usually at low traffic. A NAT instance is a standard EC2 instance that AWS bills at its normal price, with no NAT-specific or per-GB processing fee, while a gateway charges hourly plus per GB processed. You manage patching and failover yourself, and AWS recommends gateways for availability and bandwidth. You still pay for the public IPv4 address and data transfer out.
Do you still pay data transfer out if you use a static IP proxy?
Yes. Traffic that leaves AWS for a proxy outside AWS is billed as data transfer out, the same as traffic going anywhere else on the internet. With OutboundGateway, you eliminate the NAT gateway's hourly charge, public IP address, and per-GB processing fee.