Cost Optimization for Network

We summarize network cost optimization strategies for NAT Gateway, VPC Endpoints, and data transfer costs.

Network costs are easy to overlook on an AWS bill, but for high-traffic services they can become surprisingly large. In the SAA-C03 exam, data transfer cost optimization comes up frequently. To answer "Which configuration reduces network costs?", you need to understand where data is flowing and which direction.

 

The Basic Rules of Data Transfer Costs

Why do they matter? AWS charges differently based on the direction and path of data movement. Not knowing these rules can lead to a much larger bill than expected.

An easy way to remember: "Incoming is free. Same neighborhood is free. The farther data travels, the more it costs."

| Direction | Condition | Cost | |-----------|-----------|------| | Inbound | Internet to AWS | Free | | Same AZ | Using private IP | Free | | Same AZ | Using public or Elastic IP | Small fee | | Same region, different AZ | Both directions | Small fee per GB | | Different region | Both directions | Higher fee per GB | | AWS to Internet | Outbound | Most expensive |

Core principle: Using private IPs for communication within the same Availability Zone incurs no transfer cost. Simply switching from public IPs to private IPs for server-to-server communication within the same AZ is a cost saving.

 

What Is a NAT Gateway and Why Can It Get Expensive?

Why does it exist? Servers in private subnets are isolated from direct internet access — that is the point. But those servers still need to reach the internet sometimes, for software updates or calls to external APIs. NAT Gateway handles that outgoing traffic on their behalf.

What is it? Think of a shared mailroom in an apartment building. When a resident (private server) sends a letter, it goes out under the mailroom's address instead of the resident's apartment number. Replies come back to the mailroom, which distributes them to the right resident. The outside world only sees the mailroom address, never the individual apartment.

Why can it get expensive? NAT Gateway generates two types of charges simultaneously: Hourly usage fee (charged just for being on, even with no traffic) Data processing fee (charged per GB of data processed)

When servers in multiple AZs send traffic through a NAT Gateway in a different AZ, cross-AZ transfer fees stack on top of those charges.

 

Ways to Reduce NAT Gateway Costs

Method 1 — Route S3 and DynamoDB traffic through VPC Endpoints:

S3 and DynamoDB offer free Gateway Endpoints that allow access without going through NAT Gateway at all. If all S3 traffic flows through NAT Gateway, data processing fees accumulate continuously. Setting up an S3 Gateway Endpoint means S3 traffic bypasses NAT Gateway entirely — and that cost disappears.

Method 2 — Place a NAT Gateway in each AZ:

When a server in AZ-A uses a NAT Gateway in AZ-B, cross-AZ transfer fees are added. Place one NAT Gateway per AZ and configure each AZ's servers to use the NAT Gateway in their own AZ. Cross-AZ transfer fees disappear, though hourly NAT Gateway charges will multiply by the number of AZs.

Method 3 — NAT Instance for very small environments:

For very low-traffic environments, you can configure an EC2 instance as a NAT Instance instead of using the managed NAT Gateway. It costs less per hour, but you must manage availability, patching, and scaling yourself.

 

Reducing Costs with VPC Endpoints

Why do they exist? When servers inside a VPC access AWS services like S3 or DynamoDB through the internet, outbound fees apply. A VPC Endpoint creates a direct private connection inside the AWS network — like using an internal office phone line instead of a public payphone. No internet traffic, no outbound fees.

| Type | Target Services | Cost | |------|----------------|------| | Gateway Endpoint | S3, DynamoDB | Free | | Interface Endpoint (AWS PrivateLink) | Other AWS services (SNS, SQS, API Gateway, etc.) | Hourly + data processing fee |

S3 Gateway Endpoints are free. Any environment that uses S3 heavily should have one configured. In the exam, when the question asks "How do you reduce NAT Gateway costs when accessing S3?", the answer is almost always the S3 Gateway Endpoint.

 

Reducing Outbound Costs with CloudFront

Why does it exist? Serving files directly from S3 means paying outbound internet fees for every request. CloudFront caches content at hundreds of edge locations worldwide, so users receive files from the nearest edge location rather than from the origin (S3).

Why is it cheaper? S3 to CloudFront origin transfer: deeply discounted compared to standard S3 outbound (sometimes effectively free) CloudFront to end user: lower per-GB rate than standard S3 outbound High cache hit ratio means fewer origin requests, reducing S3 request costs too

Example: A service that delivers the same images to users globally. Serving directly from S3 means every request triggers S3 outbound fees. With CloudFront, only the first request per edge location hits S3. All subsequent users at that location are served from cache.

 

VPC Peering vs Transit Gateway

Why compare them? When connecting multiple VPCs, the connection method you choose determines your cost structure.

VPC Peering is a point-to-point connection. Think of it as building a dedicated private corridor between two buildings. There is no hourly connection fee — you pay only for data transfer. But as the number of VPCs grows, the number of peering connections grows exponentially: N VPCs require N × (N-1) / 2 peering connections.

Transit Gateway is a central hub. All VPCs connect to one hub (N VPCs need only N connections). There is an hourly attachment fee plus a data processing fee, so for a small number of VPCs, peering is cheaper. As VPC count grows, Transit Gateway becomes more economical and much easier to manage.

| Item | VPC Peering | Transit Gateway | |------|------------|----------------| | Cost structure | Data transfer only | Hourly connection fee + data processing | | Connection count | N × (N-1) / 2 | N | | Scalability | Low | High | | Recommended when | 2 to 3 VPCs | 4 or more VPCs |

 

Exam Key Points

"Eliminate NAT Gateway cost when accessing S3" -- S3 Gateway Endpoint (free)

"Like an internal phone line instead of a public payphone" -- Analogy for VPC Gateway Endpoints

"Prevent cross-AZ NAT Gateway costs" -- Place a separate NAT Gateway in each AZ

"Reduce internet outbound costs" -- Deliver content through CloudFront

"Free transfer within the same AZ" -- Must use private IP addresses

"Connect a few VPCs, pay only for data transfer" -- VPC Peering

"Centrally manage many VPCs, pay hourly connection fee" -- Transit Gateway

"Inbound data from the internet" -- Always free

S3 Gateway Endpoint is free — the most common correct answer for network cost-reduction questions

CloudFront is cheaper than direct S3 outbound, and higher cache hit rates yield even more savings

Back to blog list