Explanation
Why the waste happens and who it affects.
The charge does not depend on whether any site-to-site tunnel, VNet-to-VNet link, ExpressRoute circuit or point-to-site client is actually using the gateway, and the public IP addresses attached to the gateway keep billing as well.
Gateways are left behind after a data center migration completes, a branch office is closed, an ExpressRoute circuit is decommissioned or a connectivity test ends. Microsoft notes that deleting an ExpressRoute circuit but keeping the gateway still incurs charges until the gateway is deleted. Microsoft's FinOps best practices for Networking include 'Remove idle VNet gateways' with a Resource Graph query, and Azure Advisor has a preview recommendation 'Delete Azure virtual network gateways with no connections'.
Billing model
The pricing dimensions that drive this cost.
Gateway charges are fixed by SKU and time, not by traffic.
- Gateway hours
- VPN Gateway is billed for the time the gateway is provisioned and available, per SKU; a partial hour is billed as a full hour
- Included connections
- The hourly price includes the first 10 site-to-site tunnels and 128 point-to-site connections, with extra tunnels or connections billed separately
- ExpressRoute gateway
- Charged hourly in addition to the circuit, and keeps charging after the circuit is deleted
- Gateway public IPs
- Static public IP addresses incur charges whether or not they carry traffic
How to detect
5 checks to find it in your estate.
- Run the FinOps best practices Resource Graph query that left-joins microsoft.network/virtualnetworkgateways to microsoft.network/connections on properties.virtualNetworkGateway1.id and returns gateways with no connection resources
- Review Azure Advisor Cost recommendations for '(Preview) Delete Azure virtual network gateways with no connections'
- Before treating a VPN gateway as idle, check point-to-site use: P2S clients do not create connection resources, so review the P2S Connection Count (P2SConnectionCount) and Gateway P2S Bandwidth (P2SBandwidth) metrics over at least 30 days
- For gateways that do have connections, check Tunnel Bandwidth (TunnelAverageBandwidth) and Gateway S2S Bandwidth (AverageBandwidth), or ExpressRouteGatewayBitsPerSecond for ExpressRoute gateways, to find connections that carry no traffic
- Cross-check with network owners and change records for decommissioned sites, completed migrations and deleted ExpressRoute circuits
How to fix
4 ways to remove the waste.
- Confirm with the network owner that no site, circuit or remote user depends on the gateway, then delete the gateway and any stale connection and local network gateway resources
- Delete or release the public IP addresses that were attached to the deleted gateway, since they continue to bill on their own
- Record the gateway configuration (SKU, BGP settings, address spaces, connection settings) before deletion so it can be recreated if a site needs connectivity again
- For gateways that must stay but carry light traffic, review whether a smaller SKU meets the tunnel, throughput and feature requirements
Documentation
Vendor references for pricing and configuration.