Explanation
Why the waste happens and who it affects.
Firewalls are often deployed per VPC for a security project, a compliance review or a pilot, and they stay in place after route tables are changed, the workload moves, the VPC is retired or inspection is centralized elsewhere. Traffic stops flowing, but the endpoints keep billing.
Because a firewall normally has an endpoint in each of two or three Availability Zones, and may also have secondary endpoints from VPC endpoint associations and an Advanced Inspection charge, a single forgotten firewall can carry several hourly charges at once. The waste is most common where network teams deploy firewalls from templates into every VPC and nobody reviews whether each one still receives traffic. AWS Trusted Advisor has a dedicated check for this pattern.
Billing model
The pricing dimensions that drive this cost.
Network Firewall charges are per endpoint, per Region and Availability Zone.
- Firewall endpoint-hours
- An hourly rate for each firewall endpoint in each Availability Zone, charged regardless of how much traffic it processes
- Traffic processed
- Billed per GB of traffic processed by the firewall endpoint
- Secondary endpoints
- A separate, reduced hourly rate for each additional VPC endpoint association with a firewall
- Advanced Inspection
- An additional hourly rate per Availability Zone when TLS inspection is enabled
- NAT gateway waiver
- Standard NAT gateway hourly and data processing charges are waived one-to-one for a NAT gateway in the same Region and networking path as the firewall, so deleting the firewall ends the waiver for a NAT gateway that stays
How to detect
5 checks to find it in your estate.
- Review the Trusted Advisor cost optimization check Inactive AWS Network Firewall, which flags a firewall when all of its endpoints processed 0 bytes in the last 30 days and reports the firewall ARN, VPC, subnets and TotalBytesProcessed
- In CloudWatch (AWS/NetworkFirewall namespace), check ReceivedPackets and ReceivedBytes per FirewallName and AvailabilityZone over at least 30 days; these metrics are only reported when there is a nonzero value, so a firewall with no datapoints for the period has received no traffic
- Inspect VPC, subnet and Transit Gateway route tables for routes whose target is the firewall's VPC endpoints; a firewall with no route pointing to any of its endpoints cannot receive traffic
- List VPC endpoint associations (secondary endpoints) for each firewall and check them the same way, since each one bills separately
- Confirm with the network or security owner whether the firewall is part of a standby, disaster recovery or compliance design before treating it as unused
How to fix
5 ways to remove the waste.
- Delete firewalls that have processed no traffic and are no longer required; before deletion, disassociate VPC endpoint associations, remove the firewall from any route tables that reference it, disable its logging configuration, and turn off delete protection if it is enabled
- Delete unused VPC endpoint associations on firewalls that must remain, to remove their secondary endpoint charges
- Where many VPCs each run their own lightly used firewall and inter-VPC traffic already flows through Transit Gateway, consider a centralized inspection VPC, which Trusted Advisor suggests to reduce hourly charges on inactive firewalls
- Reduce the number of Availability Zones a non-production firewall spans if the workload it protects does not use them
- Keep the firewall policy and rule groups (or the infrastructure-as-code that defines them) if the firewall may be recreated later, so deletion does not lose the rule configuration
Documentation
Vendor references for pricing and configuration.