# Inactive AWS Network Firewall | Cloud Efficiency Hub

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/inactive-aws-network-firewall

AWS Network Firewall creates a firewall endpoint in each Availability Zone subnet you configure, and every endpoint is billed by the hour whether or...

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

AWS Network Firewall creates a firewall endpoint in each Availability Zone subnet you configure, and every endpoint is billed by the hour whether or not traffic is routed through it.

PointFive Research

Cloud cost research at PointFive

AWS service

[AWS Network Firewall](https://www.pointfive.co/efficiency-hub/cloud-services/aws-network-firewall)

Category

[Networking](https://www.pointfive.co/efficiency-hub/service-category/networking)

Reference

CER-0357

Type

Idle or Unused Resource

## Explanation

Why the waste happens and who it affects.

Firewalls are often deployed per VPC for a security project, a compliance review or a pilot, and they stay in place after route tables are changed, the workload moves, the VPC is retired or inspection is centralized elsewhere. Traffic stops flowing, but the endpoints keep billing.

Because a firewall normally has an endpoint in each of two or three Availability Zones, and may also have secondary endpoints from VPC endpoint associations and an Advanced Inspection charge, a single forgotten firewall can carry several hourly charges at once. The waste is most common where network teams deploy firewalls from templates into every VPC and nobody reviews whether each one still receives traffic. AWS Trusted Advisor has a dedicated check for this pattern.

## Billing model

The pricing dimensions that drive this cost.

Network Firewall charges are per endpoint, per Region and Availability Zone.

Firewall endpoint-hours

An hourly rate for each firewall endpoint in each Availability Zone, charged regardless of how much traffic it processes

Traffic processed

Billed per GB of traffic processed by the firewall endpoint

Secondary endpoints

A separate, reduced hourly rate for each additional VPC endpoint association with a firewall

Advanced Inspection

An additional hourly rate per Availability Zone when TLS inspection is enabled

NAT gateway waiver

Standard NAT gateway hourly and data processing charges are waived one-to-one for a NAT gateway in the same Region and networking path as the firewall, so deleting the firewall ends the waiver for a NAT gateway that stays

## How to detect

5 checks to find it in your estate.

- Review the Trusted Advisor cost optimization check  Inactive AWS Network Firewall , which flags a firewall when all of its endpoints processed 0 bytes in the last 30 days and reports the firewall ARN, VPC, subnets and TotalBytesProcessed

- In CloudWatch (AWS/NetworkFirewall namespace), check ReceivedPackets and ReceivedBytes per FirewallName and AvailabilityZone over at least 30 days; these metrics are only reported when there is a nonzero value, so a firewall with no datapoints for the period has received no traffic

- Inspect VPC, subnet and Transit Gateway route tables for routes whose target is the firewall's VPC endpoints; a firewall with no route pointing to any of its endpoints cannot receive traffic

- List VPC endpoint associations (secondary endpoints) for each firewall and check them the same way, since each one bills separately

- Confirm with the network or security owner whether the firewall is part of a standby, disaster recovery or compliance design before treating it as unused

## How to fix

5 ways to remove the waste.

- Delete firewalls that have processed no traffic and are no longer required; before deletion, disassociate VPC endpoint associations, remove the firewall from any route tables that reference it, disable its logging configuration, and turn off delete protection if it is enabled

- Delete unused VPC endpoint associations on firewalls that must remain, to remove their secondary endpoint charges

- Where many VPCs each run their own lightly used firewall and inter-VPC traffic already flows through Transit Gateway, consider a centralized inspection VPC, which Trusted Advisor suggests to reduce hourly charges on inactive firewalls

- Reduce the number of Availability Zones a non-production firewall spans if the workload it protects does not use them

- Keep the firewall policy and rule groups (or the infrastructure-as-code that defines them) if the firewall may be recreated later, so deletion does not lose the rule configuration

## Documentation

Vendor references for pricing and configuration.

- [AWS Network Firewall Pricing  aws.amazon.com](https://aws.amazon.com/network-firewall/pricing/)

- [Cost optimization - AWS Support  docs.aws.amazon.com](https://docs.aws.amazon.com/awssupport/latest/user/cost-optimization-checks.html)

- [AWS Network Firewall metrics in Amazon CloudWatch  docs.aws.amazon.com](https://docs.aws.amazon.com/network-firewall/latest/developerguide/monitoring-cloudwatch.html)

- [Deleting a firewall in AWS Network Firewall  docs.aws.amazon.com](https://docs.aws.amazon.com/network-firewall/latest/developerguide/deleting-firewall.html)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- AWS EIP  CER-0110

### [Unassociated Elastic IP Address](https://www.pointfive.co/efficiency-hub/inefficiencies/unassociated-elastic-ip-address)

Elastic IPs are often provisioned but forgotten - left unassociated, or still attached to EC2 instances that have been stopped. AWS bills every public IPv4 address, including an EIP, by the hour whether it is in use or idle, so in either...

Networking

- AWS ELB  CER-0059

### [Inactive Classic Load Balancer (CLB)](https://www.pointfive.co/efficiency-hub/inefficiencies/inactive-classic-load-balancer-clb)

Classic Load Balancers that no longer serve active workloads will persist if they are not properly decommissioned. This often happens after application migrations, architecture changes, or testing activities. Even if no connections or...

Networking

- AWS ELB  CER-0006

### [Inactive Network Load Balancer (NLB)](https://www.pointfive.co/efficiency-hub/inefficiencies/inactive-network-load-balancer-nlb)

Network Load Balancers that are no longer needed often persist after architecture changes, service decommissioning, or migration projects. When no active TCP connections or traffic flow through the NLB, it still generates hourly...

Networking

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

