# Transit Gateway Data Processing on High-Volume VPC-to-VPC Traffic

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/transit-gateway-data-processing-on-high-volume-vpc-to-vpc-traffic

Hub-and-spoke network designs attach every VPC to an AWS Transit Gateway and route all inter-VPC traffic through it.

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

Hub-and-spoke network designs attach every VPC to an AWS Transit Gateway and route all inter-VPC traffic through it.

PointFive Research

Cloud cost research at PointFive

AWS service

[AWS Transit Gateway](https://www.pointfive.co/efficiency-hub/cloud-services/aws-transit-gateway)

Category

[Networking](https://www.pointfive.co/efficiency-hub/service-category/networking)

Reference

CER-0353

Type

Inefficient Architecture

## Explanation

Why the waste happens and who it affects.

That is a sound default for manageability, transitive routing and on-premises connectivity, but Transit Gateway charges a data processing fee on every gigabyte sent into it from a VPC. When a small number of VPC pairs exchange very large, steady volumes, for example an application VPC reading from a shared data platform VPC, replication between service VPCs or log shipping to a central VPC, those pairs can account for most of the Transit Gateway bill.

VPC peering between the same two VPCs has no data processing charge: traffic that stays within an Availability Zone is free and traffic that crosses Availability Zones is billed at standard in-Region data transfer rates. The AWS multi-VPC networking whitepaper describes peering as offering the lowest overall cost and highest aggregate performance for inter-VPC connectivity, while noting its limits at scale. The waste arises when heavy flows that need none of Transit Gateway's features stay on the hub because it is the default path.

## Billing model

The pricing dimensions that drive this cost.

Transit Gateway and VPC peering bill inter-VPC traffic differently.

TGW attachment-hours

The VPC owner is billed for each hour a VPC is attached to a transit gateway

TGW data processing

Charged per GB sent from a VPC, Direct Connect, VPN or Network Firewall to the transit gateway, billed to the owner of the sending VPC

Peering within an AZ

Data transfer over a VPC peering connection that stays within an Availability Zone is free

Peering across AZs

Billed at standard in-Region data transfer rates in both directions ($0.01/GB each way on the VPC pricing page), with no processing fee

## How to detect

5 checks to find it in your estate.

- Use the AWS/TransitGateway CloudWatch metrics BytesIn and BytesOut with the TransitGatewayAttachment dimension to rank VPC attachments by the volume they send through the transit gateway

- Enable Transit Gateway flow logs (or use VPC flow logs) to break that volume down by source and destination VPC and identify the few VPC pairs that carry most of the traffic

- Review Transit Gateway data processing charges in Cost Explorer or the Cost and Usage Report by account, since processing is billed to the account that owns the sending VPC

- For each heavy pair, confirm whether the traffic actually needs Transit Gateway features such as transitive routing, centralized inspection through a firewall appliance, or on-premises paths

- Check whether the heavy flows cross Availability Zones, which affects how much peering would save compared with processing charges

## How to fix

5 ways to remove the waste.

- Create a VPC peering connection between each heavy VPC pair and route the peer VPC's CIDR (or a portion of it) to the peering connection in both VPCs' route tables; if the transit gateway route uses a broader summary range, the more specific peering route wins by longest prefix match, and if it uses the identical CIDR, replace that route

- Keep Transit Gateway for transitive, hybrid and inspected flows; do not move traffic to peering where security policy requires it to pass through a centralized inspection VPC

- Where possible, keep chatty producer and consumer workloads in the same Availability Zone so peered traffic is free rather than billed at cross-AZ rates

- Limit peering to a small number of high-volume pairs; peering does not support transitive routing and is capped at 125 active peering connections per VPC, so a full mesh is not a practical replacement for the hub

- Re-measure attachment BytesIn after the change to confirm the processing charges moved as expected

## Documentation

Vendor references for pricing and configuration.

- [AWS Transit Gateway Pricing  aws.amazon.com](https://aws.amazon.com/transit-gateway/pricing/)

- [Amazon VPC Pricing  aws.amazon.com](https://aws.amazon.com/vpc/pricing/)

- [VPC peering - Building a Scalable and Secure Multi-VPC AWS Network Infrastructure  docs.aws.amazon.com](https://docs.aws.amazon.com/whitepapers/latest/building-scalable-secure-multi-vpc-network-infrastructure/vpc-peering.html)

- [CloudWatch metrics in AWS Transit Gateway  docs.aws.amazon.com](https://docs.aws.amazon.com/vpc/latest/tgw/transit-gateway-cloudwatch-metrics.html)

- [How route priority works  docs.aws.amazon.com](https://docs.aws.amazon.com/vpc/latest/userguide/route-tables-priority.html)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- AWS NAT Gateway  CER-0325

### [Excessive NAT Gateway Data Processing Charges from Unoptimized Traffic Routing](https://www.pointfive.co/efficiency-hub/inefficiencies/excessive-nat-gateway-data-processing-charges-from-unoptimized-traffic-routing)

NAT Gateway charges a per-gigabyte data processing fee on all traffic that passes through it - in either direction - regardless of whether the destination is the public internet or another AWS service in the same region. This per-GB charge...

Networking

- AWS ELB  CER-0187

### [Elastic Load Balancer with Only One EC2 Instance](https://www.pointfive.co/efficiency-hub/inefficiencies/elastic-load-balancer-with-only-one-ec2-instance)

An ELB with only one registered EC2 instance does not achieve its core purpose-distributing traffic across multiple backends. In this configuration, the ELB adds complexity and cost without improving availability, scalability, or fault...

Networking

- AWS VPC  CER-0118

### [Missing VPC Endpoints for High-Volume AWS Service Access](https://www.pointfive.co/efficiency-hub/inefficiencies/missing-vpc-endpoints-for-high-volume-aws-service-access)

When EC2 instances, Lambda functions, or containerized workloads in private subnets access AWS-managed services without VPC Endpoints, that traffic typically reaches the service's public endpoint through a NAT Gateway, and every GB incurs...

Networking

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

