# Unnecessary Public IPv4 Addresses on In-Use Resources

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/unnecessary-public-ipv4-addresses-on-in-use-resources

Since February 1, 2024, AWS charges an hourly fee for every public IPv4 address, whether it is idle or attached to a running resource.

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

Since February 1, 2024, AWS charges an hourly fee for every public IPv4 address, whether it is idle or attached to a running resource.

PointFive Research

Cloud cost research at PointFive

AWS service

[AWS VPC](https://www.pointfive.co/efficiency-hub/cloud-services/aws-vpc)

Category

[Networking](https://www.pointfive.co/efficiency-hub/service-category/networking)

Reference

CER-0349

Type

Inefficient Configuration

## Explanation

Why the waste happens and who it affects.

Many resources still receive public addresses they never use: default subnets and subnets with auto-assign public IPv4 enabled give every EC2 instance a public address, launch templates and ECS services are often configured to assign one, and databases or other services are created as publicly accessible out of habit. When those resources are only reached from inside the VPC, over VPN or Direct Connect, or through a load balancer, the public address adds a per-resource charge and unnecessary attack surface.

Each address is a small charge, so the waste becomes material through volume: large EC2 and container fleets, per-developer environments and autoscaling groups can carry thousands of addresses. Unassociated Elastic IPs are only part of the picture; auto-assigned addresses on running instances and service-managed addresses on resources such as RDS instances or ECS tasks are billed the same way. VPC IPAM Public IP insights shows every public IPv4 address in an account or organization by type.

## Billing model

The pricing dimensions that drive this cost.

Public IPv4 addresses are billed per address per hour, regardless of whether they carry traffic.

In-use public IPv4

An hourly charge ($0.005 per address-hour on the VPC pricing page) for each public IPv4 address associated with a running resource, such as an EC2 instance, load balancer or RDS database

Idle public IPv4

The same $0.005 hourly charge for public IPv4 addresses, such as Elastic IPs, that are allocated but not associated with a resource

BYOIP exception

Addresses brought to AWS with Bring Your Own IP, and customer-owned IPs, are not charged

## How to detect

5 checks to find it in your estate.

- Open VPC IPAM Public IP insights, which lists every public IPv4 address across Regions (and across the organization when IPAM is integrated with AWS Organizations) by type: EC2 public IPs, service-managed IPs, Amazon-owned EIPs and BYOIP, along with the associated service, instance and security groups

- In the Cost and Usage Report, break down the PublicIPv4:InUseAddress usage type by account and operation to see which resource types drive the charge

- List subnets with MapPublicIpOnLaunch enabled that host workloads not meant to be reachable from the internet, and launch templates, ECS services and other configurations that request a public IP

- For each resource type, check whether inbound access actually arrives through the public address; instances behind a load balancer or reached only over private connectivity usually do not need one

- Check databases and other managed resources configured as publicly accessible that are only used from inside the VPC

## How to fix

5 ways to remove the waste.

- Disable auto-assign public IPv4 on subnets that host private workloads and in launch templates, and stop requesting public IPs in ECS services and similar configurations; the change applies as instances and tasks are replaced

- Place internal workloads in private subnets, use Application or Network Load Balancers for inbound traffic, and use EC2 Instance Connect Endpoint for administrative access instead of per-instance public addresses

- For outbound internet access, route private subnets through a NAT gateway, but compare costs first: a NAT gateway has its own hourly and per-GB processing charges, so it saves money only when it replaces enough public addresses or is already in place

- Turn off public accessibility on databases and other managed resources that are only accessed privately

- Adopt IPv6 where clients and dependencies support it, since the charge applies to public IPv4 addresses

## Documentation

Vendor references for pricing and configuration.

- [Amazon VPC Pricing  aws.amazon.com](https://aws.amazon.com/vpc/pricing/)

- [View public IP insights  docs.aws.amazon.com](https://docs.aws.amazon.com/vpc/latest/ipam/view-public-ip-insights.html)

- [Identify and optimize public IPv4 address usage on AWS  aws.amazon.com](https://aws.amazon.com/blogs/networking-and-content-delivery/identify-and-optimize-public-ipv4-address-usage-on-aws/)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- AWS VPC  CER-0118

### [Missing VPC Endpoints for High-Volume AWS Service Access](https://www.pointfive.co/efficiency-hub/inefficiencies/missing-vpc-endpoints-for-high-volume-aws-service-access)

When EC2 instances, Lambda functions, or containerized workloads in private subnets access AWS-managed services without VPC Endpoints, that traffic typically reaches the service's public endpoint through a NAT Gateway, and every GB incurs...

Networking

- AWS VPC  CER-0038

### [Inactive VPC Interface Endpoint](https://www.pointfive.co/efficiency-hub/inefficiencies/inactive-vpc-interface-endpoint)

VPC Interface Endpoints are commonly deployed to meet network security or compliance requirements by enabling private access to AWS services. However, these endpoints often remain provisioned even after the original use case is deprecated....

Networking

- AWS S3  CER-0161

### [Missing S3 Gateway Endpoint for Intra-Region EC2 Access](https://www.pointfive.co/efficiency-hub/inefficiencies/missing-s3-gateway-endpoint-for-intra-region-ec2-access)

When EC2 instances in private subnets access Amazon S3 in the same region without a Gateway VPC Endpoint, traffic is routed through a NAT Gateway to the public S3 endpoint. Data transfer from S3 to EC2 in the same region is free, but every...

Networking

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

