Multiple NAT Gateways in the same VPC and Availability Zone
- Severity
- Info
- Service
- EC2
- Check ID
- NAT_REDUNDANT_SAME_AZ
What this check finds
Having more than one NAT Gateway in the same VPC and Availability Zone is redundant — one NAT Gateway per AZ is sufficient for HA. Additional NAT Gateways in the same AZ provide no resilience benefit and each costs approximately $32/month in data processing and hourly charges.
Passing looks like: No redundant NAT Gateways in same AZ.
How to fix it
Identify which NAT Gateways are in the same AZ and consolidate to one per AZ. Update route tables in that AZ to point to a single NAT Gateway, then delete the redundant ones.
AWS console
VPC → NAT Gateways → filter by VPC → identify same-AZ duplicates → delete extras.
Compliance
This is a cost check. It flags spend that buys nothing, which no compliance framework asks about, so it is not mapped to a control.
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs
More EC2 checks
- HighAccount does not block public sharing of EBS snapshots
- HighAMI is publicly shared
- HighEBS snapshot is public
- HighEC2 instance CPU spiked abnormally — possible compromise or runaway process
- HighEC2 instance has an IAM role with admin privileges
- MediumAccount default for instance metadata does not require IMDSv2
- MediumEBS default encryption is not enabled for this region
- MediumEBS volume is not encrypted at rest