NAT Gateway has zero outbound traffic for 7 days

Severity
High
Service
VPC
Check ID
NAT_UNUSED

What this check finds

A NAT Gateway with no outbound bytes over 7 days is likely unused, yet incurs the base hourly charge of ~$0.045/hr ($32.85/month) plus data processing charges. Unused NAT Gateways commonly remain after workloads are migrated, deleted, or moved to a different subnet or VPC.

Passing looks like: No unused NAT Gateways.

How to fix it

Delete the NAT Gateway if it is no longer needed.

AWS CLI

  1. aws ec2 delete-nat-gateway --nat-gateway-id NAT_GATEWAY_ID
  2. Release the associated Elastic IP to avoid further charges:

    aws ec2 release-address --allocation-id ALLOCATION_ID

Names in capitals are placeholders for your own resource. Review a command before you run it.

AWS console

VPC → NAT gateways → select → Actions → Delete NAT gateway.

Compliance

This is a cost check. It flags spend that buys nothing, which no compliance framework asks about, so it is not mapped to a control.

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More VPC checks

All VPC checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only