Apoxy:// Solutions

Cut your NAT gateway bill

A one line migration could save you 20% or more on your AWS NAT Gateway charges.

01The billSide by side

Reliable Data Processing for Less.

We bill the same two things but for high traffic workloads a lower data processing charge can have huge impact to your bill.

Data processing
$0.011/GB76%
AWS: $0.045/GB. Same bytes, a quarter the rate.
Per-AZ
$65/mo+$32.15
AWS: $32.85/mo per gateway. Apoxy is HA in each AZ.
Data transfer out
Unchanged
AWS egress rates are the same on either path.
02CostCalculator

See what you can save.

For some workloads, this isn't going to be cheaper. If you have significant volume, this could get your team another engineer.

Fig. 01 — Monthly cost, US East list pricesRev. A
102.3 TB
1 TB32 TB1 PB
AZs per region3
1
$3,383/mo

27% off the NAT gateway bill

At 102.3 TB/mo across 3 AZ deployments, Apoxy Edge NAT is cheaper. $7,956 of each side is the identical AWS data-transfer-out line. For running the gateway and processing data the cost could be 72% less.

NAT gateway$12,659
Apoxy Edge NAT$9,277
Per-AZ charge Data processing Data transfer out (identical)
AWS

NAT gateway

  • NAT gateway uptime (3 gateways)$0.045/hr × 730 hr × 3$99
  • Data processing$0.045/GB × 102.3 TB$4,605
  • Internet data transfer outAWS published tiers × 102.3 TB$7,956
Monthly total$12,659
Apoxy

Edge NAT

  • Apoxy Edge NAT (3 AZ deployments)$65/mo × 3$195
  • Data processing$0.011/GB × 102.3 TB$1,126
  • Internet data transfer outAWS published tiers × 102.3 TB — identical to NAT gateway$7,956
Monthly total$9,277

Estimated from published on-demand rates, based on the traffic you set above. Higher volume discounts may be available, talk to our team for an accurate quote.

03MigrationRoute table

A one line migration.

This is not wired into your application. It is a target on the default route of your private subnet's route table. Just change one line per AZ and start saving. Ask us about cross-zone static IP add-ons.

Fig. 02 — Default route, private subnetRev. A
PRIVATE-SUBNET-RTrtb-04c7a19f3b8e2d05c
DestinationTargetType
10.0.0.0/16localVPC
0.0.0.0/0nat-0a1b2c3d4e5f6apoxy-egress-use1NAT GATEWAYAPOXY ENDPOINT
Billed on this route$0.045/GB processed · $32.85/mo per AZ$0.011/GB processed · $65/mo per AZ
Edit target
  • Instances don't change at all.
  • No application config change, no redeploy, no restart.
  • Cut over one subnet first, then one AZ, then the rest.
  • Leave the NAT gateway provisioned until you are convinced.
04FAQNAT gateway

Questions we get.

How risky is the cutover?

Existing connections will keep using the target they were established on but new connections take the updated target. You can cut over a single private subnet first, leave the NAT gateway provisioned, and you can undo faster than you can open the incident channel. We don't think you'll have to, but we understand if you want the option. We've been there too.

What does rollback actually involve?

Just change the row back to the NAT gateway. There is no state to migrate, no data to move, and nothing in your application that knows which target it used. This was designed to be as simple and painless as possible.

Does my data transfer out bill change?

No. AWS meters internet data transfer out at its published tiers on either path, with the first 100 GB a month free. What goes away is the NAT gateway's per-GB processing charge that sits underneath it, and the per-AZ hourly charge for the gateways you retire. That is why our calculator shows data transfer out on both columns and greys it out. However, if you have very large volumes of traffic, we have an architecture that could save you even more. Ask us about it.

What throughput does it handle?

During provisioning, our team will walk you through how we provision at more than 4x your peak Gbps rate with high availability. We will review your historical traffic and show you exactly the capacity we have allocated for you, but you won't have to manage any of it.

What happens when an AZ has a bad day?

Egress is deployed per AZ, the same shape as the NAT gateways it replaces, so an AZ failure is contained to that AZ's subnets. Our team will notify you of any issues and do our best to route around them automatically.

Should I just use VPC endpoints instead?

This will depend on your workload. For S3 and DynamoDB, generally yes. While these endpoints keep that traffic off the NAT path entirely, if you need to use interface endpoints then you will incur other hourly-per-AZ and per-GB charges. We can help you figure out the best routing strategy for your application to save you as much as possible while maintaining the highest reliability.

How is this different from running NAT instances?

Architecturally, a self-managed NAT instance means maintenance for you. This is a fully managed service. There is no AMI to track or EC2 instance to update. No worrying about instance type and sizing against your traffic demands. Forget the autoscaling group and ENI dance for failover, and let your pager focus on application issues. Apoxy NAT is a fully managed service that saves you time and money with a simple architecture you can deploy in minutes.

Show us your bill.

We'll show you exactly what you can save on the first call and then follow up with your team to plan the details.