aws-network-firewallnetwork-firewall-pricing-calculator

AWS Network Firewall Pricing Calculator - Estimate Endpoint and Traffic Processing Costs

AWS Network Firewall pricing calculator to estimate primary and secondary endpoint charges, traffic processing, Advanced Inspection, and Advanced Threat Protection costs by region.

Frequently Asked Questions

How much does AWS Network Firewall cost per month?

In us-east-1, a primary Network Firewall endpoint is $0.395/hour, a secondary endpoint is $0.158/hour, and standard traffic processing is $0.065/GB. Your monthly total depends on how many endpoints you keep active, how much traffic you inspect, and whether you enable Advanced Inspection or Advanced Threat Protection.

What are secondary Network Firewall endpoints?

Secondary endpoints are discounted hourly endpoints used when one firewall is associated with multiple VPCs in the same Region and Availability Zone. They do not add a separate per-GB processing charge; traffic processing is still billed on the standard firewall traffic meter.

How is Advanced Inspection billed?

Advanced Inspection adds an extra hourly endpoint charge when TLS inspection is enabled. The standard traffic processing charge still applies, but AWS does not add a second per-GB charge specifically for Advanced Inspection traffic.

How is Advanced Threat Protection billed?

Advanced Threat Protection adds an additional per-GB processing charge on top of the standard traffic processing rate when active threat defense managed rule groups are enabled in your firewall policy.

CloudBurn

Catch AWS cost mistakes before they ship.

Use the calculator for quick estimates, then use CloudBurn when you need a deterministic cost review workflow. Run scan against Terraform and CloudFormation before deploy, then run discover against live AWS to find the waste that is already burning.

Read the docs to learn how it works.