Separate Cloud NAT charges from network transfer costs
On this page
This check is due for a source refresh. Confirm the current documentation before you rely on provider-specific details.
Separate Cloud NAT hourly, processing, transfer, connectivity, and logging charges before reducing traffic, or you may cut GiB processed while leaving hourly costs unchanged. Match each charge to its billing unit and send it to the owner of that cost driver.
What you need first
- Tool
- Use the checklist with billing records for selected projects and dates. For traffic context, Cloud Logging is Google's service for viewing Cloud NAT logs and VPC Flow Logs. Use existing results only.
- Access
- Ask an authorized billing colleague for the scoped charge breakdown and an authorized network colleague for the NAT variant and existing log results. Have each use approved access for that scope.
- If you do not use that tool
- Send the colleagues the project names, start and end dates, and gateway names if known. Request NAT charge lines with usage units, related transfer or connectivity charges, logging charges, and an existing-log traffic summary.
Why this is worth a look
Skipping the split can send you after traffic when the charge is driven by assigned VM instances or external IP hours. Public NAT has gateway-hour, external-IP-hour, and processed-GiB charges, plus data transfer out. Private NAT has an hourly gateway charge based on assigned VM instances, processed GiB, and applicable Cloud Interconnect, Cloud VPN, or Network Connectivity Center costs. Both variants count inbound and outbound processed data. Cloud NAT logging has separate Cloud Logging, BigQuery, or Pub/Sub charges.
Run this check
CHECKLISTComplete this checklist on records supplied by authorized billing and network colleagues. Use one project set and date range. Record usage units separately and use existing logs only for traffic context.
CLOUD NAT COST BREAKDOWN
Projects: ____________________
Gateway names, if known: ____________________
Start and end dates: ____________________
Work from supplied billing records and existing log results.
Do not change gateways, IP addresses, or logging settings.
[ ] Record each charge's billed amount, usage quantity and unit,
billing item name (SKU), project, and date range.
Keep hourly charges, processed GiB, transfer, connectivity,
and logging in separate groups.
[ ] Confirm the NAT variant with the network owner. Match NAT
billing items using these names:
Public NAT:
- Networking Cloud NAT gateway uptime
- Networking Cloud NAT IP usage
- Networking Cloud NAT data processing
Private NAT:
- Networking Private NAT gateway uptime
- Networking Private NAT data processing
[ ] Identify what drives the hourly charge:
- Public NAT gateway: assigned virtual machine (VM) instances.
The hourly rate is capped at the rate for 32 instances.
- Public NAT external IPs: each static or ephemeral address
used by the gateway is billed per hour.
- Private NAT gateway: assigned VM instances using the gateway.
The resulting gateway charge is hourly.
Ask the NAT owner to review the relevant driver.
[ ] Keep processed GiB separate from other network charges:
- Both NAT variants process inbound and outbound data.
- Public NAT also has data transfer out costs.
- Private NAT also has applicable Cloud Interconnect,
Cloud VPN, or Network Connectivity Center service costs.
Ask the workload and network-path owners to review these groups.
Send logging charges to the log collection and storage owner.
[ ] If traffic attribution is needed, use existing logs covering
the same window:
- Cloud NAT logs: summarize destinations; distinguish created
connections from outgoing packets dropped for lack of a NAT port.
- VPC Flow Logs: summarize high-traffic resources and destinations.
Record the reporting network's project and aggregation interval.
Do not treat either log summary as billed usage.
Mark attribution unresolved if logs are missing or insufficient.
[ ] Record the next review: charge group, owner, supporting records,
and the question they need to resolve before any change.
How to confirm it
- 01
Choose the projects and dates
Request the billing breakdown for the selected projects and dates. Include transfer, connectivity, and logging charges associated with NAT traffic, not just billing items named Cloud NAT.
- 02
Identify the charge to review
Complete the checklist's billing sections and confirm Public NAT or Private NAT with the network owner. Choose the cost driver that needs attention before asking for a traffic reduction.
- 03
Explain traffic only where needed
Ask the network colleague for existing-log results when processing or transfer charges need explanation. Use VPC Flow Logs to identify high-traffic resources and destinations, and Cloud NAT logs for connection context. Leave attribution unresolved if coverage is insufficient.
- 04
Hand off a specific question
Send the responsible owner the charge group, dates, usage units, and supporting records. Ask what can change that billed driver and what operational checks are needed before making a change.
Before making changes
Do not use missing logs as proof of no traffic. Cloud NAT logs cover TCP and UDP only, can omit events, and do not log dropped incoming packets. VPC Flow Logs sample packets and aggregate them by IP connection, so they are not billing totals. This review assumes the billing records cover the intended projects and dates, the NAT variant can be confirmed, and existing logs are from the same window. It identifies cost drivers, not whether a gateway or IP address is safe to remove.