aws-samples / landing-zone-accelerator-on-aws-for-tse-se

MIT No Attribution
39 stars 16 forks source link

After update, daily Network Firewall costs spiked #8

Open ka-rostom opened 1 week ago

ka-rostom commented 1 week ago

Upgraded from 1.9.2-b to 1.10.0-a, and saw a significant jump in Network Firewall spend (~$19.00/daily).

Looking through the diffs between the two releases, I am having a hard time figuring out which changes in the latest LZA release 1.10.0-a would cause this jump in Network Firewall spend.

We upgraded our LZA setup on November 13th, which correlates directly with the jump in Network Firewall spend in the attached graph (attached below).

image

Please advise. Thank you! :)

oliviergaumond commented 4 days ago

@ka-rostom were you using AWS Network Firewall before? The pricing for Network Firewall Endpoint is 0.395$/h which roughly adds up to 19$/day when deploying firewall endpoints in two Availability Zones such as in this sample configuration. It looks like those endpoints were initially deployed on Nov 13th based on your graph.

ka-rostom commented 1 day ago

Were those added to the latest version?

We upgraded our LZA setup on November 13th, which correlates directly with the jump in Network Firewall spend in the attached graph (attached below).

rjjaegeraws commented 16 hours ago

Hi ka-rostom,

Here's a screenshot showing 3 months of Network Firewall in a test environment which would have different versions applied. Your increase spend aligns with the default deployment as Olivier mentioned above. image

I recommend that you compare your Network-Config.yaml with your previous versions and look closely at the Network Firewall section. Was it previously deployed?