Skip to content

DNS Firewall Billing

0

Hello community, I would like to know how DNS Firewall billing works. I am planning to use this feature, but I am a bit worried about the cost since my idea is to use DNS Firewall to filter certain types of queries and for the unfiltered ones, use my external protection DNS service (PDNS). In this case, every query generated on my vpc will go first to DNS Firewall, this service will apply its filters and, after that, the queries will go through the DNS Resolver Outbound Endpoint to the PDNS. So I don't know if AWS will charge me twice per DNS query (once for DNS Firewall and once for Outbound Endpoint).

I hope someone can help me with this concern

Thanks!

asked 2 years ago805 views

1 Answer
2
Accepted Answer

DNS Firewall billing is based on the number of DNS queries processed and the number of domain names stored in your rule groups. Here's how it works in your scenario:

  1. DNS Firewall charges: You will be charged $0.60 per million queries for the first 1 billion queries, and $0.40 per million queries for queries over 1 billion. This applies to all DNS queries originating from within your VPCs and those traversing inbound Resolver endpoints from on-premises networks.

  2. Domain names in rule groups: If you store domain names within your rule groups, you'll be charged $0.0005 per domain name per month (prorated hourly). However, if you use managed domain lists within your firewall rules, you won't be charged for the domain names, but you'll still be charged for the DNS queries inspected against these rules.

  3. Resolver Outbound Endpoint: For the queries that pass through the DNS Resolver Outbound Endpoint to your external PDNS, you will be charged separately. The pricing for Resolver queries is $0.40 per million queries for the first 1 billion queries and $0.20 per million queries for queries over 1 billion.

So, to answer your concern: Yes, you will effectively be charged twice for the queries that pass through both DNS Firewall and the Outbound Endpoint. All queries will be charged for DNS Firewall inspection, and those that are not filtered and proceed to your external PDNS will incur additional charges for the Resolver Outbound Endpoint.

To manage costs, you might consider:

  1. Optimizing your DNS Firewall rules to filter as much as possible before queries reach the Outbound Endpoint.
  2. Monitoring your query volume and adjusting your architecture if needed.
  3. Using AWS Cost Explorer to track and analyze your DNS-related expenses.

Remember that while there are separate charges, this setup provides you with layered security and the flexibility to use both AWS DNS Firewall and your external PDNS service.
Sources
Amazon Route 53 pricing - Amazon Web Services
AWS DNS firewall with custom DNS | AWS re:Post

answered 2 years ago

EXPERT

reviewed 2 years ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.