Practical guide

NLB TCP and TLS costs: what to measure before comparing

compare NLB TCP and TLS capacity cost assumptions. Includes a worked example, calculator scope, and practical questions.

Updated · Sources checked

A protocol change can change the cost driver

A Network Load Balancer forecast should identify whether the listener and workload use TCP, TLS, or UDP before translating traffic into capacity units. The billing dimensions and thresholds are protocol-specific. The same connection count does not necessarily produce the same NLCU usage under different configurations.

Keep application behavior constant when comparing alternatives. Moving TLS work can also affect target compute and certificate management, so the NLB subtotal is only part of the decision.

Worked example: compare derived capacity totals

Imagine two technically valid configurations for the same workload. After applying the correct official dimension definitions, configuration A produces 1,000 NLCU-hours in a month and configuration B produces 1,600. Both use one NLB for 730 hours.

Holding the applicable NLCU price constant for this arithmetic example, the difference is 600 × NLCU-hour rate. The running-hour component cancels because it is the same in both cases. These NLCU totals are hypothetical derived inputs, not a claim that TLS always costs 60% more than TCP.

Run the calculator separately for each measured total. If the relevant pricing differs, preserve that distinction outside the simplified comparison. Also estimate any change in backend CPU usage: shifting cryptographic work between layers can move cost instead of removing it.

Gather inputs from the whole connection lifecycle

Measure connection creation, connection duration, and bytes across representative intervals. Short-lived clients can create a very different shape from persistent connections even when monthly transferred data is identical. Include reconnect storms and deployment events in a stress scenario without assuming that every hour looks like the worst hour.

This calculator accepts existing NLCU-hours and load-balancer hours. It does not select a protocol, model TLS cryptographic parameters, or calculate backend cost. Transfer, public IPv4, and other service charges also remain outside its scope.

Document where TLS terminates and which component owns certificates before adopting a change. A lower capacity number is useful only if the design still meets application, security, and operational requirements.

Frequently asked questions

Does TLS always make an NLB more expensive? The answer depends on the applicable dimensions and observed workload; compare derived usage.

Will fewer connections always reduce NLCUs? Only if the affected connection dimension determines capacity or the change also reduces the dominant dimension.

Calculate your scenario

Use the network load balancer cost calculator. Keep the displayed region, pricing date, billing units, and exclusions alongside your result. The arithmetic examples above illustrate usage or explicitly hypothetical rates; they are not AWS quotes.

Source

Billing structure checked against official AWS documentation on September 6, 2026.

Official sources

Related calculators

Continue reading