Skip to main content

East-West Traffic

East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments.

What is East-West Traffic?

East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments. It can cross segments, firewalls, gateways, regions, and cloud boundaries. Do not assume it is trusted because it does not enter from the public internet. Apply identity, encryption, segmentation, and access policy according to the resource and request.

Why it matters

An attacker can use internal service paths for discovery and lateral movement after one workload is compromised. Internal traffic therefore needs explicit identity, policy, and monitoring.

How it works

  1. The organization maps required service-to-service flows and the identity of each workload or caller.
  2. Enforcement points apply authentication, encryption, segmentation, and access policy to those flows.
  3. Logs and current context support review and later authorization decisions.

Example

A front-end workload can call one payment API over an authenticated encrypted path. Policy blocks that workload from opening a direct database connection.

Pomerium boundary

Pomerium can protect selected internal HTTP, TCP, and UDP routes with identity-aware policy. It applies policy to traffic that uses those routes. It does not protect east-west paths that bypass Pomerium.

Limits and non-claims

  • East-west is a traffic description and does not identify one security control or trust level.
  • Encryption hides content but does not by itself authorize the source or requested operation.
  • Unmanaged services and bypass paths remain outside a gateway or service-mesh policy.

Evaluation checklist

  • Relative to which boundary is this traffic east-west?
  • Which workload identity, credential, resource, action, and policy exist at every hop?
  • Can a compromised workload reach a peer, data store, metadata service, or control plane directly?

Sources and further reading

Keep learning

Network and Infrastructure

North-South Traffic

North-south traffic crosses an environment or trust boundary, such as traffic between a user and an application or between a private service and the internet.

Learn this term
Security Operations and Risk

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

Learn this term
Zero TrustNetwork and Infrastructure

Micro-segmentation

The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo