What is North-South Traffic?
North-south traffic crosses an environment or trust boundary, such as traffic between a user and an application or between a private service and the internet. The boundary can be a data center, VPC, cluster, or application edge. TLS normally authenticates the server to the client. Use mutual TLS or another client-authentication method when the service must also verify the client at the transport layer.
Why it matters
Boundary-crossing traffic connects systems with different trust conditions. Teams need clear entry points for authentication, authorization, encryption, inspection, and logging.
How it works
- Define the environment or trust boundary and identify each communication path that crosses it.
- Authenticate the relevant endpoints and protect data in transit with TLS or another suitable secure protocol.
- Apply access policy and logging at the boundary enforcement point before traffic reaches the protected resource.
Example
A remote engineer opens a private Grafana service in a VPC through an identity-aware Pomerium route at the application edge.
Pomerium boundary
A Pomerium route has an external address and one or more upstream destinations. Pomerium receives the boundary-crossing request, authenticates the user through the configured identity provider, evaluates route policy, and forwards only an approved request.
Limits and non-claims
- North-south is a relative direction. The same flow can cross several nested boundaries.
- A boundary control cannot protect a direct or alternate path that bypasses it.
- North-south controls do not govern east-west traffic that stays within the defined boundary.
Evaluation checklist
- Relative to which external boundary is this traffic north-south?
- Which gateway decision and application authorization protect the final target action?
- Can a public endpoint, alternate ingress, return path, or control-plane route bypass inspection?
