Skip to main content

North-South Traffic

North-south traffic crosses an environment or trust boundary, such as traffic between a user and an application or between a private service and the internet.

What is North-South Traffic?

North-south traffic crosses an environment or trust boundary, such as traffic between a user and an application or between a private service and the internet. The boundary can be a data center, VPC, cluster, or application edge. TLS normally authenticates the server to the client. Use mutual TLS or another client-authentication method when the service must also verify the client at the transport layer.

Why it matters

Boundary-crossing traffic connects systems with different trust conditions. Teams need clear entry points for authentication, authorization, encryption, inspection, and logging.

How it works

  1. Define the environment or trust boundary and identify each communication path that crosses it.
  2. Authenticate the relevant endpoints and protect data in transit with TLS or another suitable secure protocol.
  3. Apply access policy and logging at the boundary enforcement point before traffic reaches the protected resource.

Example

A remote engineer opens a private Grafana service in a VPC through an identity-aware Pomerium route at the application edge.

Pomerium boundary

A Pomerium route has an external address and one or more upstream destinations. Pomerium receives the boundary-crossing request, authenticates the user through the configured identity provider, evaluates route policy, and forwards only an approved request.

Limits and non-claims

  • North-south is a relative direction. The same flow can cross several nested boundaries.
  • A boundary control cannot protect a direct or alternate path that bypasses it.
  • North-south controls do not govern east-west traffic that stays within the defined boundary.

Evaluation checklist

  • Relative to which external boundary is this traffic north-south?
  • Which gateway decision and application authorization protect the final target action?
  • Can a public endpoint, alternate ingress, return path, or control-plane route bypass inspection?

Sources and further reading

Keep learning

Network and Infrastructure

East-West Traffic

East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments.

Learn this term
Network and Infrastructure

Firewall

A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy.

Learn this term
Network and Infrastructure

Perimeter

A security perimeter is a boundary where controls inspect or restrict communication. NIST zero trust does not remove firewalls or all network boundaries.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo