North-south and east-west traffic

North-south traffic crosses the boundary of the network being protected; east-west traffic moves between systems inside it. Both labels depend on which boundary is named.

North-south and east-west describe the direction of a traffic flow relative to a protected boundary. North-south traffic crosses that boundary, either coming in from outside or going out to it: a user on the internet reaching a web server, or a workstation sending data to a cloud service. East-west traffic stays inside the boundary, moving between systems within it, such as an application server querying a database in the same data centre. The labels are relative to whichever boundary is being discussed, so a single flow can be east-west for the site as a whole and north-south for a segment inside it.

The distinction matters because of where controls sit. A perimeter firewall, with ingress and egress filtering at the edge, inspects north-south traffic only. A control placed only at the boundary does not see east-west traffic, which is the path an attacker uses to move laterally after compromising one internal host. That gap is the reason for micro-segmentation and distributed firewalls, which enforce policy close to each workload, and it is a core argument behind zero trust.

Exam relevance: a scenario may describe an attacker moving between internal servers undetected despite a strong perimeter. Candidates are expected to recognise an east-west visibility gap and to reject the assumption that the perimeter firewall sees all traffic.