Egress filtering

TCP/IP packets that are being sent out of the internal network are examined via a router, firewall, or similar edge device.

[1] Egress filtering helps ensure that unauthorized or malicious traffic never leaves the internal network.

In a corporate network, typical recommendations are that all traffic except that emerging from a select set of servers would be denied egress.

For this reason, egress filtering is an uncommon feature on consumer and very small business networks.

PCI DSS requires outbound filtering to be in place on any server in the cardholder's environment.