All traffic from the trusted network is allowed out. As a general rule it is wise not to restrict outbound traffic, unless separate routers and firewalls are configured to handle it, to avoid overloading the firewall. If an organization wants control over outbound traffic, it should use a separate filtering device. The rule shown in Table 6-8 allows internal communications out, and as such would be used on the outbound interface.
Why should rule set 3 come after rule set 1 and 2? It makes sense to allow the rules that unambiguously impact the most traffic to be earlier in the list. The more rules a firewall must process to find one that applies to the current packet, the slower the firewall will run. Therefore, most widely applicable rules should come first since the firewall employs the first rule that applies to any given packet.