... no network traffic from the agents or superagents back to the ePO. I.e. Only oneway from ePO out.
Unfortunately that requirement effectively means you can't use ePO
ePO's design is almost completely client-side driven - the only thing from server to client that is server-side driven is an agent wakeup call, and even that simply tells the clients to contact the server.
If the clients can't communicate with the server, then ePO cannot function. Sorry