LogoThreatmatic
Policies

Creating a policy

Define and enforce a Zero Trust policy in the Threatmatic Console

Creating a policy

Threatmatic policies define what traffic is allowed or blocked across your fleet. Each policy targets a specific traffic flow — by source, destination, protocol, and application — and applies an action to it.

Policy fields

FieldDescription
TitleHuman-readable name for this policy (required)
SlugURL-friendly identifier, auto-generated from the title (required)
Source or LocalSource IP or local address to match (e.g. 192.168.1.10)
Source PortSource port(s) to match (e.g. 80,4443)
Destination or RemoteDestination IP or remote address to match
Destination PortDestination port(s) to match (e.g. 80,4443)
ProtocolNetwork protocol: Any, TCP, UDP, etc.
ActionWhat to do with matched traffic: Permit, Block, or Audit
DirectionEgress (outbound) or Ingress (inbound)
VisibilityPrivate (org-internal) or Public
ApplicationApplication label to match (e.g. chrome, slack)
WeightPolicy priority — higher weight takes precedence (max 1000)
Throttle RateCap the network speed for matched traffic (0–100)

Steps

Navigate to Policies

  1. Sign in to the Console
  2. Go to Policies → Add Policy

Name the policy

Enter a Title — e.g. Block outbound P2P. The Slug is auto-generated but can be edited to create a stable identifier for the policy.

Define the traffic match

Fill in the fields that describe the traffic you want to target:

  • Source or Local / Source Port — leave blank to match any source
  • Destination or Remote / Destination Port — leave blank to match any destination
  • Protocol — defaults to Any; narrow to TCP or UDP as needed
  • Direction — Egress for outbound traffic, Ingress for inbound
  • Application — optionally match by application label (e.g. chrome)

You only need to fill in the fields relevant to your use case — unset fields are treated as wildcards.

Set the action and visibility

  • Action — Permit allows the traffic; Block drops it
  • Visibility — use Private for policies that should only apply within your organization

Configure additional settings (optional)

Expand Additional Settings to adjust:

  • Weight — controls evaluation order when multiple policies match. Higher weight wins (default: 1000).
  • Throttle Rate — limits network speed for matched traffic as a percentage of available bandwidth (default: 80).

Create the policy

Click Create. The policy is saved and will be evaluated against traffic on its next match.

After creating a policy, assign it to devices or groups to put it into effect. An unassigned policy is saved but not enforced.

Next steps

How is this guide?

Last updated on

On this page