Creating a policy
Define and enforce a Zero Trust policy in the Threatmatic Console
Creating a policy
Threatmatic policies define what traffic is allowed or blocked across your fleet. Each policy targets a specific traffic flow — by source, destination, protocol, and application — and applies an action to it.
Policy fields
| Field | Description |
|---|---|
| Title | Human-readable name for this policy (required) |
| Slug | URL-friendly identifier, auto-generated from the title (required) |
| Source or Local | Source IP or local address to match (e.g. 192.168.1.10) |
| Source Port | Source port(s) to match (e.g. 80,4443) |
| Destination or Remote | Destination IP or remote address to match |
| Destination Port | Destination port(s) to match (e.g. 80,4443) |
| Protocol | Network protocol: Any, TCP, UDP, etc. |
| Action | What to do with matched traffic: Permit, Block, or Audit |
| Direction | Egress (outbound) or Ingress (inbound) |
| Visibility | Private (org-internal) or Public |
| Application | Application label to match (e.g. chrome, slack) |
| Weight | Policy priority — higher weight takes precedence (max 1000) |
| Throttle Rate | Cap the network speed for matched traffic (0–100) |
Steps
Navigate to Policies
- Sign in to the Console
- Go to Policies → Add Policy
Name the policy
Enter a Title — e.g. Block outbound P2P.
The Slug is auto-generated but can be edited to create a stable identifier for the policy.
Define the traffic match
Fill in the fields that describe the traffic you want to target:
- Source or Local / Source Port — leave blank to match any source
- Destination or Remote / Destination Port — leave blank to match any destination
- Protocol — defaults to
Any; narrow toTCPorUDPas needed - Direction —
Egressfor outbound traffic,Ingressfor inbound - Application — optionally match by application label (e.g.
chrome)
You only need to fill in the fields relevant to your use case — unset fields are treated as wildcards.
Set the action and visibility
- Action —
Permitallows the traffic;Blockdrops it - Visibility — use
Privatefor policies that should only apply within your organization
Configure additional settings (optional)
Expand Additional Settings to adjust:
- Weight — controls evaluation order when multiple policies match. Higher weight wins (default: 1000).
- Throttle Rate — limits network speed for matched traffic as a percentage of available bandwidth (default: 80).
Create the policy
Click Create. The policy is saved and will be evaluated against traffic on its next match.
After creating a policy, assign it to devices or groups to put it into effect. An unassigned policy is saved but not enforced.
Next steps
How is this guide?
Last updated on