LogoThreatmatic
Zones

Create a zone

Define a network zone with an entry point, allowed IP ranges, and DNS servers

Create a zone

A zone defines a network segment that enrolled devices can reach through the Threatmatic control plane. Each zone has an entry point (the WireGuard gateway), a set of allowed IP ranges, and optional DNS servers.

Prerequisites

  • Admin role in your Threatmatic organization
  • A running entry point (engine IP reachable by enrolled devices)

Steps

Open the Zones page

  1. Go to Console → Zones
  2. Click New Zone

Name and describe the zone

Enter a Name (e.g. HQ Network) and optionally a Slug (auto-generated from the name). The slug is used in policy rules and API references.

Set the entry point

Enter the Entry Point — the public IP or hostname of the Threatmatic engine that serves as the WireGuard gateway for this zone.

Each zone has one entry point. If you need redundancy, deploy multiple engines behind a load balancer and point the entry point at the load balancer address.

Configure allowed IPs

Enter the CIDR ranges that devices will be able to reach through this zone (e.g. 10.0.0.0/8, 192.168.1.0/24). These become the WireGuard AllowedIPs pushed to enrolled devices.

Add DNS servers (optional)

Enter DNS server IPs to push to devices when they connect to this zone. Useful for resolving internal hostnames that are not publicly resolvable.

Save

Click Create Zone. The zone will appear in the list with status Inactive until at least one device is assigned.

Next steps

How is this guide?

Last updated on

On this page