Create a zone
Define a network zone with an entry point, allowed IP ranges, and DNS servers
Create a zone
A zone defines a network segment that enrolled devices can reach through the Threatmatic control plane. Each zone has an entry point (the WireGuard gateway), a set of allowed IP ranges, and optional DNS servers.
Prerequisites
- Admin role in your Threatmatic organization
- A running entry point (engine IP reachable by enrolled devices)
Steps
Open the Zones page
- Go to Console → Zones
- Click New Zone
Name and describe the zone
Enter a Name (e.g. HQ Network) and optionally a Slug (auto-generated from the name). The slug is used in policy rules and API references.
Set the entry point
Enter the Entry Point — the public IP or hostname of the Threatmatic engine that serves as the WireGuard gateway for this zone.
Each zone has one entry point. If you need redundancy, deploy multiple engines behind a load balancer and point the entry point at the load balancer address.
Configure allowed IPs
Enter the CIDR ranges that devices will be able to reach through this zone (e.g. 10.0.0.0/8, 192.168.1.0/24). These become the WireGuard AllowedIPs pushed to enrolled devices.
Add DNS servers (optional)
Enter DNS server IPs to push to devices when they connect to this zone. Useful for resolving internal hostnames that are not publicly resolvable.
Save
Click Create Zone. The zone will appear in the list with status Inactive until at least one device is assigned.
Next steps
How is this guide?
Last updated on