Decide who can reach what — across every site.
Tag your nodes by role, site, or environment and write access rules against those tags. Rules compile to the kernel data plane and are enforced identically on every node in the mesh — not just at a central choke point.
- Tag-based rules: allow/deny by role, site, protocol, port
- Enforced on the kernel data plane (iptables) at every node
- Default-deny isolation mode, per network
- Policy propagates to all edges in under a second