Core: server1.local · mTLS required · policy bundle v1

Microsegmentation control plane

Devices
Policies
Flows
Cloud / K8s Workloads
Policy Enforcement
Device Policy Bundle Status

Visibility

All observed flows and access attempts: source, destination, process, and verdict
Endpoint Access Graph aggregated inbound attempts and outbound access by selected endpoint
Traffic summary
Top conversations
green allowred denyamber learn/auditblue observed
Flow and Access Attempt Log

Policy Management

Create and manage policies, groups, and policy packages for your fleet
How policy management works
  1. Create or review groups — define containers (e.g. IP ranges, identities) that policies can target.
  2. Create policies — each policy references groups or direct CIDRs. Enabled policies are included in the endpoint package.
  3. Enabled policies ship automatically — the enabled-package includes every enabled policy and is pushed to enrolled endpoints.
  4. Check status below — see whether enrolled endpoints have applied the latest package.
Policy Package Entries
—
enabled policies in package
Total Policies
—
all configured policies
Enabled Policies
—
enforcing on endpoints
Groups
—
group containers
Group Members
—
total member values across all groups
Latest Package Report
—
no reports yet
Policy package contents / enabled policiesserved in endpoint bundles
All configured policiesaction, scope, matchers
Policy groupsgroup container members used by policies
No policy groups loaded

Newly Seen Traffic

Flows outside the assigned package baseline — triage drift vs suspicious behavior
Open
—
needs decision
Suspicious
—
high risk
Expected
—
accepted drift
Added / Blocked
—
package decisions
Closed-loop workflow
Learn baseline → build package → audit/enforce → review newly seen flows → add expected drift to a package or block/investigate suspicious traffic.
Triage queue
Audit Events Immutable log
Recent Audit
Audit Event Stream Last 50 events

Device Enrollments

Pairing codes, JIT access, enrollment flow
Download Node Installer auto-embeds this management server

Generate a Linux bootstrap installer that writes the Core URL/IP/DNS and one-time pairing code into the endpoint service config. No admin token or private key is embedded.

Active Pairing Codes
No active pairing codes. Generate one to allow new devices to enroll.

Endpoint Client

PacketSpear Node — endpoint-local visibility and enforcement
Local endpoint
workstation-jg
Device UUID: —
platform=darwin owner=jeremy site=clay
mTLS
✓ Verified
Heartbeat
14s ago
Policy backend
audit / pf pending
Node version
v0.1.0-dev
Enforcement mode
Current policy bundle
sha256:3bd1f0a7c11e21c9
7
policies
3
unsupported caps
0
apply errors
Rules compiled for this endpoint first-match-wins
Terminal — packetspear-node status live output
$ packetspear-node status --watch
✓ enrolled as workstation-jg
✓ mTLS verified against Core CA
→ fetching policy bundle...
✓ bundle sha256:3bd1f0a7 applied=skipped mode=audit
! darwin backend pf not active; compiling dry-run rules
→ sent heartbeat: mode=audit ips=[10.0.10.23]

Settings

Token management and dashboard configuration
API Authentication

API requests require an admin token when enforced. Set your token below to enable authenticated requests.

Login timeoutcustomer session control

Choose how long this browser keeps an admin session before requiring sign-in again. This customer setting is enforced by the dashboard even if the server token has not expired yet.

minutes
Backup / Restorecustomer configuration JSON

Export policies, honeyports, and policy group containers. Restore validates JSON and upserts supported customer configuration.