# Policy configuration Policies can be used to block or allow traffic from one zone to another. They specify default actions for when there are no matching [rules](rules.md) for specific types of traffic. The implicit default policy is to drop all zone-to-zone traffic. A simple policy definition file looks like this: ```yaml --- # Example policy: Accept all traffic from firewall to the "lan" zone - source: fw dest: lan policy: accept # Disallow forwarding traffic from "dmz" to "lan" # by dropping all traffic and logging the event. - source: dmz dest: lan policy: drop log: true ```