default or selected kernelversion does not have config value CONFIG_IP_NF_MATCH_POLICY.
Result is shown for kernelversion 5.2.15

IPsec policy match support

modulename: ipt_policy.ko

configname: CONFIG_IP_NF_MATCH_POLICY

Linux Kernel Configuration
└─>Networking
└─>Networking options
└─>Network packet filtering (replaces ipchains)
└─>IP: Netfilter Configuration
└─>IPsec policy match support
In linux kernel since version 2.6.16 (release Date: 2006-03-19)  
Policy matching allows you to match packets based on the
IPsec policy that was used during decapsulation/will
be used during encapsulation.

To compile it as a module, choose M here. If unsure, say N.

source code: