Inbound default-accept is the other Unix inheritance
Root Lock allowlists per-program outbound. Root Lock Firewall is the host-path stateful filter for a closed appliance.
Root Lock Firewall | Prototype
Prototype: Root Lock Firewall is under active development. Documentation reflects current design intent and is subject to change.
Overview: An inbound port that nobody approved is open by default. Root Lock Firewall is the host-path packet filter on a closed HeartSuite appliance: observe real traffic, approve a finite allowlist, seal it.
The workload runs on the image. Packets are judged by connection state.
Execution, files, and per-program outbound destinations stay Root Lock by HeartSuite. Root Lock is the hardened operating system under the filter.
If execution control or per-program outbound allowlisting on an existing server is the requirement, stay with Root Lock and the OS or cloud inbound control already on that host. See Deployment scenarios for fit by environment.
Covers Root Lock Firewall prototype. Root Lock remains the shipped kernel product; its inbound language is unchanged.
Root Lock allowlists per-program outbound. Root Lock Firewall is the host-path stateful filter for a closed appliance.
When Root Lock Firewall fits, when it sits beside Root Lock, and when a campus NGFW is still the right box for the edge.
Root Lock Firewall is a closed image: a stateful host filter on Linux netfilter (nft). What is in the box.
2024–2026 Cisco and Fortinet campaigns depended on management planes and extra services. Root Lock Firewall is designed without those surfaces.
What Root Lock Firewall is, what it complements, and why it sits beside a campus NGFW rather than replacing one.
Current Root Lock Firewall prototype scope and the development work still ahead.
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.