# Root Lock Firewall

> A closed appliance that watches real traffic on this box, lets you approve a finite allowlist, and seals it. Prototype documentation.

---

LLMS index: [llms.txt](/llms.txt)

---

---

*Root Lock Firewall | Prototype*

---

> **Prototype**: Root Lock Firewall is under active development. Documentation reflects current design intent and is subject to change.

**Overview**: An inbound port that nobody approved is open by default. Root Lock Firewall is the host-path packet filter on a closed HeartSuite appliance: observe real traffic, approve a finite allowlist, seal it.

The workload runs on the image. Packets are judged by connection state.

Execution, files, and per-program outbound destinations stay [Root Lock by HeartSuite](../rootlock/). Root Lock is the hardened operating system under the filter.

If execution control or per-program outbound allowlisting on an existing server is the requirement, stay with [Root Lock](../rootlock/) and the OS or cloud inbound control already on that host. See [Deployment scenarios](deployment-scenarios/) for fit by environment.

## Learn about Root Lock Firewall

- [Introduction and overview](introduction/) — Core concepts, the inbound and host-path problem, and how Root Lock Firewall differs from Root Lock.
- [Architecture and compatibility](architecture/) — Closed image, Linux netfilter on the nft path, and what sits under the filter.
- [Deployment scenarios](deployment-scenarios/) — Where the appliance fits, where it fits alongside Root Lock, and where a campus NGFW still belongs.
- [How Root Lock Firewall compares](how-it-compares/) — Host-shaped sealed allowlist versus campus NGFW blades, and the complementary tools for each gap.
- [Recent firewall campaigns](examples/) — What Cisco and Fortinet incidents in 2024–2026 depended on, and which of those surfaces stay off this appliance.
- [Roadmap](roadmap/) — Current prototype scope and planned development.

## About this documentation

*Covers Root Lock Firewall prototype. Root Lock remains the shipped kernel product; its inbound language is unchanged.*

---

Section pages:

- [Inbound default-accept is the other Unix inheritance](/firewall/introduction/): Root Lock allowlists per-program outbound. Root Lock Firewall is the host-path stateful filter for a closed appliance.
- [Where a host-shaped firewall belongs](/firewall/deployment-scenarios/): When Root Lock Firewall fits, when it sits beside Root Lock, and when a campus NGFW is still the right box for the edge.
- [What sits under a closed firewall image](/firewall/architecture/): Root Lock Firewall is a closed image: a stateful host filter on Linux netfilter (nft). What is in the box.
- [What Cisco and Fortinet incidents needed to exist](/firewall/examples/): 2024–2026 Cisco and Fortinet campaigns depended on management planes and extra services. Root Lock Firewall is designed without those surfaces.
- [A sealed host filter beside a campus NGFW](/firewall/how-it-compares/): What Root Lock Firewall is, what it complements, and why it sits beside a campus NGFW rather than replacing one.
- [What the firewall prototype covers today](/firewall/roadmap/): Current Root Lock Firewall prototype scope and the development work still ahead.
