This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

What the firewall prototype covers today

Current HeartSuite Firewall prototype scope and the development work still ahead.

    Prototype: HeartSuite Firewall is under active development.

    Current capabilities

    The table below is the prototype contract for the appliance image: the intended observe → approve → seal path through the Dashboard, Firewall Rules, Firewall Lockdown, and Maintenance. It describes design scope rather than a generally available feature list.

    CapabilityNotes
    Closed virtual applianceQCOW2 and OVA. Console or serial first. Delivery is the closed image.
    Host-shaped stateful filterINPUT/OUTPUT of this box. Workload on the image. Linux netfilter, nft path.
    Observation → approve → sealDashboard Firewall Rules queue. Typed YES. Firewall Lockdown is a paired commitment with Root Lock Lockdown; the Dashboard does not run both.
    Read-only inventory after sealMutate keys absent. Maintenance is the change path.
    HeartSuite as update authorityOnce sealed, the filter fetches nothing from a public CDN or reputation feed.
    Root Lock underneathExecution, files, and per-program outbound IPs remain Root Lock by HeartSuite — the kernel product.

    See Architecture and compatibility for the nft-path constraint and the virtual-appliance residual.

    Planned

    Next

    ItemNotes
    Demonstration roundtripObservation → review → seal → inventory → maintenance on a real KVM image. This documentation stays Prototype until that roundtrip exists.
    Image as the only customer pathCustomers receive the closed image; install scripts stay a laboratory tool.

    Subsequent

    ItemNotes
    Hardware applianceSame inspection class: host-shaped stateful filter. Removes the hypervisor residual.
    Edge SKUFORWARD/NAT, box in front of other hosts. Changes placement. Inspection stays stateful host filtering unless application inspection is added later.
    Self-rendered nftablesCandidate only. Would keep the same product class (stateful host filter) and could make the seal hashable.

    Product identity stays a sealed host-shaped stateful filter. App-ID catalogs, TLS interception, URL clouds, sandbox blades, SD-WAN, SASE, SSL-VPN concentrator, cloud firewall / FWaaS, proxy / WAF, a vendor-panel replacement, and UFW as a second manager stay outside that identity.