Inbound default-accept is the other Unix inheritance
Root Lock allowlists per-program outbound. Root Lock Firewall is the host-path stateful filter for a closed appliance.
Root Lock Firewall | Prototype
Prototype: Root Lock Firewall is under active development. Documentation reflects current design intent and is subject to change.
An inbound port that nobody approved is open by default on a general-purpose server. Scanners find it. Login services see unsolicited attempts. The operating system will accept a connection on any listening socket unless a packet filter refuses it first.
Root Lock Firewall is that packet filter, delivered as a closed virtual appliance. It watches real traffic on this box, you approve a finite allowlist, and Firewall Lockdown seals what you approved. Packets are judged by connection state. The workload runs on the image. The appliance is not an NGFW, not a proxy, not a cloud firewall service, and not an inline box you place in front of another server.
Root Lock Firewall does not decide which programs may execute, which files they may read or write, or which outbound destinations each program may reach. Those are Root Lock by HeartSuite’s domain. Packets this box sends and receives are still this filter. Root Lock sits under the firewall as the hardened operating system. It is not itself a firewall.
If the requirement is execution control or per-program outbound allowlisting on an existing server, Root Lock Firewall is not the right fit on its own. See Deployment scenarios for fit and non-fit by environment.
Covers Root Lock Firewall prototype. Root Lock remains the shipped kernel product; its inbound language is unchanged.
Root Lock allowlists per-program outbound. Root Lock Firewall is the host-path stateful filter for a closed appliance.
When Root Lock Firewall fits, when it sits beside Root Lock, and when a campus NGFW is still the right box for the edge.
Root Lock Firewall is a closed image: a stateful host filter on Linux netfilter (nft). What is in the box, and what you do not get to reconfigure.
2024–2026 Cisco and Fortinet campaigns depended on management planes and extra services. Root Lock Firewall is designed not to ship those.
What Root Lock Firewall is, what it is not, what it complements, and why it sits beside a campus NGFW rather than replacing one.
Current Root Lock Firewall prototype scope, what is intentionally not in the image, and the development work still ahead.
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.