Inbound default-accept is the other Unix inheritance
Root Lock allowlists per-program outbound. HeartSuite Firewall is the host-path stateful filter for a closed appliance.
HeartSuite Firewall | Prototype
Prototype: HeartSuite Firewall is under active development. Documentation reflects current design intent and is subject to change.
Overview: An inbound port that nobody approved is open by default. HeartSuite Firewall is the packet filter for traffic to and from a closed HeartSuite appliance: you observe real traffic, approve a finite allowlist, and seal it. The workload runs on the appliance image itself, and the filter judges packets by connection state.
Root Lock by HeartSuite is the hardened operating system under the filter, so execution, file access, and per-program outbound destinations stay under Root Lock’s control.
If execution control or per-program outbound allowlisting on an existing server is the requirement, stay with Root Lock and the OS or cloud inbound control already on that host. See Deployment scenarios for fit by environment.
Covers the HeartSuite Firewall prototype. Root Lock remains the shipped kernel product, and what the Root Lock pages say about inbound traffic still applies to it.
Root Lock allowlists per-program outbound. HeartSuite Firewall is the host-path stateful filter for a closed appliance.
When HeartSuite Firewall fits, when it sits beside Root Lock, and when a campus NGFW is still the right box for the edge.
HeartSuite Firewall is a closed image: a stateful host filter on Linux netfilter (nft). What is in the box.
2024–2026 Cisco and Fortinet campaigns depended on management planes and extra services. HeartSuite Firewall is designed without those surfaces.
What HeartSuite Firewall is, what it complements, and why it sits beside a campus NGFW rather than replacing one.
Current HeartSuite Firewall prototype scope and the development work still ahead.
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.