A listener will accept a stranger by default
Inbound default-accept is a different OS assumption from Root Lock’s outbound allowlist. How HeartSuite Firewall addresses that hole.
HeartSuite Firewall | Prototype
Overview: A listening service on a Linux host accepts inbound connections unless a packet filter refuses them. HeartSuite Firewall is that filter on a closed HeartSuite appliance: observe real traffic, approve a finite allowlist, seal it.
Root Lock controls outbound destinations per program, at the kernel, using literal IP addresses. The two products address different layers and are designed to be used together on the appliance image.
Inbound default-accept is a different OS assumption from Root Lock’s outbound allowlist. How HeartSuite Firewall addresses that hole.
Host-shaped stateful filter on a closed appliance: observe real traffic, approve a finite allowlist for this box, then seal it. Root Lock is the OS under the filter.
HeartSuite Firewall’s packet boundary, residuals, and which tool to put beside it for those gaps.
From first boot to Firewall Lockdown: observe, approve, seal. The intended Dashboard path on a HeartSuite Firewall appliance.
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.