Cup'n'String
Join Waitlist

© 2026 Cup'n'String

All Guides/Local OS Firewall (Guard) Guide
LO

Local OS Firewall (Guard)

Integration & Setup Manual

Local OS Firewall (Guard) Integration Guide

Overview

The Local OS Firewall Guard provider orchestrates the device-resident OS firewall — Windows Defender Firewall / WFP on Windows, nftables/iptables on Linux, and pf on macOS — directly through the Cup’n’String agent. This is the deepest, most immediate enforcement layer: rules are applied at kernel level on the device, per-process isolation is supported, and enforcement works offline when the agent cannot reach the Guard control plane.

This provider wraps the three native OS firewall integrations (macOS pf, Windows WFP, Linux nftables) under a unified Guard policy model, making it possible to push the same AI tool outbound policy across mixed-OS developer fleets from a single Guard rule set.

Support level

Kernel-Level Enforcement — device-resident, per-process, fail-closed. Offline local enforcement. Authenticated device communication.

Review the platform prerequisites and policy outcomes before enabling enforcement.

Known limitations

  • Per-process enforcement scopes rules to process owner (UID/GID) and port — full PID-level rules require the agent to be running with kernel extension or eBPF support.
  • On macOS, System Integrity Protection (SIP) limits some pf configurations. Confirm platform prerequisites with your administrator.

Setup outline

  1. Confirm the supported platform and deployment requirements with your administrator.
  2. Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
  3. Review policy in your environment before enabling enforcement, then verify the intended access outcomes.

Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.

Integration Info

Support LevelKernel-Level Enforcement
CategoryFirewalls
Setup ComplexityLow
Governed Safeguards
Network

Links

Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.

Supported Environments Matrix