Local OS Firewall (Guard)
Integration & Setup Manual
Local OS Firewall (Guard) Integration Guide
Overview
The Local OS Firewall Guard provider orchestrates the device-resident OS firewall — Windows Defender Firewall / WFP on Windows, nftables/iptables on Linux, and pf on macOS — directly through the Cup’n’String agent. This is the deepest, most immediate enforcement layer: rules are applied at kernel level on the device, per-process isolation is supported, and enforcement works offline when the agent cannot reach the Guard control plane.
This provider wraps the three native OS firewall integrations (macOS pf, Windows WFP, Linux nftables) under a unified Guard policy model, making it possible to push the same AI tool outbound policy across mixed-OS developer fleets from a single Guard rule set.
Support level
Kernel-Level Enforcement — device-resident, per-process, fail-closed. Offline local enforcement. Authenticated device communication.
Recommended Guard mode
Review the platform prerequisites and policy outcomes before enabling enforcement.
Known limitations
- Per-process enforcement scopes rules to process owner (UID/GID) and port — full PID-level rules require the agent to be running with kernel extension or eBPF support.
- On macOS, System Integrity Protection (SIP) limits some pf configurations. Confirm platform prerequisites with your administrator.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix