Firewalls
Network policy enforced on every workload
Code with unrestricted network access is a liability, and integrations often run code you didn't write. Metorial's virtual firewalls put a network policy in front of every integration and MCP server, controlling inbound and outbound traffic so each workload reaches only approved destinations, malicious traffic is blocked, and everything on the wire is recorded.
- 01
Enforce ingress and egress rules.
Per-workload firewall rules control which hosts and endpoints an integration can send to and receive from. Traffic is allowlisted rather than open by default.
- 02
Block exfiltration and lateral movement.
Egress filtering stops compromised or malicious code from reaching unauthorized destinations. A single bad workload can't leak data or pivot into other systems.
- 03
Inspect and record traffic.
All network activity is monitored and logged, giving you the detailed traffic visibility needed for security investigations and compliance.
What firewalls cover
Network policy on every workload
- Traffic governedIngress and egress
- Default postureAllowlist
- Applies toEvery integration and MCP server
- TrafficInspected and logged
Set the network policy. Allowlist every destination. Block exfiltration. Inspect all traffic.
FAQ
Answers to common questions about firewalls and how they fit into governed AI agent infrastructure.
What do Metorial firewalls do?
They're virtual firewalls that enforce network policy on every integration and MCP server, governing inbound and outbound traffic so each workload can only communicate with the hosts and endpoints you allow.Can I set firewall rules per workload?
Yes. Rules can be configured per integration or MCP server. Each one's network access matches what it actually needs instead of a single shared policy.Do firewalls support egress filtering?
Yes. Outbound traffic is governed by allowlist rules. An integration can't reach unauthorized destinations. This is what blocks data exfiltration and lateral movement if code is compromised.Is network traffic inspected and logged?
Yes. All network activity is monitored and recorded, giving you traffic visibility for security investigations and compliance auditing.How do firewalls relate to enclaves?
Enclaves provide the isolated runtime, and firewalls enforce the network policy around it. Process isolation and network control work together as one boundary.Do firewalls apply to custom and third-party servers?
Yes. Firewall rules govern network access for first-party integrations, custom MCP servers, remote MCP servers, and Docker MCP servers, including code you didn't write.
