> ## Documentation Index
> Fetch the complete documentation index at: https://docs.boat.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Firewall rules inside a sandbox

> Add firewall rules in a sandbox without blocking Boat's agent or tunnel.

You have root, so you can add any firewall rule. Boat reaches the sandbox in two ways. A rule that blocks either one marks the sandbox degraded.

| What | Protocol | Runs as |
| - | - | - |
| Boat agent (commands, snapshots, health) | TCP port 8911 | `user` |
| Tunnel for HTTPS URLs and the agent | WireGuard, outgoing UDP to the address in `sudo wg show wg0 endpoints` | kernel, but carries packets from `user` processes |

## Block outgoing UDP for `user`

Linux tags a tunnel packet with the process that sent the data inside it. So an owner rule on `user` also blocks the tunnel.

To block outgoing UDP for `user` and keep Boat working, allow the tunnel endpoint first.

```bash theme={null}
WG=$(sudo wg show wg0 endpoints | awk '{print $2}' | cut -d: -f1)
sudo iptables -I OUTPUT 1 -m owner --uid-owner user -p udp ! -d 127.0.0.0/8 -j REJECT
sudo iptables -I OUTPUT 1 -p udp -d "$WG" -j ACCEPT
```

## What happens to a blocked sandbox

Boat never stops a sandbox for this, or marks it `error`, if it answers on any route. Instead:

* The sandbox shows `"health": "degraded"` with a reason.
* Boat sends a [`sandbox.degraded`](/webhooks#events) webhook.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.