Skip to content
Join the waitlistWaitlist

Network footprint and the firewall rule

Every connection Guard makes, which ones are optional, how to see them, and a firewall rule that enforces them.

ConnectionDirectionWhenDefault
api.hyperliquid.xyz:443 (HTTPS, WebSocket)outpaper and mainnet: prices, account, orderson
api.hyperliquid-testnet.xyz:443outtestneton in testnet only
DNSoutto resolve the aboveon
127.0.0.1:8547in, from your machineyour boton
the relay (WebSocket)outTradingView alerts, browser Guardoff
telemetry heartbeat (version, venue, number of vetoes)outcounting installsoff

Nothing else. No update check, no crash reporter, no analytics. The relay and telemetry are off until you switch them on in guard.toml.

Zunder’s own executor already behaves this way on the trading side: it goes to the configured network’s URL only, refuses plain HTTP and follows no redirects (docs/testnet.md).

Terminal window
# Linux
sudo ss -tnp | grep zunder-guard
# macOS
sudo lsof -nP -i -a -c zunder-guard

The installer runs Guard as its own user, zunder-guard. With nftables, that user may reach DNS and port 443, and nothing else:

Terminal window
sudo nft add table inet zunder
sudo nft add chain inet zunder out '{ type filter hook output priority 0; }'
sudo nft add rule inet zunder out meta skuid zunder-guard oif lo accept
sudo nft add rule inet zunder out meta skuid zunder-guard udp dport 53 accept
sudo nft add rule inet zunder out meta skuid zunder-guard tcp dport 53 accept
sudo nft add rule inet zunder out meta skuid zunder-guard tcp dport 443 accept
sudo nft add rule inet zunder out meta skuid zunder-guard counter drop

The counter on the last rule counts every packet Guard tried to send elsewhere. It should stay at zero:

Terminal window
sudo nft list chain inet zunder out

What this does not prove. A port rule cannot tell api.hyperliquid.xyz from any other server on port 443. Hyperliquid’s addresses are not published as fixed, so pinning IPs is fragile. To restrict by hostname, put Guard behind an allow-listing proxy, or use an application firewall (on macOS, for example, LuLu or Little Snitch) with a rule for zunder-guard that allows only Hyperliquid’s hostnames.

Guard opens no port to the outside. If ss -tlnp shows Guard listening on anything but 127.0.0.1 (or the private address you configured), stop it and check guard.toml.

This page as plain Markdown, for people and LLMs: /docs/deploy/network-footprint.md