# How to Use FireJail to Sandbox Linux Applications: Complete Setup Guide

> Learn how to use FireJail to sandbox Linux applications. This guide provides a complete setup for running programs in secure, restricted environments with ease.

- Repository: [IMTheNachoMan/How-To-Secure-A-Linux-Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)
- Tags: how-to-guide
- Published: 2026-05-14

---

**FireJail is a lightweight sandboxing tool that leverages Linux namespaces, seccomp-BPF, and kernel hardening features to isolate applications, allowing you to run programs like Chrome or Firefox in restricted environments by simply installing the package and creating symlinks to the `firejail` wrapper.**

FireJail provides a practical approach to application isolation on Linux systems by combining kernel-level security mechanisms with easy-to-use profiles. According to the `imthenachoman/How-To-Secure-A-Linux-Server` repository, you can harden your server or desktop by sandboxing common applications without modifying the underlying programs. This guide explains how to use FireJail to sandbox Linux applications based on the implementation details found in the repository's README.md and supporting documentation.

## What Is FireJail and How Does It Work?

FireJail operates by launching target binaries under new Linux namespaces (mount, PID, network, IPC, and UTS) and applying seccomp-BPF filters to restrict system calls. As documented in the README.md section "Run applications in a sandbox with FireJail", the tool automatically blocks write access to most of the host filesystem, disables access to hardware devices, and restricts network communication when no explicit profile is supplied.

When you invoke FireJail, it reads application-specific profiles from `/etc/firejail/` that define filesystem access rules, capability restrictions, and network policies. If a profile is not explicitly supplied, FireJail applies a sensible default sandbox that still provides significant isolation from the host system.

## Installing FireJail and Community Profiles

The first step in sandboxing applications is installing FireJail along with the community-provided profiles package. These profiles contain pre-configured security policies for popular applications like Firefox, Chrome, and Thunderbird.

On Debian or Ubuntu systems, install the packages using:

```bash
sudo apt install firejail firejail-profiles

```

For Debian Buster users requiring newer features, install from the backports repository:

```bash
sudo apt install -t buster-backports firejail firejail-profiles

```

The `firejail-profiles` package installs security profiles to `/etc/firejail/`, providing immediate protection for common desktop programs without manual configuration.

## Configuring Automatic Sandboxing with Symlinks

The recommended workflow from the repository involves creating symbolic links that intercept calls to target applications and automatically route them through FireJail.

### Creating Symlinks for Common Applications

To sandbox Google Chrome automatically whenever it launches, create a symlink pointing to the FireJail wrapper:

```bash
sudo ln -s /usr/bin/firejail /usr/local/bin/google-chrome-stable

```

After creating this link, launching `google-chrome-stable` from the command line or desktop environment automatically invokes FireJail with the appropriate Chrome profile. The sandbox restrictions apply transparently without requiring users to change their launch habits.

### Running Applications Manually

You can also launch applications directly through FireJail without creating symlinks. To start Firefox with its default profile:

```bash
firejail firefox

```

For custom scripts or applications requiring specific restrictions, specify a profile explicitly:

```bash
firejail --profile=/etc/firejail/custom.profile myscript.sh

```

## Inspecting and Managing Active Sandboxes

FireJail provides several command-line options to monitor running sandboxes and verify applied restrictions.

To list all currently active sandboxes with their process IDs and applied profiles:

```bash
firejail --list

```

For a hierarchical view showing the parent-child relationships between sandboxes and their corresponding profiles:

```bash
firejail --tree

```

Before deploying a new profile in production, test it for syntax errors and policy conflicts using the dry-run option:

```bash
firejail --profile=/etc/firejail/gedit.profile --dry-run gedit

```

This validates that the profile parses correctly without actually launching the restricted environment.

## Integrating with System-Wide Security Hardening

FireJail works effectively alongside other hardening measures documented in the repository. The [`linux-kernel-sysctl-hardening.md`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main/linux-kernel-sysctl-hardening.md) file complements sandboxing by tightening kernel parameters that reduce the attack surface for any process attempting to escape isolation. Additionally, the [`nginx.md`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main/nginx.md) guide demonstrates how to combine FireJail with service-specific hardening techniques for web server applications.

## Summary

- FireJail uses Linux namespaces and seccomp-BPF to isolate applications from the host filesystem and network.
- Install FireJail and community profiles using `sudo apt install firejail firejail-profiles` to access pre-built security policies in `/etc/firejail/`.
- Create symlinks in `/usr/local/bin/` pointing to `/usr/bin/firejail` to automatically sandbox applications without changing user workflows.
- Use `firejail --list` and `firejail --tree` to monitor active sandboxes and verify profile application.
- Test profiles safely using the `--dry-run` flag before production deployment.

## Frequently Asked Questions

### What is FireJail used for?

FireJail is a SUID sandbox program that restricts the running environment of untrusted applications using Linux namespaces and seccomp-bpf. It prevents processes from accessing sensitive parts of the filesystem, restricts network capabilities, and limits system calls to reduce the attack surface of third-party software.

### How do I create a symlink to sandbox an application automatically?

Create a symbolic link in `/usr/local/bin/` that points to `/usr/bin/firejail` and name it after the target application binary. For example: `sudo ln -s /usr/bin/firejail /usr/local/bin/google-chrome-stable`. When users launch the application, the system calls the FireJail wrapper first, which then applies the appropriate security profile.

### Where are FireJail profiles stored?

FireJail profiles are stored in the `/etc/firejail/` directory when installed via the `firejail-profiles` package. Each profile corresponds to a specific application (e.g., `firefox.profile`, `chrome.profile`) and defines filesystem access rules, network restrictions, and capability limitations for that program.

### Can I test a FireJail profile before running it?

Yes, use the `--dry-run` option to validate a profile without actually launching the sandbox. For example: `firejail --profile=/etc/firejail/custom.profile --dry-run myscript.sh`. This checks for syntax errors and policy conflicts while displaying the restrictions that would be applied.