Whonix consists of two virtual machines: the Whonix-Gateway that routes all traffic through Tor, and the Whonix-Workstation where the user runs applications. The workstation cannot make direct internet connections because it has no route to the internet except through the gateway VM. Applications in the workstation that attempt to connect directly to the internet find no route and fail. This VM-based network isolation is hardware-enforced (by the VM boundary) rather than software-enforced (by iptables rules that can be misconfigured).
Whonix is persistent: data survives reboots and is stored on disk like a normal operating system. This persistence is valuable for hidden service operations that require maintaining onion keys, configuration files, and long-term state. Persistent storage allows operators to build up an operational environment over time without starting from scratch at each session.
The risk of persistence is that disk forensics on a seized device reveals accumulated operational history. Whonix with encrypted persistent storage (using LUKS) mitigates this by requiring decryption at boot, but the data exists on disk and is recoverable by anyone with the encryption key.