Mac firewall guides
Using a Mac firewall with a VPN or Private Relay
Test a firewall with the VPN and Private Relay configuration you actually use. Outbound has no published compatibility result for these combinations yet.
Updated
Step by step
- Record a working baseline. Write down the macOS build, VPN version and firewall version. Confirm normal browser and app connections before changing the setup.
- Test the content filter alone. With authorization, test the filter without the optional VPN or Private Relay path. Do not remove a required organization policy.
- Add the VPN. Connect the VPN and repeat browser, DNS lookup, SSH and app-specific tasks. Include an internal service if your VPN provides one.
- Test Private Relay separately. If you use Private Relay, test that configuration separately before combining it with a VPN. Record which change affects the symptom.
- Document the exact result. Save the version numbers and whether the connection succeeded. If a combination fails, restore the last working configuration and contact the relevant vendor.
A shared API does not prove shared behavior
Outbound uses Apple’s NEFilterDataProvider. Other products use related networking APIs, but their settings and extra components differ. Outbound v1 does not install a DNS proxy.
Testing is specific to a build
A working combination today is not a promise about the next operating-system or VPN update. Re-run the same checks after a change. See the published Outbound status; no pass result is implied by a minimum macOS version.
If you lose connectivity
In Outbound, Help › Network Not Working? shows the other network filters and VPNs macOS reports, a note about iCloud Private Relay, and Pause for 15 Minutes. Otherwise open System Settings → Network → Filters or VPN & Filters and disable the component under investigation. Ask IT for help on a managed Mac. Follow the recovery guide before making more changes.
Outbound instructions are based on Outbound 1.0 and its command-line help. Download Outbound. External product and platform sources are linked beside the relevant guidance.