Mac firewall guides
Mac firewall settings: incoming connections and options
Mac firewall settings are in System Settings → Network → Firewall. Turn it on to control incoming connections, then use Options to choose which apps may receive them. These settings do not block outgoing connections.
Updated
Step by step
- Open Firewall settings. Open the Apple menu, choose System Settings, click Network in the sidebar, then Firewall. Scroll down if needed.
- Turn the firewall on or off. Turn on Firewall to enable incoming connection controls. To turn it off, use the same switch. For troubleshooting, note its original state so you can restore it.
- Review the automatic permissions. Click Options. Review Block all incoming connections and the separate automatic permissions for built-in software and downloaded signed software. The choices are explained below.
- Allow or block an app. Under the app and service list, click the add button and select the app. Use its up and down arrows to choose whether to allow or block incoming connections.
- Choose stealth mode and save. Enable stealth mode if you want the Mac to ignore probing requests. Click OK to save the options. Test any service you need to reach from another computer.
- Check the status in Terminal. Run /usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate. It reports whether the built-in firewall is enabled. This checks the global switch, not each app permission.
Where are Mac firewall settings, and how do you turn them on or off?
Open System Settings → Network → Firewall to turn the built-in firewall on or off.
Turn on Firewall, then click Options to configure it. Options is unavailable while Firewall is off. Use the switch again to turn it off. Apple’s firewall setup guide covers the setting and app permissions.
What do the firewall options do?
The options decide how much incoming traffic to allow.
- Block all incoming connections: blocks incoming connections to non-essential apps and services. Basic Internet services remain available, but other sharing services are blocked.
- Automatically allow built-in software to receive incoming connections: adds built-in apps and services signed by a valid certificate authority to the allowed list without asking you.
- Automatically allow downloaded signed software to receive incoming connections: does the same for downloaded apps and services with valid signatures.
Choose these permissions based on the services you need to use. Apple’s Firewall options guide explains each control. The two automatic permissions concern incoming access, not permission to contact websites.
How do you allow or block incoming connections for one app?
Add the app in Options, then choose whether to allow or block its incoming connections. Use the add button below the app and service list, select the app, and use the arrows beside its entry to change the permission.
This is an incoming permission. It will not stop the app contacting a remote server. After changing it, test the service from another computer if you need that access. Apple’s app permission instructions show the controls.
What does stealth mode change?
Stealth mode makes your Mac ignore probing requests such as ping and connection attempts to closed TCP or UDP ports. It is a setting for reducing responses to probes, not a way to block an app’s outgoing traffic.
With Firewall on, click Options, turn on Enable stealth mode, then click OK. Apple’s stealth mode guide explains the setting.
How do you check firewall status from Terminal?
Run /usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate to check whether the built-in firewall is enabled.
/usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstateThe command reads the global state; it does not change it or list each app’s permission. For Apple’s local command help, run /usr/libexec/ApplicationFirewall/socketfilterfw -h. You can also check the switch in Firewall settings.
When is an outbound firewall the right tool?
Use an outbound firewall when you want to decide which remote destinations an app may contact. The built-in settings above control incoming access; they do not provide outgoing app and destination rules. Apple’s firewall security guide lists the incoming controls.
Turning on Block all incoming connections will not keep an app offline. See whether the macOS firewall blocks outgoing connections and how to block an app’s internet access before choosing another tool.
Outbound instructions are based on Outbound 1.0 and its command-line help. Download Outbound. External product and platform sources are linked beside the relevant guidance.