Mac firewall guides

Does the macOS firewall block outgoing connections?

No. The macOS Firewall settings control incoming connections. They do not provide a per-app outbound destination allowlist.

Updated

Incoming and outgoing are different decisions

An incoming connection starts elsewhere and reaches a service on your Mac. An outgoing connection starts with a process on your Mac contacting a destination. Apple’s Firewall settings guide explains the incoming settings.

What an outbound firewall adds

Outbound combines the process identity with a host, domain, IP address or network range. Rules can also specify ports, protocol, direction and lifetime. That lets an app reach one service while denying another.

A hostname is available when the app connected by name. When the filter receives only an address, the rule and monitor must work with that address.

Where pf fits

pf is a packet-filtering facility with a rules language for network traffic. Its job differs from a graphical list of app decisions. Do not confuse a port or IP block with a rule that identifies one signed application.

Use the control that answers the question

  • Control access to a service on your Mac: review the built-in firewall.
  • Choose where one app may connect: use an outbound app firewall.
  • Administer a network policy: evaluate a packet filter or managed content filter and test it first.

You can keep Apple’s incoming firewall enabled while evaluating an outbound tool. Running multiple third-party content filters needs separate compatibility testing.

Outbound instructions are based on Outbound 1.0 and its command-line help. Download Outbound. External product and platform sources are linked beside the relevant guidance.