Mac firewall guides
Fix a network extension that will not run
An approved network extension and an enabled content filter are separate parts of setup. Check both before assuming a rule is broken.
Updated
Step by step
- Confirm the app location. Keep Outbound.app in Applications and open that copy. macOS activates the network extension only from the Applications folder.
- Inspect extension status. Open Terminal and run systemextensionsctl list. Look for Outbound’s extension identifier, com.outboundfirewall.outbound.filter, and record its state.
- Review system approval. Open System Settings and search for Network Extensions. On newer systems this is under General → Login Items & Extensions. Follow the app’s approval prompt on your macOS version.
- Check the filter configuration. Open Network → Filters or VPN & Filters. Confirm that the Outbound content filter is present and enabled. Extension approval alone does not establish that filtering is active.
- Read Outbound status. Run outboundctl status and compare it with System Settings. If the result is unknown or not configured, send the status and macOS build to support, or use Help › Report a Problem, rather than repeatedly reinstalling.
Managed Macs need a different path
A configuration profile can approve an extension, configure the filter and restrict removal. Check the installed MDM payloads and signing identifiers. Apple’s system-extension MDM documentation describes the management controls.
Do not disable platform protections
Turning off System Integrity Protection is not an installation step for Outbound. If the extension cannot activate, download a fresh copy of the signed, notarized DMG from the download page and contact support.
What status can and cannot prove
outboundctl status reports filter configuration and the rule count. It is not a complete end-to-end traffic test. Confirm with a controlled new connection and a monitor entry once setup is complete.
systemextensionsctl list
outboundctl statusOutbound instructions are based on Outbound 1.0 and its command-line help. Download Outbound. External product and platform sources are linked beside the relevant guidance.