The Mac firewall: what it blocks and how to see it from the menu bar

The question that brings most people here is whether the Mac firewall is worth turning on, and the answers found in forums split cleanly into two camps that never engage with each other. One says to turn it on because a firewall is basic hygiene. The other says a Mac behind a router has nothing listening anyway, so the switch is theatre.

Both are arguing about a feature whose scope is narrower than either side assumes. The macOS firewall is an inbound filter for applications, and once that is clear, the disagreement mostly dissolves into a question about which networks a particular Mac spends its time on.

One direction only

Apple's description of the feature is specific about what it is for, and the word incoming does most of the work.

A firewall can protect your Mac from unwanted contact initiated by other computers when you're connected to the internet or a network. However, your Mac can still allow access through the firewall for some services and apps. Source: support.apple.com, read September 28, 2026

Nothing a Mac sends out is affected by this setting. An app that phones home, a tracker embedded in a page, a piece of software checking a licence server, all of that passes regardless. That single fact settles a large share of the arguments, because the people who say the firewall does nothing useful are often thinking about outbound traffic, and the people who say it is essential are often imagining it filters both directions.

The same page names the two ways traffic gets in even with the firewall on. Turning on a sharing service causes macOS to open a specific port for it, and an app or service on another machine can be granted access, or be allowed because it carries a trusted certificate. The firewall is therefore not a wall with a switch, but a list with defaults.

The pane lives in System Settings under Network, then Firewall, and Apple's own instructions elsewhere begin by saying to turn it on first if it is off, which is a reasonable hint that plenty of Macs are running without it.

The five settings that actually decide anything

Everything meaningful is behind the Options button, and Apple's descriptions are worth having side by side rather than discovered one at a time.

Setting What Apple says it does
Block all incoming connections Prevent incoming connections to nonessential services and apps
Add and Remove Add or remove an app or service from the allowed list
Automatically allow built-in software Allow built-in apps signed by a valid certificate authority to be added to the allowed list without your authorization
Automatically allow downloaded signed software Allow downloaded apps signed by a valid certificate authority to be added without your authorization
Enable stealth mode Prevent the Mac from responding to probing requests that can be used to reveal its existence

The two automatic allow settings are the reason turning the firewall on so often changes nothing observable. Any signed application, including software downloaded from anywhere, can add itself to the allowed list without a prompt while those are on. Turning the firewall on and leaving them on produces a firewall that says yes to nearly everything that asks politely.

Apple also warns that the list is not the whole picture.

Certain apps that don't appear in the list may have access through the firewall. These can include system apps, services, and processes, as well as digitally signed apps that are opened automatically by other apps. To block access for these programs, add them to the list. Source: support.apple.com, read September 28, 2026

An empty or short list is therefore not evidence that nothing is allowed. It is evidence that nothing has been explicitly decided.

When an alert appears, and when one does not

There is one interactive behaviour worth expecting. When macOS detects an attempt to reach an app that has not been added and allowed, an alert asks whether to allow or deny the connection, the message stays until it is answered, and connection attempts are denied in the meantime.

That alert only happens for software the automatic allow settings do not cover. Turning both of those off is what converts the firewall from a passive list into something that asks, and it is the change that makes the feature visible in daily use. It also produces a run of prompts for a week or two while the common cases get decided, which is the cost of the arrangement and the reason most people leave the defaults alone.

Block all incoming connections, and what it costs

This is the setting people reach for when travelling, and it is worth knowing what survives it. Apple's description is that it prevents incoming connections to nonessential services and apps, and it draws a specific line: basic internet services, a set of apps that let the Mac find services provided by other computers on the network, keep working, while connections to all other sharing services are prevented.

In practice that means a Mac with this on stays usable on a network but stops being reachable on it. File sharing, screen sharing and printer sharing all stop accepting connections. Anything that expects to reach the Mac by name from another device stops finding it.

Apple adds one piece of advice that is easy to skip and worth following. Shared services can connect through the firewall when they are turned on in Sharing settings, and for additional security the service itself can be turned off there. Turning a sharing service off in Sharing settings is stronger than blocking it at the firewall, because it removes the listener instead of guarding it.

Stealth mode is about being found, not about being safe

Stealth mode is the setting most often turned on for the wrong reason. Apple's description of it is precise.

When stealth mode is on, your Mac doesn't respond to either "ping" requests or connection attempts from a closed TCP or UDP network. Source: support.apple.com, read September 28, 2026

The settings reference adds that the Mac still answers requests from authorized apps, while unauthorized requests such as an ICMP ping get no response. So the change is to scanning and discovery rather than to access. A port that was closed was already refusing connections. With stealth mode on it stops replying at all, which makes the Mac harder to enumerate on an unfamiliar network and slightly harder to troubleshoot on a familiar one, since a ping from another machine will simply fail.

For a laptop used on hotel and conference networks this is a sensible default. For a desktop on a home network where other devices need to find it, it adds friction for no gain.

The list that matters more than this one

Because the firewall guards listeners rather than removing them, the more consequential pane is Sharing, and Apple points at it from inside the firewall documentation itself. Each service switched on there is a process waiting for connections, and each one causes macOS to open a port for it.

That reframes the question usefully. A Mac with nothing turned on in Sharing has almost nothing for an inbound filter to protect, which is exactly the situation the people who call the firewall unnecessary are describing. A Mac with screen sharing, file sharing and remote login switched on has three doors, and the firewall is then deciding who may knock on them.

Remote Login deserves a specific mention because it has grown in importance. On a Mac with Apple silicon running macOS 26 or later, Apple's deployment documentation states that FileVault can be unlocked over ssh after a restart when Remote Login is turned on and a network connection is available. That is a genuinely useful capability for a machine that lives in another room, and it is also a listener that accepts connections before anyone has logged in. Anyone enabling it should be deliberate about the firewall settings around it rather than treating the two panes as unrelated.

The general rule is worth stating plainly. Turn a service off when it is not needed, and use the firewall for the services that have to stay on. Blocking a running service is weaker protection than not running it, and it is easier to forget.

Reading the state without a window

The firewall pane shows a switch and a list, and nothing else. There is no status menu for it: macOS documents which items can appear in the menu bar, and the firewall is not among them. Nothing at the top of the screen reports whether it is on, whether stealth mode is active, or whether anything has been denied.

What does exist is a command line tool, socketfilterfw, which lives in /usr/libexec/ApplicationFirewall/ rather than on the normal path. Its own usage text lists a matched pair of read and write flags for every setting in the pane: --getglobalstate and --setglobalstate, --getblockall and --setblockall, --getstealthmode and --setstealthmode, plus --listapps to print the allowed list, --getappblocked to ask about one path, and --getallowsigned and --setallowsignedapp for the two automatic allow settings. There is also --getloggingmode and --setloggingmode, which is the only route to a record of what the firewall has been doing.

One clarification, because it comes up whenever the command line enters the conversation. macOS also ships pf, a packet filter with its own control tool pfctl, described in its manual page as restricting the types of packets that pass through network interfaces entering or leaving the host based on filter rules. That is a different, lower level mechanism, and it is not what the Firewall pane configures. Rules written for one are invisible to the other, which is why advice mixing the two tends to produce a Mac where neither is doing what its owner believes.

What can be seen from the menu bar

Since macOS puts nothing up there for the firewall, anything that reports network state in the menu bar is third party, and the tools that do it are mostly concerned with the direction the built in firewall ignores. Outbound connection monitors add a status item precisely because the interesting traffic is the traffic leaving, and a Mac with one installed usually has another icon or two beside it from a VPN client or a network utility. A look at how those resident tools differ is a separate exercise, but they share one property: they are only useful if their icon is actually visible.

Two built in controls help with arranging that, and they are worth knowing before installing anything. Holding Command and dragging a status menu icon moves it along the bar. Holding Command and dragging it out of the bar removes it. Those apply to the system's own items, and they run out of room quickly on a laptop where the notch takes a bite out of the available width.

What to change first

Decide which networks the Mac actually joins. A desktop that only ever sees one trusted home network gains very little from this pane, while a laptop that joins hotel and café networks should have the firewall on and stealth mode on, and should have unused services turned off in Sharing settings rather than merely blocked. Then remember what the setting does not cover, because outbound traffic needs a different tool entirely, and the icon that tool puts in the menu bar is only worth having if Koffret keeps it in sight.

Frequently asked questions

Should I turn the Mac firewall on if I am behind a router?

A router already blocks unsolicited inbound traffic from the internet, so on a home network the firewall adds little. It starts to matter the moment the Mac joins a network shared with strangers, because then other devices on the same network can reach it directly and the router is not in the way.

Does the Mac firewall stop apps from sending data out?

No. It filters incoming connections only. Anything an app chooses to send leaves the Mac regardless of the setting, which is why outbound monitoring is handled by separate software rather than by this pane.

Why does turning the firewall on not seem to change anything?

Because two settings behind the Options button allow built in software and downloaded signed software to add themselves to the allowed list without asking. With both on, most software is permitted silently. Turning them off is what makes the firewall start prompting.

What breaks if I turn on Block all incoming connections?

Sharing services stop accepting connections, so file sharing, screen sharing and printer sharing become unreachable, and other devices stop finding the Mac by name. Apple notes that a set of basic internet services, which let the Mac find services offered by other computers, keeps working.

How do I check the firewall state from the Terminal?

The tool is socketfilterfw, in /usr/libexec/ApplicationFirewall/, and it has read flags matching every setting in the pane, including --getglobalstate, --getblockall, --getstealthmode and --listapps. It is not the same as pfctl, which controls the separate pf packet filter and is not what the Firewall pane configures.

Back to all posts