# How to Turn On the Firewall on a Mac (macOS 14, 15, 26), and What It Doesn’t Block

> Step-by-step: turn on the macOS firewall, enable stealth mode and allow an app through it, from Apple’s own guides. Then the part it leaves open: outgoing connections.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/blog/how-to-turn-on-mac-firewall

Every Mac ships with a firewall, and most people never open its settings. This guide shows where it is in System Settings on macOS 14 Sonoma, macOS 15 Sequoia and macOS 26 Tahoe, what each of its options does, and how to let a specific app through. The steps and option names come from Apple’s macOS User Guide and the Apple Platform Security guide, linked in the sources, and the labels were checked on a Mac running macOS 26.7 on 4 October 2026. The last part covers what this firewall was never designed to do, because that is where most of the confusion about Mac firewalls comes from.

## What the built-in firewall is

Apple calls it an application firewall. Instead of listing ports, you list apps and services and decide whether each may accept connections from the network. Apple’s Platform Security guide describes its controls in four lines: block all incoming connections regardless of app, automatically allow built-in software to receive incoming connections, automatically allow downloaded and signed software to receive incoming connections, and add or deny access based on user-specified apps. A fifth option prevents the Mac from responding to ICMP probing and port-scan requests. Every one of these concerns traffic that arrives at your Mac from outside. The firewall pane says so itself when it is off: “This computer’s firewall is currently turned off. All incoming connections to this computer are allowed.”

## How to turn on the firewall on a Mac

Apple documents the same path for Sonoma, Sequoia and Tahoe.

1. Choose Apple menu › System Settings.
2. Click Network in the sidebar.
3. Click Firewall. You may need to scroll down to see it.
4. Turn on Firewall.
5. To change the extra settings, click Options…, turn settings on or off, then click OK.

When the switch is on, the pane reads: “The firewall is turned on and set up to prevent unauthorized applications, programs, and services from accepting incoming connections.” That sentence is a precise description of the scope: unauthorised apps accepting incoming connections. You can also confirm the state from Terminal without changing anything, using the command-line tool that ships with macOS.

*Terminal (macOS 26.7)*

```console
# read the firewall state; no administrator password needed to read
$ /usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate
Firewall is enabled. (State = 1)
$ /usr/libexec/ApplicationFirewall/socketfilterfw --getstealthmode
Firewall stealth mode is off
```

On a Mac managed by an employer or a school, the firewall may be set by a configuration profile. In that case the settings appear locked, and the command-line tool answers that firewall settings cannot be modified from the command line on managed Mac computers.

## The Options…, one by one

- Block all incoming connections: blocks every incoming connection except those required for basic internet services, such as DHCP and IPSec. Apple warns that this also blocks sharing services, such as file sharing, screen sharing and media sharing.
- Automatically allow built-in software to receive incoming connections: built-in apps and services signed by a valid certificate authority are added to the allowed list without asking you.
- Automatically allow downloaded signed software to receive incoming connections: the same for downloaded apps and services signed by a valid certificate authority.
- Enable stealth mode: in Apple’s words, it prevents your Mac from responding to probing requests that can be used to reveal its existence.

### Should you turn on stealth mode?

Stealth mode makes the Mac ignore test requests such as ping that use ICMP, along with port-scan probes. Other devices on the same network then get no answer when they check whether your Mac is there. On a laptop that joins public Wi-Fi this is a sensible default, and it does not stop your own apps from working, since it only concerns unsolicited requests from outside. If you rely on another device pinging the Mac, for example a home monitoring tool, it may report the Mac as unreachable once stealth mode is on.

## How to allow an app through the Mac firewall

When the firewall is on and an app that is not yet on the list starts listening for connections, macOS asks: “Do you want the application ‘App name’ to accept incoming network connections?” with the buttons Deny and Allow. Your answer is saved in the list under Options…. To add an app yourself, or to change an earlier answer:

1. Open System Settings › Network › Firewall and click Options…. The button is unavailable while the firewall is off.
2. Click the Add button (+) under the list of applications and services, then select the app.
3. Next to the app, choose Allow incoming connections or Block incoming connections.
4. Click OK.

Apple adds two cautions. Blocking an app’s access through the firewall could interfere with that app or with other software that depends on it, and certain apps that do not appear in the list may still have access through the firewall, including system apps, services and processes, and digitally signed apps that are opened automatically by other apps. The list is therefore not a complete inventory of what can accept a connection, only of the decisions recorded so far.

> **Note:** Allowing an app here only means it may receive connections from other computers, as a file server, a game host or a screen-sharing session would. It does not decide whether that app may connect out to the internet, which every app can already do.

## What the macOS firewall does not block

None of the settings above, and none of the keys in Apple’s firewall configuration profile for managed Macs, restricts outgoing connections. An app you installed can open a connection to any server, in any country, at any time, and the built-in firewall is not asked. That is a deliberate design choice rather than a defect: most of what a modern Mac does, from syncing mail to checking for updates, is outgoing, and an inbound filter keeps unsolicited visitors away without breaking any of it.

The consequence is that the risks that matter most on a personal Mac today travel outbound. A password-stealing program sends what it collected to a server it chose. An app with an analytics library reports to a third party. An AI agent that was given a poisoned instruction uploads a file. In each case the connection starts on your Mac, so an inbound firewall, with or without stealth mode, never sees a reason to step in. macOS also contains the lower-level pf packet filter, which can block outgoing traffic by address and port, but it has no notion of which app opened a connection; our [article on pf](https://hisnlabs.com/en/blog/macos-pf-firewall-limits) explains why it is not a practical per-app firewall.

## Adding outbound control with FireAI

FireAI, the firewall HisnLabs makes, covers the outgoing side that the built-in firewall leaves open. It runs as an Apple Network Extension content filter, the framework Apple provides for this purpose, so macOS asks it about every new connection before it opens, with the app identity, the remote host or IP address, the port and the protocol. Apps are identified by their code signature rather than their name, so a modified copy of a known app does not inherit that app’s rules.

The first time an app tries to reach a destination you have no rule for, FireAI pauses that one connection and asks, showing the destination and, when it can tell, its country and company. You can allow or block it just this once, until the app quits, until you restart, or always, and for one address, the whole website, one IP address or anywhere. Rules can also be written in advance per app, by website, domain, IP address or port. FireAI enforces rules on incoming connections too, but it never prompts about them, so keep Apple’s firewall on for that job: the two are complementary, not alternatives.

> Keep Apple’s firewall on for incoming connections, and let FireAI ask about outgoing ones. Every feature is free for 17 days, no card needed. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## A short checklist

- System Settings › Network › Firewall: on.
- Options…: stealth mode on for laptops that use public Wi-Fi.
- Review the app list under Options… and remove apps you no longer use.
- Turn on Block all incoming connections when you are on an untrusted network and do not need sharing services.
- For outgoing connections, use an outbound firewall, since the built-in one does not filter them.

## How FireAI and HisnLabs fit in

Apple’s firewall decides who may connect to your Mac; FireAI decides where your apps may connect to. Keep the first on and try the second free for 17 days.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [Apple macOS User Guide: Block connections to your Mac with a firewall](https://support.apple.com/guide/mac-help/block-connections-to-your-mac-with-a-firewall-mh34041/mac)
- [Apple macOS User Guide: Change Firewall settings on Mac](https://support.apple.com/guide/mac-help/change-firewall-settings-on-mac-mh11783/mac)
- [Apple Platform Security: Firewall security in macOS](https://support.apple.com/guide/security/firewall-security-in-macos-seca0e83763f/web)
- [Apple Platform Deployment: Firewall payload settings for Apple devices](https://support.apple.com/guide/deployment/firewall-payload-settings-dep8d306275f/web)
- [Apple Developer: Content filter providers (NetworkExtension)](https://developer.apple.com/documentation/networkextension/content-filter-providers)
- [FireAI docs: how the network filter works](https://hisnlabs.com/en/docs/how-the-network-filter-works)
- [FireAI docs: answer your first connection prompt](https://hisnlabs.com/en/docs/answer-your-first-connection-prompt)
- [FireAI docs: per-app rules](https://hisnlabs.com/en/docs/per-app-rules)
- [FireAI: pricing and the 17-day trial](https://hisnlabs.com/en/pricing)
