How to Turn On and Configure the Firewall on Mac

Illustration for How to Turn On and Configure the Firewall on Mac

Quick Answer

To enable the Mac firewall, open the Apple menu, choose System Settings, select Network in the sidebar, and click Firewall. Turn on Firewall, then use Options to control which apps and services can accept incoming connections.

On older versions of macOS, open System Preferences, select Security & Privacy, click the Firewall tab, and choose Turn On Firewall.

The firewall helps block unwanted incoming network connections. It does not replace safe browsing habits, malware protection, software updates, or the firewall built into your router.

What the Mac Firewall Does

A firewall controls incoming network connections to your Mac. When an app or service tries to receive a connection from another device, the firewall can allow or block it.

This is especially useful when your Mac connects to public or unfamiliar networks, such as those in hotels, airports, cafés, libraries, and conference centers.

The built-in macOS firewall primarily helps protect services and apps that accept incoming connections. It is not designed to block every connection your Mac makes to the internet. For example, it generally does not ask for permission every time a web browser connects to a website.

The firewall also does not automatically make an untrusted app safe. Keep macOS and your apps updated, download software from reputable sources, and be cautious when granting apps access to your Mac.

Turn On the Firewall in System Settings

These instructions apply to the current System Settings layout.

  1. Click the Apple menu in the upper-left corner of the screen.
  2. Select System Settings.
  3. Click Network in the sidebar.
  4. Select Firewall.
  5. Turn on Firewall.

You may need to authenticate with an administrator password, Touch ID, or another available sign-in method before changing the setting.

Once enabled, macOS begins enforcing its firewall rules. You can click Options to configure app-specific permissions and additional settings.

Warning: Turning on the firewall can affect apps and services that accept incoming connections. If you are using file sharing, screen sharing, media sharing, remote administration, or a local development server, check those services afterward.

Turn On the Firewall in System Preferences

Some Macs use the older System Preferences interface.

  1. Open the Apple menu.
  2. Select System Preferences.
  3. Click Security & Privacy.
  4. Select the Firewall tab.
  5. If the settings are locked, click the lock icon and authenticate.
  6. Click Turn On Firewall.

To adjust access rules, click Firewall Options.

The names and locations of settings can differ slightly depending on the macOS interface installed on your Mac. If you do not see Firewall under Network, use the search field in System Settings or System Preferences and search for “firewall.”

Configure App-Specific Firewall Access

The firewall can allow or block specific apps and services. This is useful when an app needs to accept incoming connections—for example, a file-sharing tool, multiplayer game, remote-access utility, or development server.

Add an app to the firewall list

  1. Open System Settings.
  2. Go to Network > Firewall.
  3. Click Options.
  4. Click the Add button, which may appear as a plus sign.
  5. Select the app in the file-selection window.
  6. Click Add.
  7. Set the app to Allow incoming connections.
  8. Click Done.

On older macOS versions:

  1. Open System Preferences.
  2. Go to Security & Privacy > Firewall.
  3. Click Firewall Options.
  4. Click the plus sign.
  5. Select the app.
  6. Choose Allow incoming connections.
  7. Click OK.

Remove an app from the list

Removing an app from the firewall list does not uninstall it. It only removes its specific firewall rule.

  1. Open the firewall options.
  2. Select the app or service.
  3. Click the Remove button, usually shown as a minus sign.
  4. Confirm or click Done, depending on the macOS interface.

If the app later needs incoming access, macOS may ask you whether to allow it when it attempts to receive a connection.

Understand the available access choices

Firewall entries commonly have one of these settings:

  • Allow incoming connections: The app can accept incoming connections.
  • Block incoming connections: The firewall prevents the app from accepting incoming connections.

Only allow incoming connections for apps you recognize and trust. If an app does not need to receive connections, blocking it is usually the more restrictive choice.

Some macOS services may appear automatically in the list. Avoid changing system services unless you understand what they do or are following instructions from a trusted administrator.

Enable Stealth Mode

Stealth mode makes your Mac less responsive to certain unsolicited network requests. For example, the Mac may avoid responding to some probes that are commonly used to discover devices on a network.

To enable it:

  1. Open System Settings.
  2. Select Network.
  3. Click Firewall.
  4. Click Options.
  5. Turn on Enable stealth mode.
  6. Click Done.

On older macOS versions, open System Preferences > Security & Privacy > Firewall > Firewall Options, then select Enable stealth mode.

Stealth mode can reduce the information your Mac reveals to other devices, but it does not make your Mac invisible or anonymous. It also does not replace a VPN, router firewall, secure Wi-Fi configuration, or other security controls.

Review Signed Software Options

Firewall settings may include options related to signed software. A digital signature helps identify software issued by a known developer and indicates whether the app has been modified since it was signed.

Depending on your macOS interface, you may see settings such as:

  • Automatically allow downloaded signed software to receive incoming connections
  • Automatically allow built-in software to receive incoming connections

These options can reduce prompts for software that macOS recognizes as signed or built in.

Should you leave these options enabled?

For most everyday users, the default settings are reasonable. They make it easier for trusted Apple software and properly signed apps to work without repeated approval prompts.

For a more restrictive configuration, you can turn off automatic allowances and approve apps individually. This may improve control, but it can also result in more prompts or cause legitimate services to stop working until you add an exception.

Before changing these options, note their current state so you can restore them if necessary.

Allow or Block a Service

The firewall controls incoming connections, but a service must also be turned on before it can accept them. For example, enabling a firewall exception does not automatically enable file sharing or screen sharing.

To review sharing services:

  1. Open System Settings.
  2. Select General.
  3. Click Sharing.
  4. Review the available services.
  5. Turn on only the services you need.
  6. Return to Network > Firewall and check the related firewall permission.

On older macOS versions, sharing controls may be under System Preferences > Sharing.

Warning: Enabling a sharing service changes how your Mac communicates with other devices. Only enable services you understand, and review which users are allowed to connect.

When possible, restrict sharing to your local network rather than exposing services directly to the public internet. Avoid forwarding ports to your Mac unless you understand the security implications and have a specific need.

Mac Firewall vs. Router Firewall

Your Mac and your router protect different parts of your network.

Router firewall

A router firewall generally controls traffic between your home network and the internet. It can help prevent unsolicited internet traffic from reaching devices inside your network.

Many routers use network address translation, or NAT. In simple terms, NAT allows multiple devices to share one public internet connection while making direct inbound connections from the internet more difficult.

Mac firewall

The Mac firewall controls incoming connections to your Mac itself. It can still be useful behind a router because:

  • Other devices on the same local network may try to connect to your Mac.
  • You may use your Mac on public Wi-Fi.
  • A device or network configuration may expose services differently than expected.
  • A compromised device on the local network could attempt to contact your Mac.

A router firewall does not make the Mac firewall unnecessary, and the Mac firewall does not replace a properly secured router. Use both where practical.

Test Whether an App Is Being Blocked

If an app cannot receive connections, first determine whether the problem is the Mac firewall or something else.

  1. Confirm that the app is open and the relevant feature is enabled.
  2. Check the app’s own settings for network access, sharing, or server mode.
  3. Open System Settings > Network > Firewall > Options.
  4. Find the app in the list.
  5. Set it to Allow incoming connections if you trust it.
  6. Try the connection again.
  7. If the problem continues, temporarily turn off the firewall only for testing.

Warning: Turning off the firewall changes your Mac’s network protection. If you do this as a test, turn it back on immediately after testing. Do not leave it disabled as a permanent workaround.

If the app works only when the firewall is off, turn the firewall back on and create a specific exception instead. Avoid allowing every app or opening unnecessary services.

Troubleshooting Blocked Services

An app keeps asking for permission

Make sure you are allowing the correct copy of the app. If you have multiple versions—for example, one in Applications and another in a Downloads folder—macOS may treat them as different apps.

Remove outdated entries from the firewall list and add the current app again. Then restart the app and test the connection.

File sharing does not work

Check all of the following:

  1. System Settings > General > Sharing: confirm that File Sharing is enabled.
  2. Confirm that the correct folders and users have access.
  3. Check Network > Firewall > Options for the relevant service.
  4. Make sure both Macs are connected to the same network when using local sharing.
  5. Check whether the network blocks device-to-device communication.

Some public and guest Wi-Fi networks intentionally prevent connected devices from communicating with each other. The Mac firewall cannot override that network restriction.

Screen sharing or remote access is blocked

Confirm that the relevant sharing service is enabled and that the connecting account has permission. Also check whether the Mac is awake and connected to the expected network.

If the Mac is behind a router, firewall, VPN, or corporate network, that device or service may block the connection before it reaches the Mac.

A development server is unreachable

Local development tools often listen on a specific port and network interface. Check the tool’s documentation and settings first.

Then confirm:

  • The server is running.
  • It is listening on the expected address and port.
  • The firewall allows the correct application.
  • The network profile permits devices to communicate.
  • Another security tool is not blocking the connection.

Avoid exposing a development server directly to the internet unless you understand authentication, encryption, port forwarding, and the risks involved.

The firewall setting is unavailable

If the firewall controls are missing, dimmed, or cannot be changed:

  • Authenticate as an administrator.
  • Check whether a work or school management profile controls the setting.
  • Restart the Mac and check again.
  • Install available macOS updates.
  • Contact the organization’s administrator if the Mac is managed.

Do not remove a management profile from an organization-owned Mac without authorization.

You cannot identify the correct app

Look at the app’s name and location before allowing it. If you are unsure, choose Block incoming connections, then check the app’s documentation or contact its developer.

Do not approve an unfamiliar app merely because it requests network access. A legitimate app should have a clear reason for receiving incoming connections.

Frequently Asked Questions

Should I turn on the firewall on my Mac?

For most users, yes. Enabling the Mac firewall provides an additional layer of protection against unwanted incoming connections, particularly on public or untrusted networks.

Does the Mac firewall block websites?

Usually, no. The firewall is primarily designed to control incoming connections to apps and services on your Mac. It is not a website filter or a general outbound internet blocker.

Will turning on the firewall break my internet connection?

It normally should not prevent ordinary web browsing, email, or other outgoing connections. However, apps and services that accept incoming connections may require an exception.

Should I use stealth mode?

Stealth mode is a reasonable option if you want your Mac to respond less visibly to certain unsolicited network requests. It is not a complete security solution and may not stop every form of network discovery.

Should I allow every app through the firewall?

No. Allow only apps and services that need incoming access and that you trust. Blocking unnecessary apps reduces the number of services reachable from the network.

Does the firewall protect me from malware?

The firewall can block some unwanted incoming connections, but it does not detect or remove all malware. Keep macOS and apps updated, use reputable software, and avoid opening suspicious files or links.

Do I need a third-party firewall?

Many users can use the built-in macOS firewall without additional firewall software. Third-party tools may offer more detailed outbound controls, but they can add complexity and duplicate existing protections. Research any security tool carefully before installing it.

Can I configure the firewall with Terminal?

Terminal can inspect and manage certain macOS firewall components, but the graphical settings are safer and easier for most users. Firewall-related command-line tools and behavior can vary by macOS release, so avoid running commands copied from unknown sources.

Final Thoughts

Turning on the Mac firewall is a simple way to control unwanted incoming connections. Open System Settings > Network > Firewall, enable Firewall, and use Options to allow only the apps and services that need access.

For a practical configuration, keep the firewall enabled, consider turning on stealth mode, leave signed-software options at their defaults unless you need stricter control, and review sharing services regularly. Remember that the Mac firewall works alongside—not instead of—the firewall in your router and other basic security practices.