Macs have a legendary reputation for security, largely because macOS is built on a rock-solid UNIX foundation and includes built-in anti-malware tools like XProtect. However, while macOS is excellent at stopping malicious files from running, it is surprisingly relaxed about network connections. Out of the box, a brand-new Mac has its system firewall completely disabled.
When you are connected to your private home Wi-Fi network behind a secure router, this is perfectly safe. The danger arises when you take your MacBook to a coffee shop, airport, or hotel. On a public Wi-Fi network, anyone else connected to that same network can theoretically probe your computer for open ports and vulnerable sharing services.
Enabling the macOS Application Firewall provides a crucial layer of defense. It silently monitors all incoming network traffic and blocks unauthorized applications from accepting connections from the outside world. This guide explains how to enable and configure the macOS Firewall.
Step 1: Turn On the Firewall
Unlike complex enterprise firewalls that require you to memorize port numbers and IP protocols, Apple designed the macOS firewall to be incredibly user-friendly.
- Click the Apple menu () in the top-left corner of your screen.
- Select System Settings (or System Preferences on older macOS versions).
- In the left-hand sidebar, click on Network.
- In the main Network panel, click on Firewall.
- Toggle the main switch to the On position. (You may be prompted to enter your administrator password or use Touch ID to authorize this change).
The firewall is now active. It will immediately begin blocking unauthorized incoming connections in the background without interrupting your web browsing or email.
Step 2: Configure Firewall Options (Optional but Recommended)
While the default settings are good, you should review the advanced options to ensure the firewall is not blocking applications you actually want to use (like a local Plex media server or a multiplayer game).
- With the Firewall turned on, click the Options… button just below the toggle switch.
- You will see a list of applications that have requested permission to accept incoming connections. You can manually use the “+” and “-“ buttons to add or remove apps from this list.
- Ensure that Automatically allow built-in software to receive incoming connections is turned on. This ensures native Apple services like AirDrop and Screen Sharing continue to function properly.
- Ensure that Automatically allow downloaded signed software to receive incoming connections is also turned on. This allows legitimate, Apple-notarized apps from trusted developers (like Zoom or Spotify) to bypass the firewall without annoying you with constant pop-up alerts.
Stealth Mode for Maximum Security
At the very bottom of the Firewall Options window, you will see a toggle for Enable Stealth Mode.
Normally, if a hacker or a malicious script sends a “ping” across a public Wi-Fi network to see if your computer exists, your Mac will politely reply, “Yes, I am here.” When you enable Stealth Mode, your Mac simply drops the ping and refuses to answer. To anyone probing the network, your computer appears to be completely invisible or turned off, significantly reducing your profile as a potential target.