How to Turn On the Firewall on a Mac

The Inbound Port Vulnerability Vector

When you connect your MacBook to a public Wi-Fi network at a coffee shop or an airport, you are thrust into a highly hostile digital environment. Your machine is suddenly sharing a localized network with dozens of unknown devices, any of which could be attempting to probe your Mac for open software ports. To immediately halt all unauthorized inbound network requests and render your machine cryptographically invisible to automated network scanners, you must activate the hardware firewall.

How to Turn On the Firewall

Apple includes a robust, application-layer firewall directly within the core operating system, but it is frequently disabled by default on new machines.

1. Click the Apple Logo in the absolute top-left corner of the screen.
2. Select System Settings from the dropdown menu (or System Preferences on older versions of macOS).
3. In the left-hand navigation sidebar, scroll down and click on Network.
4. In the main pane, click on the section titled Firewall.
5. You will see a master toggle switch at the top of the screen.
6. Click the toggle switch to move it to the On position (it will turn green).
7. The Crucial Configuration (Stealth Mode): Simply turning the firewall on is insufficient for a public network. You must click the Options… button located directly beneath the toggle switch.
8. A new configuration panel will appear. Check the box labelled Enable Stealth Mode.
9. Click OK.

The Operational Reality: The firewall is now active, and Stealth Mode is engaged. If a malicious actor on the coffee shop Wi-Fi attempts to “ping” your Mac’s IP address, your machine will completely ignore the request. It will not even send back a “connection refused” signal; it will act as if it does not exist, creating an absolute black hole for inbound traffic.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.