Skip to main content

Do You Need a Firewall on Your Mac? The Built-in One, LuLu, Little Snitch and What Your Employer Decides

· 19 min read
Pere Pages
Software Engineer
A laptop on a round café table with a glowing shield in front of its screen. Lines of light come in through an arched window and stop at the shield, and lines going out pass two small gates on their way to a network of connected dots.

Every Mac comes with a firewall, and it is switched off. This post explains what that firewall does, why turning it on is a small but free win, when a second firewall for outgoing traffic is worth installing, and why on a work Mac the decision is not yours.

note

This post reflects macOS and the firewall apps as of 2026. Prices, versions and menu names change, so check the current details before you buy or change a setting.

The gist​

Turn on the firewall that comes with your Mac. Add a second one only if you want to control what your own apps send out.

  • Turn on the built-in firewall and stealth mode. The firewall is off when the Mac arrives. It stops other computers from connecting to programs on your Mac. Stealth mode makes your Mac stop answering when other computers check whether it is there. Both cost nothing and rarely cause problems.
  • Don't count on the firewall as your main protection. macOS already checks every app before it opens and scans for known malware. The firewall is an extra layer for the services you forgot were running.
  • Add an outgoing firewall only for privacy. The built-in one never checks what your apps send to the internet. To see and block that, use LuLu (free), Little Snitch ($59, the most detail) or Radio Silence ($9, no prompts).
  • On a work Mac, change nothing yourself. Your employer usually sets the firewall already, and a firewall app can break the company's private network connection or its security software. Ask the information technology (IT) team first.

The picture: traffic goes in two directions​

A firewall is a program that decides which network traffic is allowed and which is blocked. On a laptop, the traffic goes in two directions, and that is the most important thing to understand before choosing anything:

  • Incoming traffic is when another computer tries to start a connection to your Mac. For example, a device on the same café Wi-Fi tries to reach a file-sharing service on your laptop.
  • Outgoing traffic is when an app on your Mac starts a connection to somewhere else. For example, your browser loads a page, or an app sends usage data back to its company.

A firewall that checks incoming traffic protects your Mac from other computers. A firewall that checks outgoing traffic protects your privacy from your own apps. They answer different questions, and one does not replace the other.

Your home router also sits between your devices and the internet, and it blocks most incoming connections from the internet by default. It does not help when you are on someone else's network, like a café or a hotel. That is where the Mac's own firewall matters.

How macOS ships: an incoming firewall, switched off​

macOS includes a firewall called the Application Firewall, and it is turned off by default[1]. You turn it on in System Settings → Network → Firewall[2].

It is called an application firewall because it makes decisions per app, not per network address or per port (the number that tells a computer which service a connection is for). When an app wants to accept incoming connections, the firewall checks whether that app is on the allowed list. Apple describes these options[2][3]:

  • Block all incoming connections. Only the basic services your Mac needs to work on a network get through. Sharing services, like file sharing and screen sharing, stop accepting connections.
  • Automatically allow built-in software. Apple's own apps and services that are signed (carry a verified digital signature from a known developer) are allowed without asking you.
  • Automatically allow downloaded signed software. The same rule for apps you downloaded, as long as they are signed.
  • Enable stealth mode. Your Mac stops answering "are you there?" messages from other computers. The most common of these is ping, which uses ICMP (Internet Control Message Protocol). A computer that doesn't answer is harder to find on a network.
  • A list of apps you allow or block one by one.

What the Application Firewall does not do is check outgoing traffic. Any app on your Mac can still connect to any server on the internet. Under the Application Firewall, macOS also has a lower-level tool called pf (packet filter), which can filter both directions with rules by address and port. pf has no settings screen. You use it from the Terminal with configuration files, so it is a tool for network administrators, not for everyday use.

Is it really important?​

For most people at home, the built-in firewall changes little. For a laptop that travels, and for developers, it matters more. Three things decide how much it matters.

The network you are on. At home, your router already blocks incoming connections from the internet. The devices that can reach your Mac are the ones on your own Wi-Fi: your phone, your TV, maybe a guest's laptop. On a café, hotel, airport or conference network, every other person on that Wi-Fi can try to connect to your laptop. You don't know them, and you don't control their devices.

What is listening on your Mac. A connection from outside only works if some program on your Mac is waiting for it. Programs that wait for connections are said to be listening. A fresh Mac listens on very little. The number grows when you turn on sharing services (file sharing, screen sharing, media sharing, remote login) or when you install apps that accept connections, like music servers or remote-control tools. Each of these is a way into your Mac. The firewall decides which of them other computers can reach.

Whether you are a developer. Development tools start local servers all the time, and some of them listen on every network your Mac is connected to, not only on your own computer. Python's built-in web server, for example, listens on every network the Mac is connected to by default[4]. That means that anyone on the same café Wi-Fi can open the folder you are serving. Vite does the safer thing and listens only on your own computer unless you ask otherwise[5]. You often don't know which kind of tool you are running, and that is where the firewall helps: it asks before an unknown program accepts connections from outside.

So the honest answer is that the built-in firewall is an extra layer, not your main protection. It costs nothing and it rarely causes problems. It also protects you in the cases where you forgot what is listening. That is enough reason to turn it on.

Apple's point of view: protection in layers​

Apple doesn't rely on the firewall to keep a Mac safe. macOS protects you with several layers, and most of them work before any network traffic matters:

  1. Gatekeeper and notarization. Before a downloaded app opens for the first time, macOS checks that it comes from an identified developer, that Apple has scanned it for known malicious content (this scan is called notarization), and that nobody has changed it since[6].
  2. XProtect. macOS has built-in antivirus called XProtect. It checks apps against signatures of known malware when they first open and when they change, and it can remove malware it finds. Apple updates these signatures automatically[7].
  3. System Integrity Protection. The core files of macOS are locked, so that even an app with administrator rights cannot change them.
  4. App Sandbox and privacy prompts. Many apps run in a restricted space, and every app has to ask you before it reads your camera, microphone, location, contacts or files in protected folders.
  5. The Application Firewall. It filters incoming connections, as described above. Apple lists it as one option you can configure, next to the others[3].

Seen this way, Apple's choice makes sense. A new Mac listens on almost nothing, so a firewall would block almost nothing. A firewall that is on can also confuse people when a game, a printer or a sharing feature stops working. Apple chose to leave it off and protect the Mac at other layers. That is a reasonable default for a home user, but it is a default, not a recommendation to keep it off.

Apple also never shipped an outgoing firewall. Watching what your apps send out is left to other companies.

History: when Apple's own apps skipped the firewall

In the first versions of macOS Big Sur (2020), a hidden list called ContentFilterExclusionList let more than 50 of Apple's own apps and services go around third-party firewalls and VPNs (virtual private networks, which send your traffic through another server). Security researcher Patrick Wardle showed that malware could hide its traffic behind those apps. Apple removed the list in macOS 11.2[8].

On a work Mac, your employer decides​

If your Mac belongs to your employer, the firewall settings probably belong to them too.

Companies manage their Macs with MDM (mobile device management), a service that sends settings to every company device. Apple's device management includes a firewall payload (a package of firewall settings) that can turn the firewall on, block all incoming connections, turn on stealth mode, and allow or block specific apps[9]. When MDM sets these, the switches in System Settings are locked (shown in grey), and you can't change them.

Employers usually follow a published security standard, and the common ones agree on the firewall:

  • The CIS (Center for Internet Security) Benchmark for macOS asks for the firewall to be on and for stealth mode to be on[10].
  • The United States government's security rules for macOS 15 say that the Application Firewall must be enabled[11].

Many companies also install an EDR (endpoint detection and response) tool, a security agent that watches what happens on the laptop and reports to the company's security team. Several of these tools add their own network filter to macOS. That is the same mechanism LuLu and Little Snitch use, so they can conflict. When macOS 15.0 came out, a bug in the system firewall broke network connections on Macs that ran products from CrowdStrike, SentinelOne and Microsoft, and VPN (virtual private network) apps stopped working too. Most of it was fixed in macOS 15.1[12].

The practical rules for a work Mac follow from this:

  • Don't install a firewall app without asking your IT team. It can break the company VPN or the security agent, and it may break company policy.
  • Don't turn off a firewall setting that MDM has turned on, even if you find a way to do it.
  • If something doesn't work because of the firewall, ask IT to allow it. They can add a rule for every Mac in the company.

Firewall apps for outgoing traffic​

If your Mac is your own and you want to see and control what your apps send out, you need a firewall app. All of the apps below use the same part of macOS (a network extension, which Apple lets security apps install after you approve it). The first time an app tries to connect somewhere new, they show you a prompt: allow it, or block it, once or forever.

  • The built-in Application Firewall. Free and already on your Mac. It only checks incoming connections, so it tells you nothing about what your apps send.
  • LuLu, made by Objective-See. Free and open source (anyone can read and check its code). It blocks unknown outgoing connections until you approve them. It has a passive mode that applies your rules without showing prompts, and it accepts block lists. Its own documentation is honest about its limits: some traffic doesn't go through network extensions, so LuLu can't see it, and in browsers like Chrome it can block by address but not by server name.
  • Little Snitch, made by Objective Development. A paid app with more than 20 years of history. It checks incoming connections as well as outgoing ones. On top of the prompts, it has a network monitor that shows on a world map where your Mac connects, rules per app, server, port or protocol, rule profiles that change with the network you're on, updated block lists, and encrypted DNS (Domain Name System, the service that turns names like apple.com into addresses). Version 6 costs $59 for one license and needs macOS 14 or later. A demo mode works fully for three hours at a time[13].
  • Radio Silence. A small paid app ($9) that only blocks outgoing connections. There are no prompts. You see a list of what connects, and you block an app with one click. It is the quietest of the three.
QuestionBuilt-in firewallLuLuLittle SnitchRadio Silence
PriceFree, includedFree$59$9
Checks incoming connections?YesNoYesNo
Checks outgoing connections?NoYesYesYes
Can anyone read the code?NoYesNoNo
How much it asks youAlmost neverOften in the first daysOften in the first daysNever; you check the list
How much it shows youVery littleApps and serversFull map and historyApps and servers
Fine on a work Mac?Yes, usually managedOnly if IT agreesOnly if IT agreesOnly if IT agrees

Best Good Mixed Weak

The table leads to a simple choice. Keep the built-in firewall on in every case. Add LuLu if you want outgoing control for free. Choose Little Snitch if you want to understand your traffic in detail and you will use its extra features. Choose Radio Silence if you only want to silence a few apps without prompts.

Tips​

These are ordered from most to least important.

  1. Turn on the built-in firewall and stealth mode. In System Settings → Network → Firewall, switch it on, then open Options and turn on Enable stealth mode. You can do the same from the Terminal:

    # Show whether the firewall is on
    /usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate

    # Turn on the firewall and stealth mode (asks for your password)
    sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on
    sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setstealthmode on
  2. Find out what is listening on your Mac. This command lists every program that is waiting for connections, and the address it waits on:

    # -iTCP -sTCP:LISTEN: only programs waiting for connections
    # -n -P: show numbers instead of names, which is faster
    lsof -iTCP -sTCP:LISTEN -n -P

    An address of 127.0.0.1 or [::1] means only your own Mac can connect. An address of * means every network your Mac is on can connect. Look closely at every *.

  3. Start development servers on your own computer only. Pass 127.0.0.1 when the tool supports it, for example python3 -m http.server --bind 127.0.0.1. Only listen on every network when you really need to test from your phone, and stop the server when you finish.

  4. Turn off sharing services you don't use. In System Settings → General → Sharing, switch off file sharing, screen sharing, media sharing and remote login unless you use them. A service that is off doesn't need a firewall rule.

  5. Use "Block all incoming connections" on networks you don't trust. On an airport or hotel Wi-Fi, this option is a quick way to block every way in. Switch it off again at home if AirDrop or another sharing feature stops working.

  6. Expect many prompts in the first week with an outgoing firewall. LuLu and Little Snitch ask about every new connection, and a normal Mac makes a lot of them. Answer the prompts for the apps you know. After a few days the prompts become rare, and each new one means something actually changed.

  7. Don't block Apple's system services without knowing what they do. Many background processes have unclear names but handle software updates, iCloud, time sync or the malware checks described above. If you block them, macOS updates and security checks can stop working without any warning.

  8. Keep macOS updated, and wait a little before major updates if you use a firewall app. Firewall apps depend on parts of macOS that change in major releases. Check that your firewall app supports the new version before you update.

If you are making your own setup safer, the next steps are your accounts and backups, covered in Your Personal Security Setup. For the network side at home, see Segmenting a Home Network with Omada.

References​

  1. High Performance Computing Modernization Program, Enabling IPv6 in Apple macOS, OS X and Mac OS X-based Firewalls
  2. Apple, Change Firewall settings on Mac — Mac User Guide
  3. Apple, Firewall security in macOS — Apple Platform Security
  4. Python, http.server — HTTP servers — Python documentation
  5. Vite, Server Options: server.host — Vite documentation
  6. Apple, Gatekeeper and runtime protection in macOS — Apple Platform Security
  7. Apple, Protecting against malware in macOS — Apple Platform Security
  8. AppleInsider, Apple drops exclusion list which allowed its own apps to bypass firewalls (2021)
  9. Apple, Firewall payload settings — Apple Platform Deployment
  10. Tenable, CIS Apple macOS Benchmark: Ensure Firewall Stealth Mode Is Enabled
  11. STIG Viewer, Apple macOS 15 (Sequoia) STIG: The macOS system must enable macOS Application Firewall (V-268557)
  12. Michael Tsai, macOS Firewall Regressions in Sequoia (2024)
  13. Objective Development, Objective Development Releases Little Snitch 6 (2024)