Control macOS Firewall
Controls user network traffic using macOS Network Extension.
- Allows and blocks inbound and outbound traffic according to rules.
- Network traffic can be controlled by utilizing rules such as App BundleID, App Path, protocol, port, and remote IP.
Control macOS Firewall Options Configuration
- Rule Selection: You can select between General Rules and Internet Kill Switch Rules.
- General Rules: Allows all internet connections except for blocking rules. Operates in Blacklist mode.
- Connection Block Rules: Select the conditions for the rule to be controlled using direction, app path, app bundle ID, protocol, remote IP, port, etc.
- Notification Message: Displays a pop-up message to the user when traffic is blocked due to matching a rule.
- Prevent Duplicate Message Notifications: Does not display duplicate notification messages if multiple traffic events occur within a short interval.
- Duplicate Message Notification Prevention Time: Does not display duplicate notification messages for the specified time.
Configuring Network Blocking Policy via Node Policy
- Go to Policy in the top menu.
- In the left Policy menu, go to Policy > Node Policy > Node Action.
- In the Node Action management window, find and click macOS Firewall Control.
- Enter Condition Settings and options.
- In the left Policy menu, go to Policy > Node Policy.
- Click the node policy to configure the network blocking policy.
- Find Node Action Settings and click Assign.
- In the Available items, find macOS Firewall Control and drag it to the Selected items.
- Click the Add button.
- Click the Update button.
- Click the Apply Change Policy button in the top right.
Configuring Network Blocking Policy via Enforcement Policy
Step 1. Create Control Target Node Group
- Go to Policy in the top menu.
- In the left Policy menu, go to Group > Node.
- Click Select Tasks > Create.
- Click the Add button.
- Configure the conditions for the control target and click the Add button.
- Click the Create button.
Step 2. Create Control Action
- In the left Policy menu, go to Policy > Enforcement Policy > Control Action.
- Click Select Tasks > Create.
- In the Plugin selection item, select the macOS Firewall Control plugin.
- Enter Condition Settings and options.
- Click the Create button.
Step 3. Create Enforcement Policy
- In the left Policy menu, go to Policy > Enforcement Policy > Enforcement Policy.
- Click Select Tasks > Create and complete the Enforcement Policy Wizard.
- In the Policy General tab, enter the Policy ID to use in the ID field.
- In the Node Group Settings tab, select the newly added node group and move it to the Selected item.
- In the Permission Assignment and Control Options tabs, enter the desired options.
- In the Control Action Settings tab, find the created Control Action and move it to the Selected item.
- Click the Complete button.
- Click Apply Change Policy in the top right.