 |
 |
OS X Firewall
|
 |
|
 |
|
Fresh-Faced Recruit
Join Date: Apr 2002
Status:
Offline
|
|
How effective is 10.3's Firewall program? Does it compare to a program such as Nortons. How safe would using it with my broadband connection (cable)?
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Jun 1999
Location: Las Vegas, NV, USA
Status:
Offline
|
|
The firewall is very good. You don't need to supplement it with anything else, certainly not Norton. The consensus among most here is that Norton causes more problems than it solves. The only reason people buy is because it has name recognition with switchers.
Chris
|
|
|
| |
|
|
|
 |
|
 |
|
Clinically Insane
Join Date: Nov 1999
Status:
Offline
|
|
The firewall which comes with OSX is actually quite powerful, though you wouldn't know it from the interface Apple provides to configure it. While it'll get the job done for casual net users, if you have needs above and beyond the basics there are third-party configuration tools available which do a much better job. One of the first was called BrickHouse, and while its interface is a little rough around the edges it's still one of the best out there.
|
|
You are in Soviet Russia. It is dark. Grue is likely to be eaten by YOU!
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Feb 2001
Location: zurich, switzerland
Status:
Offline
|
|
As the others have said, OSX's firewall is very powerful, but Apple provides only a simple interface to the user, which is probably a good thing, since most users would not understand the more powerful features, such as blocking outgoing connections on certain ports as well as incoming on most ports.
The commandline tool ipfw is where all the action happens. It has a fairly good manpage, and if you do some online research, it'll do all you need and much more.
|
|
weird wabbit
|
| |
|
|
|
 |
|
 |
|
Senior User
Join Date: Jan 2002
Location: Laurentia
Status:
Offline
|
|
Maybe this isn't the place for this question, but...
Out of the box, does OS X need a firewall? What ports are default-open to incoming traffic?
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Nov 2001
Status:
Offline
|
|
Originally posted by cambro:
Maybe this isn't the place for this question, but...
Out of the box, does OS X need a firewall? What ports are default-open to incoming traffic?
Out of the box, no ports are open to incoming traffic. So no, it really doesn't need a firewall, because there's nothing listening, and therefore there aren't any services that can be attacked.
If you turn on remote access or some form of sharing, then ports will be opened. Of course, you can't use a firewall on those ports, because they need to listen 
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Feb 2001
Location: zurich, switzerland
Status:
Offline
|
|
Originally posted by CatOne:
Out of the box, no ports are open to incoming traffic. So no, it really doesn't need a firewall, because there's nothing listening, and therefore there aren't any services that can be attacked.
If you turn on remote access or some form of sharing, then ports will be opened. Of course, you can't use a firewall on those ports, because they need to listen
This is why a customised firewall is such a good idea, i.e. setting up ipfw properly. With the rules set up correctly, you can share data to certain address and not to others, thereby avoiding most of the pitfalls of having open ports.
|
|
weird wabbit
|
| |
|
|
|
 |
|
 |
|
Forum Regular
Join Date: Jun 2003
Location: Oklahoma City
Status:
Offline
|
|
Since I use a router with a built-in firewall, I only rely on an app to monitor outgoing connections. I suppose "LIttle Snitch" is the best for that?
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Nov 2001
Status:
Offline
|
|
Originally posted by Burke:
Since I use a router with a built-in firewall, I only rely on an app to monitor outgoing connections. I suppose "LIttle Snitch" is the best for that?
yes.
|
|
|
| |
|
|
|
 |
 |
|
 |
|
|
|
|
|

|
|
 |
Forum Rules
|
 |
 |
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is Off
|
|
|
|
|
|
 |
 |
 |
 |
|
 |
|