Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > Application Firewall

Application Firewall
Thread Tools
Professional Poster
Join Date: Sep 2000
Location: San Francisco
Status: Offline
Reply With Quote
Nov 7, 2007, 09:26 AM
 
Since the other thread got hijacked, I thought I would post this new info here. At least, I think it is new.

Mac OS X 10.5: About the Application Firewall
     
Professional Poster
Join Date: Mar 2000
Location: New York, NY, USA
Status: Offline
Reply With Quote
Nov 7, 2007, 09:47 AM
 
I can't get my ipfw settings to stick between restarts.
The era of anthropomorphizing hardware is over.
     
Junior Member
Join Date: Mar 2005
Status: Offline
Reply With Quote
Nov 7, 2007, 10:45 AM
 
this sounds like it would make LittleSnitch redundant. Is that true? Does it give you the ability to block

-any network connection
-local network connection
-broadcast
-multicast

while also selecting a ports (or port range) and the protocols (UDP, TCP, any, etc.)

can someone clarify who has used the new feature of leopard and little snitch how they compare? thanks!
     
Professional Poster
Join Date: Mar 2000
Location: New York, NY, USA
Status: Offline
Reply With Quote
Nov 7, 2007, 11:06 AM
 
Originally Posted by wobbly View Post
this sounds like it would make LittleSnitch redundant. Is that true? Does it give you the ability to block

-any network connection
-local network connection
-broadcast
-multicast

while also selecting a ports (or port range) and the protocols (UDP, TCP, any, etc.)

can someone clarify who has used the new feature of leopard and little snitch how they compare? thanks!
The Application Firewall in 10.5 is an either/or proposition. You either block all access to an application, or allow all.
The era of anthropomorphizing hardware is over.
     
Junior Member
Join Date: Mar 2005
Status: Offline
Reply With Quote
Nov 7, 2007, 11:21 AM
 
thanks! a bit dissapointing. From what i can see LIttle Snitch isn't available yet for Leopard only a beta version.
     
Posting Junkie
Join Date: Dec 2000
Status: Offline
Reply With Quote
Nov 7, 2007, 11:46 AM
 
Little Snitch is for outgoing traffic. Leopard's Application Firewall is for incoming traffic. The two don't overlap at all.

Leopard's application firewall also gives you no control over port numbers, and according to recent reports, lets certain ports through even if you tell it to block all incoming connections. I wouldn't bother with it, and would put your Mac behind a router or other hardware firewall instead so that you know your ports are blocked.

Ticking sound coming from a .pkg package? Don't let the .bom go off! Inspect it first with Pacifist. Macworld - five mice!
     
OAW
Professional Poster
Join Date: May 2001
Status: Offline
Reply With Quote
Nov 7, 2007, 12:02 PM
 
The problem with the Set access for specific services and applications setting is that the user has no idea what the DEFAULT BEHAVIOR is. Here's a simple scenario ....

I enable this setting in the firewall and add no applications to the list whatsoever. The million dollar question is are incoming connections blocked or not? If so, then that should be documented somewhere. And if not, then the protection is pretty weak since it doesn't exist until you happen to launch or manually configure various applications on your machine. And what happens if the incoming traffic isn't application specific?

Unfortunately, this linked document on the Apple Support site still doesn't address these fundamental issues.

OAW
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 05:12 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2