Help with configuration of MacBook Firewall Settings

I was wondering if anyone in the community or the Apple support team has experience on how to properly configure the firewall settings on a Mac to make it resistant against unauthorized access including airdrop, ssh, remote access, remote scripting which are enabled by default on my brand new Mac.


Below is a screenshot of how my Mac is currently configured which has led to several phishing attacks, unwanted shortcuts installed, remote scripting found and more.


Ideally knowing which of the incoming incoming connection types to turn off and leave on would be appreciated as I don't use airdrop, remote access, Automator nor shortcuts.


[Edited by Moderator]

MacBook Air (M4, 2025)

Posted on Aug 16, 2026 3:27 PM

Reply
Question marked as Top-ranking reply

Posted on Aug 16, 2026 7:41 PM

The concerns you describe are unrelated to the macOS application firewall, so as MrHoffman alluded to you would be best served by posting a brand new question with a descriptive title expressing those concerns.


Prior to posting that new question, I recommend downloading and running EtreCheck and including its report. Instructions are here: How to use the Add Text Feature When Posting Large Amounts of Text, i.e. an Etrecheck Report - Apple Community. Should you choose to do that please follow those instructions with care. It's ok to include a link back to this Discussion if you think it would be useful.


You can of course continue this Discussion, but a brand new question with zero replies always elicits more interest on this site. Besides, the title with its reference to the macOS application firewall is already answered: it conveys little to no benefit, except for certain circumstances in which a Mac is used in a shared network environment e.g. a dormitory or communal living. Unless you know of and can articulate justification for using the macOS application firewall I recommend just turning it off.


Moreover, it does absolutely zip to thwart phishing attacks, which at their core require nothing more technologically sophisticated than an email or even a phone call. On that subject I highly recommend reading MrHoffman's User Tip Better Securing Your Data, and Apple Account. From a consumer device security standpoint Macs are effectively impenetrable, while human beings remain the abundant, soft and lucrative target they have always been.


As for your specific questions, I suggest relying upon "Malwarebytes" or things like it is inappropriate and inconsistent with safe computing practices. Correlating phishing attacks with access to sensitive files will require more research. EtreCheck is likely to suggest answers to your other questions.

20 replies
Question marked as Top-ranking reply

Aug 16, 2026 7:41 PM in response to Techguru45

The concerns you describe are unrelated to the macOS application firewall, so as MrHoffman alluded to you would be best served by posting a brand new question with a descriptive title expressing those concerns.


Prior to posting that new question, I recommend downloading and running EtreCheck and including its report. Instructions are here: How to use the Add Text Feature When Posting Large Amounts of Text, i.e. an Etrecheck Report - Apple Community. Should you choose to do that please follow those instructions with care. It's ok to include a link back to this Discussion if you think it would be useful.


You can of course continue this Discussion, but a brand new question with zero replies always elicits more interest on this site. Besides, the title with its reference to the macOS application firewall is already answered: it conveys little to no benefit, except for certain circumstances in which a Mac is used in a shared network environment e.g. a dormitory or communal living. Unless you know of and can articulate justification for using the macOS application firewall I recommend just turning it off.


Moreover, it does absolutely zip to thwart phishing attacks, which at their core require nothing more technologically sophisticated than an email or even a phone call. On that subject I highly recommend reading MrHoffman's User Tip Better Securing Your Data, and Apple Account. From a consumer device security standpoint Macs are effectively impenetrable, while human beings remain the abundant, soft and lucrative target they have always been.


As for your specific questions, I suggest relying upon "Malwarebytes" or things like it is inappropriate and inconsistent with safe computing practices. Correlating phishing attacks with access to sensitive files will require more research. EtreCheck is likely to suggest answers to your other questions.

Aug 16, 2026 10:11 PM in response to Techguru45

The literal interpretation of the original question describes a catastrophic security breach, and remediation doesn’t start with firewall settings. You remediate such breaches by wiping and reloading from known-good sources, amd addressing the vulnerabilities prior to going back online.


What add-on security apps might be installed here, including any add-on anti-malware, add-on VPNs, and other such? Folks posting these can have a selection of potentially-problematic security apps added, too.


As for addressing your security, two-factor authentication, robust and non-reused passwords everywhere, reviewed and resolved the Apple security recommendations for your Mac, and related steps? (Related: Better Securing Your Data, and Apple Acco… - Apple Community)


Redecorating the firewall after a reported breach, not so much.

Aug 19, 2026 6:03 PM in response to Techguru45

Techguru45 wrote:
I noticed the local storage was almost full after 3 months of minimal use - discovered the cause was that business Apple accounts aren't compatible with iCloud hence why the local storage was being utilized instead.

This seems reasonable enough, but is this a work computer or personal computer? Is it managed by your employer? If you have any type of access to the kinds of sensitive materials that you hinted, for either government or industry work of this sort, the entire computer has to be completely separate from personal items. The type of mixing of personal and work IDs and files and accounts is strictly forbidden. Did you really do this?

I switched to using my personal iCloud to address the above - however for some reason the cache continues to load no matter how many times I erase and run a clean install of Tahoe.

So above comments. Also, your clean install has to follow this What to do before you sell, give away, trade in, or recycle your Mac - Apple Support otherwise it will retain vestiges of the old system.

In addition to my Mac randomly crashing, I started noticing regardless of which browser I used, my Mac would redirect me to other countries when trying to access Google.com.

There are innocuous reasons this can happen, it has happened to me after or during travel.

I discovered the remote scripting and shortcuts under the "sharing" section and bizarre behavior such as apps randomly launching (Apple Music, podcasts).

Also not that unusual. Sometimes my Mac launches Music for reasons unknown to me when I connect a dock and external monitor.

found out recently a lot of the caches are hidden intentionally by Apple.

Not sure how this is relevant to "hacking."

I do have access to sensitive and confidential files for my industry in tech and partnerships under NDA and within 24 hours of getting access to those files I received multiple phishing calls and emails from people claiming they were apple support - I reported it to Apple and they confirmed it indeed was phishing attempts.

A number of the things you described above would never be tolerated for an employee with access to those types of files. Phishing is not that hard to mitigate, one has to be careful not to fall for it. But it is very common.

In addition to the above, the ldap and Active Directory seem to have additional entries that look unfamiliar

I don't see this as proof of hacking.


"hackers found a way to make my son the admin of my computer as a workaround to hack into my machine and make me a standard user"


Wait. Your son has an account on your work computer? That is a huge no-no for any government or industry computer with "sensitive files." I am even surprised you are even allowed to do things like that on a computer with such "sensitive" data.


Don't be insulted: but if you gave your son an account on this computer, that is also used for all kinds of sensitive and NDA work, how do you know that your son did not do some of these things himself?


Bottom line: with an internal SSD, if you followed follow this What to do before you sell, give away, trade in, or recycle your Mac - Apple Support and then created a TOTALLY NEW Apple ID with 2-factor and used FileVault to encrypt the drive to use going forward, I do not see how any vestige of past anything would be present on this computer. All settings would have to be recreated from scratch. With strong passwords, 2-factor, and no remote access or sharing of any sort, I don't see how any hacker could get in. Your home network might be a vulnerability but any type of secure work done remotely (off site) for virtually any government or industrial entity comes with a very robust VPN professionally configured by the employer for high security.


Aug 16, 2026 4:31 PM in response to Techguru45

Techguru45 wrote:
…Below is a screenshot of how my Mac is currently configured which has led to several phishing attacks,

Phishing is a means of gaining credentials and gaining access.


Phishing activity is independent of local security.


(And if it’s not independent, your local security is seemingly already catastrophically breached.)

unwanted shortcuts installed,

How you investigated how that happened, including comparing a default install?


If you’re somehow getting shortcuts appearing, your security is catastrophically compromised.

remote scripting found and more.

this “remote scripting” was reported by what tools? What sort of remote scripting?

Ideally knowing which of the incoming incoming connection types to turn off and leave on would be appreciated as I don't use airdrop, remote access, Automator nor shortcuts.

Catastrophically compromised security is not remediated through firewall settings.


What add-on security apps might be installed here, including any add-on anti-malware, add-on VPNs, and other such?


Two-factor authentication, robust and non-reused passwords everywhere, reviewed and resolved the Apple security recommendations for your Mac, and related steps?


Are you a political dissident, investigative journalist, with access to sensitive or classified data, access to financial data, active in military or defense, senior in government or private organizations, or of great personal interest to a very well-funded organization willing to invest immense wealth as part of their interest in you?

Aug 16, 2026 5:07 PM in response to MrHoffman

Appreciate your reply and analysis.


Perhaps me providing a timeline would be more helpful as I have been in tech and owned a Mac my entire life with no issues so seeing how my brand new custom MacBook Air with an upgraded memory chip had been crashing when barely running any tasks started to catch my attention.


1) Next, I noticed the local storage was almost full after 3 months of minimal use - discovered the cause was that business Apple accounts aren't compatible with iCloud hence why the local storage was being utilized instead.


2) Apple went ahead and replaced the logic board and I switched to using my personal iCloud to address the above - however for some reason the cache continues to load no matter how many times I erase and run a clean install of Tahoe


3) In addition to my Mac randomly crashing, I started noticing regardless of which browser I used, my Mac would redirect me to other countries when trying to access Google.com


4) I discovered the remote scripting and shortcuts under the "sharing" section and bizarre behavior such as apps randomly launching (Apple Music, podcasts)


5) I installed malwarebytes to see if I could diagnose and identify the caches but found out recently a lot of the caches are hidden intentionally by Apple.


6) I do have access to sensitive and confidential files for my industry in tech and partnerships under NDA and within 24 hours of getting access to those files I received multiple phishing calls and emails from people claiming they were apple support - I reported it to Apple and they confirmed it indeed was phishing attempts


7) My Mac is under Apple+ care but since I already replaced the logic board with no success, I don't really see any other solution but to perhaps get a replacement since it appears the actual hard drive which is soldered to the motherboard may be corrupted


8) In addition to the above, the ldap and Active Directory seem to have additional entries that look unfamiliar


I've tried to uninstall apps I don't use like Automator and shortcuts but lack the permission to do so.


So perhaps you are correct that my Mac's "local security is seemingly already catastrophically breached" but there must be a remedy specially considering it's a brand new Mac under Apple+ warranty?


Aug 16, 2026 5:40 PM in response to Techguru45

Eight issues seemingly largely unrelated to the original question, this will involve data access and discussions and topics unavailable or inappropriate for posting around here or in most other forums (sensitive info, etc), as well as providing you with some supporting details around troubleshooting and some info how macOS itself operates. (e.g. Deleting macOS constituent files, for instance, hasn’t been possible for quite some time.)

Aug 16, 2026 9:31 PM in response to John Galt

Thank you for providing that information as that's the first time I've heard of the tool "EtreCheck", will surely check it out.


In regards to my original question however, do all those preexisting connections in my screenshot that are currently toggled on required?


Im trying to reduce the attack surface so wondering if "Allow incoming connections" for all of those are truly needed.


Thank you all again for your help and insights, I appreciate it.

Aug 16, 2026 10:35 PM in response to MrHoffman

So I believe what you stated is exactly the area and loop that I'm stuck in.


"You remediate such breaches by wiping and reloading from known-good sources, and addressing the vulnerabilities prior to going back online."


My process and attempts to remediate the situation to date have been ---> erase all data and settings ----> run disk utility and first aid on all volumes ----> reinstall Tahoe.


However the above process still results in my Mac loading previous caches.


I've done some more digging and it seems that the above process doesn't fully remove hidden caches such as those residing in the ~/library/caches folder.


There are a few videos on YouTube with others experiencing the same issue stating it could be a result of:


  • Local Time Machine Snapshots
  • Virtual Memory
  • System & App Caches
  • iCloud & Mail Caches
  • Orphaned Snapshots & Logs


So circling back to your point, even if I were to reinstall from say the Apple Store directly in person, wouldn't the above issues still persist given how macOS operates and handles memory, log files, etc?


I typically can troubleshoot and solve 99% of tech problems on my own but the issues with this Mac even have the Apple support team stating it's a unique situation.

Aug 17, 2026 6:47 AM in response to Techguru45

Are they required? No, of course not. But a number of networking services most Mac users take for granted won't work. Printing won't work, iPhone connections won't work, file sharing... etc.


If you really don't want those services then disconnect your Mac from the network and it'll be like 1985 all over again, but without so much as a floppy disk drive to get anything into or out of that Mac.

Aug 17, 2026 8:28 AM in response to John Galt

So originally as mentioned the goal was to keep my Mac separate from my personal iPhone device but unfortunately Apple business IDs aren't compatible with iCloud.


Thus, I prefer and also wish to separate my work machine and my personal iPhone.


Printer sharing, remote access, airplay are all things I never have used.


Whats odd is that my custom brand new Mac with an upgraded 32 gigs of memory operates at the speed of a snail whether it's loading apps, browsing the web, working on client websites, basically any task.


I'm used to running multiple windows at a time specially during client meetings so not sure if it's the hard drive that's been permanently corrupted or the fact that MacBook airs from what I've now found out, don't have internal fans and as a result instead throttle processes.


Based on everyone's input, would the best course of action at this point be to exercise my Apple+ care warranty and get a brand new replacement given how it's been 6 months of troubleshooting in addition to the logic board replacement with no success in solving the myriad of issues listed?


Thank you all again for your help and support. I've received more insight within this thread than the last 6 months of speaking to Apple support and browsing other forums combined.



Aug 17, 2026 9:04 AM in response to Techguru45

Techguru45 wrote:
So I believe what you stated is exactly the area and loop that I'm stuck in.
"You remediate such breaches by wiping and reloading from known-good sources, and addressing the vulnerabilities prior to going back online."
My process and attempts to remediate the situation to date have been ---> erase all data and settings ----> run disk utility and first aid on all volumes ----> reinstall Tahoe.
However the above process still results in my Mac loading previous caches.
I've done some more digging and it seems that the above process doesn't fully remove hidden caches such as those residing in the ~/library/caches folder.
There are a few videos on YouTube with others experiencing the same issue stating it could be a result of:
Local Time Machine Snapshots
• Virtual Memory
• System & App Caches
• iCloud & Mail Caches
• Orphaned Snapshots & Logs
So circling back to your point, even if I were to reinstall from say the Apple Store directly in person, wouldn't the above issues still persist given how macOS operates and handles memory, log files, etc?
I typically can troubleshoot and solve 99% of tech problems on my own but the issues with this Mac even have the Apple support team stating it's a unique situation.




To summarize, this started out as a firewall question with some potential confusion or possibly misstatements around correlation and causation, then expanded out to eight largely-unrelated concerns, and is now reportedly a breach remediation from unknown or unspecified vulnerabilities and including a macOS 26 reinstall, with some unfamiliarity with macOS system integrity protection, and this all with some security-related questions asked and left unanswered.


To borrow your tech-problems percentages, for what you yourself seemingly view as a 1% issue, where your knowledge and experience are lacking, it is seemingly now time to get some specific and tailored assistance for the security issues are being reported here. Given the reported potential breach, this assistance means sensitive discussions, reviews of the situation and of the response, and potentially means forensics if there’s anything left to poke at.


This so you can both focus on your 99% and on whatever tasks or services originally involving those sensitive documents, and the assistance for reestablishing security, and assistance for the creation of a formal breach report that will quite possibly be required secondary to what may have been a compromise of those sensitive documents.


As for caches, those are normal and expected. Computers were last largely isolated in the 1980s, and things have become far more interconnected and interdependent, particularly since the advent of Ethernet, and the rise of distributed and client-server computing. Detecting what if any compromises might still exist here is akin to proving a negative, too. Difficult, at best. And that's assuming there was a compromise, and not some other more benign sequence of events.


But if you’re somehow being exploited through AirDrop as you had been concerned about, you have much larger issues with your apparent value to your adversaries, too. Issues that will need assistance.


As for the firewall, shut off everything, and see what breaks.


As for this situation? This all keeps getting bigger.

Aug 17, 2026 1:47 PM in response to Techguru45

Thus, I prefer and also wish to separate my work machine and my personal iPhone.


Good idea. A parade of horribles can — and have — occurred as a result of commingling a Mac and its associated Apple Account for both business and personal reasons. Never commingle the two. Reserve an Apple Account and business iCloud account along with their associated devices exclusively for business purposes, and use a separate personal Apple Account for personal use. Buy separate devices on your own if you must, bearing in mind responsible businesses will purchase, own, and maintain Macs / iPhones / iPads for their associates. Aside from being a good common sense practice, a business will increase its liability exposure otherwise.


Conversely, it is irresponsible for an employer to expect their employees to purchase and maintain equipment (Macs / iPhones / iPads) for business use. In addition to assuming a degree of technological sophistication such practices place personal, legal, and even criminal liability directly on their employees — individuals who cannot be expected to understand or defend themselves from violations of business or criminal law over practices they have no ability to control.


Hopefully I made that point abundantly clear.


Based on everyone's input, would the best course of action at this point ...


Erase the Mac as though you were going to sell it to someone else, and then set it up as a new Mac dedicated strictly for business use. Don't use your personal information meaning create and sign in under a completely separate "business only" Apple Account, separate email addresses... etc. Instructions are here: What to do before you sell, give away, trade in, or recycle your Mac


... to exercise my Apple+ care warranty and get a brand new replacement given how it's been 6 months of troubleshooting in addition to the logic board replacement with no success in solving the myriad of issues listed?


Apple does not typically replace Macs. They repair them, and not always on site, in which case it may take days to complete. Weeks, conceivably. Another reason not to use your personal Mac for business use. Have the business supply you with a temporary replacement while the other one is in the shop. That's what responsible businesses do... even if you are its sole proprietor.


Having said that if you erase and reconfigure the Mac as new, your existing problems are likely to be resolved.

Aug 18, 2026 4:37 PM in response to John Galt

I believe the reason the "erase and reconfigure the Mac as new" option hasn't resolved the issues is perhaps due to the what I ran across below stated on apples website:


Erase and reformat a storage device in Disk Utility on Mac


"Note: With a solid-state drive (SSD), secure erase options are not available in Disk Utility. For more security, consider turning on FileVault encryption when you start using your SSD drive"

------------------------------------


Given the above, does this essentially indicate that the only option is to have the Mac sent in to have the SSD repaired seeing how the logic board replacement and multiple attempts by apple support to run disk utility, reformat and run first aid still hasn't resolved the issues?



Aug 18, 2026 4:56 PM in response to Techguru45

SSDs work differently from SSDs. There is no analog to an overwrite, not that overwriting is particularly reliable with HDDs either. The whole sector-overwrite scheme dates back to defending against sloppy head tracking from hardware in the 1980s and earlier; on floppies and ilk.


Disk encryption is automatically enabled in all T2 and Apple silicon Macs, and you will have undoubtedly had FileVault enabled to use a better password for that encryption.


If you suspect your adversaries might be or are using exploits that can provide persistence past a reset and past a reinstall, replace this gear entirely, anonymously sourcing new gear, and creating new accounts.


Get formal assistance with your data security requirements too, tailored for your particular perceived risks.


Any attacks scavenging storage or that utilize firmware- or hardware-level persistence are far past what help can be offered around here.



Aug 18, 2026 5:11 PM in response to Techguru45

Did you in fact erase the Mac and reconfigure it as a brand new device? And if so, do the problems still manifest?


And, if so, did you download and run EtreCheck? If you posted a brand new question containing its report here or there I have not noticed it.


Please note that EtreCheck is not a panacea. It's just a reporting tool that in itself fixes nothing — and even in the unlikely event of some intrusive event which seems to be your concern, it cannot conclusively prove its absence. Logically speaking, nothing can do that. EtreCheck can only suggest some actions that may be justified. Besides, if you completely erased the Mac its report is likely to be boring. It does perform certain hardware tests that might be of interest.


"Secure Erase" has been deprecated for about a decade now. It's irrelevant to your concerns so don't become distracted by it.

Help with configuration of MacBook Firewall Settings

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.