AirPlay, AirDrop, and Screen Sharing fail on MacBook due to built-in firewall

If your AirPlay, AirDrop, and/or Screen Sharing are not working, you may have the same issue I had (fixed now, with info below).


The problem (3 symptoms - same disease):

  • MacBook (running macOS Tahoe 26.6.2) could be seen on AirPlay but communication attempts would fail
  • AirDrop to Mac would fail even though MacBook could be seen on network
  • Screen Sharing would fail even though the request and "agree" dialog displays just fine.


The AirPlay and AirDrop failures were while trying to connect from my iPhone (iOS 26.6.2). For Screen Sharing it was actually noticed whilst trying to get technical support from Apple. In all three cases, I found turning the built-in firewall off would allow the services to work, but seconds after turning it back on, they would stop working again.


Solution:

Long story short, it turned out it was these applications which were set to blocked on the built-in firewall's allow list (System Settings->Network->Firewall->Options):

  • ContinuityCaptureAgent
  • ControlCenter
  • identityservicesd
  • nehelper
  • NetAuthSysAgent
  • rapportd
  • replicatord


Deleting them from the list was the solution that worked. They get automatically re-added with the correct setting as long as you have the setting that allows built-in software checked.

Simply changing the setting to 'allow' didn't seem to work - but removal worked ('-' button below the list).


I'm putting this information here because in the technical support chat and follow-up phone call, the primary suspect was my third party security app (Norton), but it turned out to be a red herring. The real problem was the built-in apps being blocked by the built-in firewall.


The lingering question:

Having never changed the firewall settings manually, the true mystery is how these apps got blocked in the first place. Could it be that the migration to macOS Tahoe from previous version is what caused the default settings to change?


MacBook Pro 16″, macOS 26.6

Posted on Sep 12, 2026 4:30 PM

Reply
11 replies

Sep 12, 2026 6:05 PM in response to FixApplePodcast

That’s a useful find, especially since turning the macOS firewall off immediately made all three services work.


As for how those Apple processes ended up blocked, I wouldn’t assume the Tahoe upgrade itself caused it unless the problem can be reproduced after another upgrade. macOS does allow individual apps and services to have explicit firewall rules, and configuration profiles or other software can also affect firewall settings. Apple’s own firewall documentation confirms both possibilities.


Your fix also makes sense: with “Automatically allow built-in software to receive incoming connections” enabled, removing the incorrect entries lets macOS add trusted built-in services back as allowed.


I’d keep an eye on those entries after the next macOS update. If they become blocked again without any manual change, that would be useful evidence of an update-related bug.

Sep 13, 2026 8:10 AM in response to FixApplePodcast

<< the primary suspect was my third party security app (Norton), ... >>


with good reason....

By far the easiest way to cause poor performance, instability, overheating and crashing is to install ANY third-party speeder-uppers, Cleaners, Optimizers, Third-party Virus scanners, Bit Torrent, or a VPN that you installed yourself. They are relentless in scanning your files, non-stop, looking for virus-like patterns in Everything, or looking for files that have changed. When completed, they do it all again.


The idea that a third party, with no special knowledge of the inner workings of MacOS, can somehow find a simple way to protect or speed up your computer — that is not already being done by MacOS itself — suggests that the MacOS developers are somehow "holding out on you". That is absurd.


You should remove any and all (other than Apple built-in) virus scanners, speeder uppers, optimizers, cleaners, App deleters or VPN packages you installed yourself, or anything of that ilk.

Sep 13, 2026 10:00 AM in response to FixApplePodcast

if you are behind a Router you control, you are already protected from unsolicited accesses by devices on the Internet. Devices on your local network use 'strictly-local' IP address from one of the three groups of IP addresses reserved for exactly that purpose, and your Router uses Network Address Translation (NAT) and state-wise Firewall to act as your agent on the Internet at large.


Only responses to connections you initiated get through the Router's state-wise Firewall are delivered to each device that initiated to connection. Unsolicited connections are discarded by default.


I expect that more than half the computers connected to the Internet are using an IP address from the range:

192.168.xxx.yyy.

Such address can NOT be Directly Routed and used for Direct Internet connection -- they must be used with a Router acting as your agent for the connection.


--------

The Firewall on your Mac is typically left OFF when using your Home/Office network, because the only additional protection it could possibly provide is from devices logged on your local network.


When on Public Wi-Fi, such as waiting at the Airport, it is prudent to enable your Mac's Firewall, because you may not be able to trust the Router's integrity or the friendly nature of the other devices connected to that network. (e.g., there may be somebody on the Airport Wi-Fi Network deliberately trying to hack other connections.)



Oct 9, 2026 1:51 PM in response to Tamlouie

Tamlouie wrote:
Why is it never been recommended to turn on the built in application Firewall? Specifically for home use devices.


Most home users are behind a Router that they Control/Trust. In that case, the Mac firewall is not needed, and can only slow things down.


--------

If you connect to Public Wi-Fi, such as at an Airport, where random users might be actively trying to steal your data, be sure to enable that Firewall on your Mac.


There is a time-saving way you can get different settings, for different places. It is called Network Locations.

I think it might also include Firewall settings


Use network locations on Mac - Apple Support





Sep 12, 2026 9:39 PM in response to FixApplePodcast

"AirPlay, AirDrop, and Screen Sharing fail on MacBook due to built-in firewall: If your AirPlay, AirDrop, and/or Screen Sharing are not working, you may have the same issue I had (fixed now, with info below).[...]"

-------


For reference...

Screensharing Issue on a Mac:

As a thought, for a workaround, speaking with Apple Support, turn on screensharing > open the Photos app > turn on speakerphone > and then speak with the Apple Support Rep, hovering over your screen as you go about troubleshooting things. This will allow the Apple Support Rep to see this firsthand, from YOUR perspective. See my User Tip: Screensharing your iPhone to Converse wit… - Apple Community


Sep 13, 2026 7:17 AM in response to FixApplePodcast

FixApplePodcast wrote:
Long story short, it turned out it was these applications which were set to blocked• on the built-in firewall's allow list (System Settings-&gt;Network-&gt;Firewall-&gt;Options):
ContinuityCaptureAgent
• ControlCenter
• identityservicesd
• nehelper
• NetAuthSysAgent
• rapportd
• replicatord

I have never seen any of those entries in the Firewall allow list. Not on any version of macOS up to Sequoia. Unless this is something brand new in Tahoe, there must be some other reason they were there.


It would be helpful if one or more Tahoe users could confirm whether or not they appear in Tahoe's firewall allow list.


If they are not, it would be good to look for other reasons they appeared there.

Sep 13, 2026 8:11 AM in response to FixApplePodcast

The key feature is that MacOS does not allow just 'any old junk' from anywhere to become Executable.

The second feature that makes the first one bulletproof is that malware can not attach itself to parts of the System.


MacOS shares a lot of the lock-down mechanisms developed for the iPhone. Applications are all sand-boxed with a list of the resources they require, and they cannot access anything outside their sandbox without crashing. Signed Applications are checked that they are from legitimate Developers, and Notarized Applications are delivered with the assurance that they have NOT been modified since their release by the Developer.


Introduced just before MacOS 12 Monterey, the system is now on a Separate, cryptographically—signed ‘sealed System Volume’. The Mac runs off read-only snapshots of this volume, which is not writeable using ordinary means. Any unauthorized changes to the crypto-signed volume are very quickly detected and you are alerted.


So you could store just about every malware known to mankind on your Mac, and your Mac would not get infected spontaneously. Scanning for virus-like patterns might make you feel a little better now, but non-stop scanning is outdated nonsense, and a tremendous waste of resources.


Nothing can become Executable Unless/Until you supply your Admin password to "make it so".


Some users may prefer to create a new Admin User with a unique password (be sure to write that password down somewhere). Then log in as the new Admin and demote their daily-use account to an "ordinary" non-Admin account. In that case, nothing can be installed "by accident" because you will need to provide both the Admin Username AND Password to install anything. This gives you an additional step to pause and think about whether you really want to do this.


Effective defenses against malware and ot… - Apple Community

Effective defenses against malware and ot… - Apple Community


AirPlay, AirDrop, and Screen Sharing fail on MacBook due to built-in firewall

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.