AndreGB

Q: OS X Server El Captan packet filter not working?

Hello guys,

 

I've enabled both the packet filter firewall and the Adaptive Firewall on OS X Server following these guides from Apple itself.

OS X Server: Packet filter rules do not load - Apple Support

How to enable the adaptive firewall on OS X Server - Apple Support

 

However, I noticed that packet filter will not create and/or use any of the tables specified in the rules. For instance, the command sudo pfctl -s Tables will not show any tables at all. Needless to say, the packet filter isn't working. The IPs I've configured as blacklisted are still getting through. Has anyone experienced anything similar?

Mac mini, OS X El Capitan (10.11.4)

Posted on May 1, 2016 9:25 AM

Close

Q: OS X Server El Captan packet filter not working?

  • All replies
  • Helpful answers

  • by Linc Davis,

    Linc Davis Linc Davis May 2, 2016 10:15 AM in response to AndreGB
    Level 10 (207,990 points)
    Applications
    May 2, 2016 10:15 AM in response to AndreGB

    The default configuration of the adaptive firewall doesn't actually work, though the documentation doesn't bother to mention that fact. Besides following those instructions, you have to edit the file /etc/af.plist. Change the value of the key "firewall_address" from the default "127.0.0.1" to the IP address of the interface on which the server listens.

  • by AndreGB,

    AndreGB AndreGB May 2, 2016 8:05 PM in response to Linc Davis
    Level 1 (9 points)
    Servers Enterprise
    May 2, 2016 8:05 PM in response to Linc Davis

    Thanks, Linc, I'll give it a try. In any case pf still isn't creating any tables. Not even af-created tables.

     

    sudo pfctl -s Tables

    still shows nothing (I do not think this is pf's correct behavior)