Discussion in 'macOS' started by yettimillan, Nov 25, 2009.

    Hi ive just been looking in system preferences and saw my firewall was off. I immediately turned it on. I don't know why it was off, i have never turned it off before, im really worried now, how can i check for bad things on my mac?
    It's off by default. So if you never turned it on it would of course be off. Nothing to worry about. Most people are reasonably protected by their router anyways.
    Speaking of Firewall, do you guys also get frequent Console logs with "Stealth Mode Connection Attempt to UDP...."? It's kind of annoying and makes me anxious, but from what I read somewhere it's just my router trying to establish connection or something?
    Does this mean people can hack my computer then or is it still secure.

    Should I have the firewall on or off?
    Short answer no
    Long answer yes.

    Generally speaking OSX is secure anyways and if you have various services turned off, such as SSH, remote login, FTP, etc. There's little most people can do to hack into your machine. Plus most routers have a firewall as well. With that said, if you feel you need that extra layer of protection, go ahead and turn it on. If someone wants to get in, they still probably can but it will take a lot of work.

    fwiw, I have issues with the firewall turned on, connections issues with vpn and remote connectivity to my work's servers. So I keep it off and have had it off for years because I have said services off and my router is sufficient to protect me and so far, it hasn't failed me
    If you have more details, we could answer that. You could
    quote a line from the log (and exclude your own IP address).
    The firewall in System Prefs in 100% medicore, don't expect it to be any help defending you. Google for "ipfw leopard" for help configuring the proper firewall.
    I'm sorry for replying kind of late, but here are two of the IP addresses I have noticed trying to establish connection to TCP:

    For the latter IP address I just checked Console and there were like 40-50 consecutive msgs saying "Firewall [54] Stealth Mode connection attempt to TCP [my IP] from..."

    Is this anything I should be concerned about then?

    P.S.: to miles01110: I read what you posted in that link, so I'm hoping it really isn't an actual attempt of hacking...

