Mac OS X Firewall Configuration: what's the easiest way to do it?

On celebration I require to set up the firewall on OS X equipments (10.5), and also I've been attempting to identify the most effective (read: very easy without giving up way too much control) means to do it.

Until now it feels like my alternatives are:

  • Apple is constructed - in energy (System Preferences, Security, Firewall). It is obtained the "easy" down, yet (unless there is something I'm missing out on) I would certainly such as a little bit extra control
  • Learning ipfw. It would certainly offer me all the control I desire, yet it feels like it is obtained a high understanding contour and also I would certainly be bothered with mistakenly obtaining it incorrect
  • "Some" visual energy. Until now all I've located is Firewall Builder, which isn't free and also appears rather intricate (yet the intricacy might deserve it) But there might be extra, which I have not located

So, what would certainly my best choice be?

Here is an instance ipfw ruleset to have fun with (& get going with finding out ipfw):

Well, you are requesting for 2 various points below. Absolutely the "easiest" point to do would certainly be to make use of Apple is constructed - in GUI. For the majority of points that need to suffice, as long as you are doing access filtering system and also simply intend to open a couple of solutions it need to be ample.

If you desire even more control, I assume ipfw is absolutely worth the moment financial investment. Nonetheless, to utilize it properly, you need to have a strong grip of existing networking principles and also methods. Or else it is really simple to make blunders and also leave on your own open.

If you intend to examine the performance of your firewall and also solution security from the outdoors, I advise making use of devices like nmap and also nessus in either instance.

There is additionally WaterRoof on the visual arrangement end, it existed at my neighborhood MUG a number of months back and also the response from individuals that've attempted it has actually declared. It is additionally free.

