Where Is the macOS Packet Filter Config?
macOS packet filter reads its rules from pf.conf, disabled by default with a friendly firewall in front of it.
Last updated
Beneath the System Settings firewall checkbox sits pf, a real packet filter inherited from OpenBSD. Its config file defines tables, scrubbing, NAT, and filter rules in a terse language.
Stock systems ship the filter off with a permissive file, so most Macs never touch it. Developers running local servers and admins shaping traffic meet it properly. The GUI firewall and pf coexist, with pf handling anything the checkbox cannot express.
Where macOS stores this, by platform
/etc/pf.conf
Default rule set lives here, usually permissive and inactive. Validate edits with pfctl check commands before loading.
Frequently asked questions
Is pf active on a stock Mac?
Almost always the GUI firewall. pf.conf ships with an empty rule set and the packet filter stays off unless enabled deliberately. Server admins and developers turn it on; desktops rarely need it.
How do I test rules safely?
Validate with pfctl -n -f before loading anything live. A bad rule set applied remotely locks you out with no recourse. Test locally, keep a revert handy, and mind SSH access first.
Notice an outdated path? Let us know.