firewall OSX 10.5.5 help

02-04-2009, 04:10 PM
I have some fairly basic questions about firewall protection.
My OS is MAC OSX 10.5.5. I have the Application firewall turned on and 'stealth' mode checked. I connect to the world via DSL using a modem with a (firmware?) default NAT firewall.

It is my understanding that the underlying unix firewall ipfw is still active (this from the apple support site). In googling the subject I find a bewildering amount of info involving iptables, ipfilter, shell scripts, Launch daemons and various config files etc all of which are absent on my machine.

So my questions are:
1) how can I tell if the ifpw fire wall is running? ipfw list shows 2 rules but the ipfw.log is empty
2) if ipfw is not running, how do I start it?
3) where can I find detailed step by step instructions, preferably specific to Mac OSX, for rules that will explain the syntax, the significance and why I should have the rule?
and finally
4) how can I safely test my firewall?

Many thanks in advance

02-04-2009, 05:58 PM
My understanding is that in OS X 10.5.x Leopard, ipfw is still running, but "turned off", with it's sole rule:
65535 allow ip from any to any

If you still want to use ipfw, there's a good ruleset here (http://securosis.com/publications/ipfw.html) specifically for Leopard.

In Leopard, Apple is instead using an application firewall (http://support.apple.com/kb/HT1810).