Add a new Firewall payload configuration to an existing profile

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

To create Mac Firewall policy

Request URL

https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/macfirewallpolicy

Scope

MDMDeviceMgmt.CREATECopied!

Header

Authorization: d92d4xxxxxxxxxxxxx15f52

Request Parameters

- Request Headers

Content-TypestringMandatory
application/jsonapplication/jsonCopied!
AcceptstringMandatory
application/jsonapplication/jsonCopied!

- Path Parameters

profile_idstringMandatory

Unique identifier of the profile. Obtain from the Create Profile or Get Profiles response

- Request Body

application/json
JSON Object
Hide Sub-Attributes
enable_firewallintegerMandatory

Enable or disable the macOS application firewall. Allowed values: 0=Disable, 1=Enable

block_all_incomingintegerOptional

Block all incoming connections except those required for basic internet services (DHCP, Bonjour, IPSec). Allowed values: 0=Disable, 1=Enable, 2=User Controlled

enable_stealth_modeintegerOptional

Enable stealth mode to prevent the Mac from responding to probing requests (ICMP ping). Allowed values: 0=Disable, 1=Enable, 2=User Controlled

allow_signed_appintegerOptional

Automatically allow downloaded signed software to receive incoming connections. Requires macOS 12.3+. Allowed values: 0=Block, 1=Allow, 2=User Controlled

allow_signedintegerOptional

Automatically allow built-in signed software to receive incoming connections. Requires macOS 12.3+. Allowed values: 0=Block, 1=Allow, 2=User Controlled

enable_loggingintegerOptional

Enable firewall logging. Allowed values: 0=Disable, 1=Enable

logging_optionintegerOptional

Firewall logging detail level. Allowed values: 0=Throttled, 1=Brief, 2=Detail

restricted_appsJSON ArrayOptional

List of app-specific firewall rules controlling incoming connections for individual applications

Show Sub-Attributes
JSON Object
Show Sub-Attributes
app_group_idlongMandatory

App group ID of the application. Obtain from the Apps API response

allow_incoming_connectionintegerMandatory

Whether to allow incoming connections for this app. Allowed values: 0=Block, 1=Allow

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request POST \
  --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/macfirewallpolicy \
  --header 'Accept: application/json' \
  --header 'Authorization:  d92d4xxxxxxxxxxxxx15f52' \
  --header 'Content-Type: application/json' \
  --data '{"enable_stealth_mode":2,"allow_signed_app":1,"block_all_incoming":2,"allow_signed":1,"enable_firewall":1,"restricted_apps":[{"allow_incoming_connection":0,"app_group_id":6967000000047041}]}'

Sample Request Body

Add Firewall payload to the profile with stealth mode and a blocked app

Copied!
  {
    "enable_stealth_mode": 2,
    "allow_signed_app": 1,
    "block_all_incoming": 2,
    "allow_signed": 1,
    "enable_firewall": 1,
    "restricted_apps": [
      {
        "allow_incoming_connection": 0,
        "app_group_id": 6967000000047041
      }
    ]
  }
                
Show full

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object
Hide Sub-Attributes
payload_idlong

Unique identifier for the created payload item

enable_firewallstring

Whether the macOS application firewall is enabled. Values: 0=Disabled, 1=Enabled

block_all_incomingstring

Whether all incoming connections are blocked. Values: 0=Disabled, 1=Enabled, 2=User Controlled

enable_stealth_modestring

Whether stealth mode is enabled. Values: 0=Disabled, 1=Enabled, 2=User Controlled

allow_signed_appstring

Whether downloaded signed software is allowed incoming connections. Values: 0=Block, 1=Allow, 2=User Controlled

allow_signedstring

Whether built-in signed software is allowed incoming connections. Values: 0=Block, 1=Allow, 2=User Controlled

enable_loggingstring

Whether firewall logging is enabled. Values: 0=Disabled, 1=Enabled

logging_optionstring

Firewall logging detail level. Values: 0=Throttled, 1=Brief, 2=Detail

restricted_appsJSON Array

List of app-specific firewall rules with resolved app details

Show Sub-Attributes
JSON Object
Show Sub-Attributes
app_group_idlong

App group ID of the application

app_namestring

Display name of the application

bundle_idstring

Bundle identifier of the application

allow_incoming_connectionstring

Whether incoming connections are allowed. Values: 0=Blocked, 1=Allowed

Possible Response Codes

200HTTP code

Sample Response: HTTP 200

Firewall payload successfully added

Copied!
  {
    "enable_stealth_mode": "2",
    "payload_id": 6967000001030034,
    "allow_signed_app": "1",
    "block_all_incoming": "2",
    "allow_signed": "1",
    "enable_firewall": "1",
    "restricted_apps": [
      {
        "app_name": "Calculator",
        "allow_incoming_connection": "0",
        "bundle_id": "com.apple.calculator",
        "app_group_id": 6967000000047041
      }
    ]
  }
                
Show full

Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes

Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.