Modify the configuration of a Firewall payload item within a profile

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

To modify Mac Firewall policy payload item

Request URL

https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/macfirewallpolicy/payloaditems/{payload_id}

Scope

MDMDeviceMgmt.UPDATECopied!

Header

Authorization: d92d4xxxxxxxxxxxxx15f52

Request Parameters

- Request Headers

Content-TypestringMandatory
application/jsonapplication/jsonCopied!
AcceptstringMandatory
application/jsonapplication/jsonCopied!

- Path Parameters

profile_idstringMandatory

Unique identifier of the profile. Obtain from the Create Profile or Get Profiles response

payload_idstringMandatory

Unique identifier of the payload item. Obtain from the Get Payload Item IDs response

- Request Body

application/json
JSON Object
Hide Sub-Attributes
enable_firewallintegerOptional

Enable or disable the macOS application firewall. Allowed values: 0=Disable, 1=Enable

block_all_incomingintegerOptional

Block all incoming connections except those required for basic internet services (DHCP, Bonjour, IPSec). Allowed values: 0=Disable, 1=Enable, 2=User Controlled

enable_stealth_modeintegerOptional

Enable stealth mode to prevent the Mac from responding to probing requests (ICMP ping). Allowed values: 0=Disable, 1=Enable, 2=User Controlled

allow_signed_appintegerOptional

Automatically allow downloaded signed software to receive incoming connections. Requires macOS 12.3+. Allowed values: 0=Block, 1=Allow, 2=User Controlled

allow_signedintegerOptional

Automatically allow built-in signed software to receive incoming connections. Requires macOS 12.3+. Allowed values: 0=Block, 1=Allow, 2=User Controlled

enable_loggingintegerOptional

Enable firewall logging. Allowed values: 0=Disable, 1=Enable

logging_optionintegerOptional

Firewall logging detail level. Allowed values: 0=Throttled, 1=Brief, 2=Detail

restricted_appsJSON ArrayOptional

List of app-specific firewall rules controlling incoming connections for individual applications

Show Sub-Attributes
JSON Object
Show Sub-Attributes
app_group_idlongMandatory

App group ID of the application. Obtain from the Apps API response

allow_incoming_connectionintegerMandatory

Whether to allow incoming connections for this app. Allowed values: 0=Block, 1=Allow

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request PUT \
  --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/macfirewallpolicy/payloaditems/{payload_id} \
  --header 'Accept: application/json' \
  --header 'Authorization:  d92d4xxxxxxxxxxxxx15f52' \
  --header 'Content-Type: application/json' \
  --data '{"enable_stealth_mode":1,"allow_signed_app":1,"block_all_incoming":2,"allow_signed":1,"enable_firewall":1,"restricted_apps":[{"allow_incoming_connection":0,"app_group_id":6967000000047041}]}'

Sample Request Body

Modify Firewall payload — change stealth mode and update blocked apps

Copied!
  {
    "enable_stealth_mode": 1,
    "allow_signed_app": 1,
    "block_all_incoming": 2,
    "allow_signed": 1,
    "enable_firewall": 1,
    "restricted_apps": [
      {
        "allow_incoming_connection": 0,
        "app_group_id": 6967000000047041
      }
    ]
  }
                
Show full

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object
Hide Sub-Attributes
payload_idlong

Unique identifier of the payload item

enable_firewallstring

Whether the macOS application firewall is enabled. Values: 0=Disabled, 1=Enabled

block_all_incomingstring

Whether all incoming connections are blocked. Values: 0=Disabled, 1=Enabled, 2=User Controlled

enable_stealth_modestring

Whether stealth mode is enabled. Values: 0=Disabled, 1=Enabled, 2=User Controlled

allow_signed_appstring

Whether downloaded signed software is allowed incoming connections. Values: 0=Block, 1=Allow, 2=User Controlled

allow_signedstring

Whether built-in signed software is allowed incoming connections. Values: 0=Block, 1=Allow, 2=User Controlled

enable_loggingstring

Whether firewall logging is enabled. Values: 0=Disabled, 1=Enabled

logging_optionstring

Firewall logging detail level. Values: 0=Throttled, 1=Brief, 2=Detail

restricted_appsJSON Array

List of app-specific firewall rules with resolved app details

Show Sub-Attributes
JSON Object
Show Sub-Attributes
app_group_idlong

App group ID of the application

app_namestring

Display name of the application

bundle_idstring

Bundle identifier of the application

allow_incoming_connectionstring

Whether incoming connections are allowed. Values: 0=Blocked, 1=Allowed

Possible Response Codes

200HTTP code

Sample Response: HTTP 200

Firewall payload item successfully modified

Copied!
  {
    "enable_stealth_mode": "1",
    "payload_id": 6967000001030034,
    "allow_signed_app": "1",
    "block_all_incoming": "2",
    "allow_signed": "1",
    "enable_firewall": "1",
    "restricted_apps": [
      {
        "app_name": "Calculator",
        "allow_incoming_connection": "0",
        "bundle_id": "com.apple.calculator",
        "app_group_id": 6967000000047041
      }
    ]
  }
                
Show full

Duration: 1 minute | Threshold: 60 | Lock period: 5 minutes

Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.