# Modify the configuration of a Firewall payload item within a profile To modify Mac Firewall policy payload item ## Endpoint `PUT /api/v1/mdm/profiles/{profile_id}/payloads/macfirewallpolicy/payloaditems/{payload_id}` ## Request Details ### Request URL `https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/macfirewallpolicy/payloaditems/{payload_id}` ### Scope `MDMDeviceMgmt.UPDATE` ### Header `Authorization: d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers - **Content-Type** `string` — **Mandatory** — `application/json` - **Accept** `string` — **Mandatory** — `application/json` ### Path Parameters - **profile_id** `string` — **Mandatory** Unique identifier of the profile. Obtain from the [Create Profile](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-create-profile.html) or [Get Profiles](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-get-profile.html) response. - **payload_id** `string` — **Mandatory** Unique identifier of the payload item. Obtain from the [Get Payload Item IDs](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mac-get-firewall-payload.html) response. ### Request Body `application/json` - `JSON Object` - **enable_firewall** `integer` — Optional Enable or disable the macOS application firewall. Allowed values: `0=Disable`, `1=Enable`. - **block_all_incoming** `integer` — Optional Block all incoming connections except those required for basic internet services (DHCP, Bonjour, IPSec). Allowed values: `0=Disable`, `1=Enable`, `2=User Controlled`. - **enable_stealth_mode** `integer` — Optional Enable stealth mode to prevent the Mac from responding to probing requests (ICMP ping). Allowed values: `0=Disable`, `1=Enable`, `2=User Controlled`. - **allow_signed_app** `integer` — Optional Automatically allow downloaded signed software to receive incoming connections. Requires macOS 12.3+. Allowed values: `0=Block`, `1=Allow`, `2=User Controlled`. - **allow_signed** `integer` — Optional Automatically allow built-in signed software to receive incoming connections. Requires macOS 12.3+. Allowed values: `0=Block`, `1=Allow`, `2=User Controlled`. - **enable_logging** `integer` — Optional Enable firewall logging. Allowed values: `0=Disable`, `1=Enable`. - **logging_option** `integer` — Optional Firewall logging detail level. Allowed values: `0=Throttled`, `1=Brief`, `2=Detail`. - **restricted_apps** `JSON Array` — Optional List of app-specific firewall rules controlling incoming connections for individual applications. ## Sample Request ```curl curl --request PUT \ --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/macfirewallpolicy/payloaditems/{payload_id} \ --header 'Accept: application/json' \ --header 'Authorization: d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/json' \ --data '{"enable_stealth_mode":1,"allow_signed_app":1,"block_all_incoming":2,"allow_signed":1,"enable_firewall":1,"restricted_apps":[{"allow_incoming_connection":0,"app_group_id":6967000000047041}]}' ``` ## Sample Request Body Modify Firewall payload — change stealth mode and update blocked apps ```json { "enable_stealth_mode": 1, "allow_signed_app": 1, "block_all_incoming": 2, "allow_signed": 1, "enable_firewall": 1, "restricted_apps": [ { "allow_incoming_connection": 0, "app_group_id": 6967000000047041 } ] } ``` ## Response Parameters ### HTTP Code 200 Response Body — `application/json` - `JSON Object` - **payload_id** `long` Unique identifier of the payload item. - **enable_firewall** `string` Whether the macOS application firewall is enabled. Values: `0=Disabled`, `1=Enabled`. - **block_all_incoming** `string` Whether all incoming connections are blocked. Values: `0=Disabled`, `1=Enabled`, `2=User Controlled`. - **enable_stealth_mode** `string` Whether stealth mode is enabled. Values: `0=Disabled`, `1=Enabled`, `2=User Controlled`. - **allow_signed_app** `string` Whether downloaded signed software is allowed incoming connections. Values: `0=Block`, `1=Allow`, `2=User Controlled`. - **allow_signed** `string` Whether built-in signed software is allowed incoming connections. Values: `0=Block`, `1=Allow`, `2=User Controlled`. - **enable_logging** `string` Whether firewall logging is enabled. Values: `0=Disabled`, `1=Enabled`. - **logging_option** `string` Firewall logging detail level. Values: `0=Throttled`, `1=Brief`, `2=Detail`. - **restricted_apps** `JSON Array` List of app-specific firewall rules with resolved app details. ### Possible Response Codes - **200** `HTTP code` ## Sample Response: HTTP 200 Firewall payload item successfully modified ```json { "enable_stealth_mode": "1", "payload_id": 6967000001030034, "allow_signed_app": "1", "block_all_incoming": "2", "allow_signed": "1", "enable_firewall": "1", "restricted_apps": [ { "app_name": "Calculator", "allow_incoming_connection": "0", "bundle_id": "com.apple.calculator", "app_group_id": 6967000000047041 } ] } ``` ## API Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 60 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.