macOS Server 5.4 running on High Sierra (macOS 10.13) has an adaptive firewall built in, or a firewall that controls incoming access based on clients attempting to abuse the server. The firewall automatically blocks incoming connections that it considers to be dangerous. For example, if a client attempts too many incorrect logins then a firewall rule restricts that user from attempting to communicate with the server for 15 minutes. If you’re troubleshooting and you accidentally tripped up one of these rules then it can be a bit frustrating. Which is why Apple gives us afctl, a tool that interacts with the adaptive firewall.
To enable the adaptive firewall, use the -f option:
Alternatively, use the -X option to disable the Adaptive Firewall:
Once run, you’ll receive an error similar to the following:
Sep 8 14:16:18 afctl <Notice>: Unloading the launchd job
Sep 8 14:16:18 afctl <Notice>: Setting the start behavior to disabled
Sep 8 14:16:18 afctl <Notice>: Clearing out the blacklist
No ALTQ support in kernel
ALTQ related functions disabled
1/1 addresses deleted.
Once started, the most basic task you can do with the firewall is to disable all of the existing rules. To do so, simply run afctl (all afctl options require sudo) with a -d option:
You’ll receive no response on successful runs. When run, the adaptive firewall’s rules are disabled. To re-enable them, use the -e option:
Turning off the rules seems a bit much for most troubleshooting tasks. To remove a specific IP address that has been blacklisted, use the -r option followed by the IP address (rules are enforced by IP):
/Applications/Server.app/Contents/ServerRoot/usr/libexec/afctl -r 192.168.210.88
To add an IP to the blacklist, use the -a option, also followed by the IP:
/Applications/Server.app/Contents/ServerRoot/usr/libexec/afctl -a 192.168.210.88
Once run, you’ll get a message as follows:
No ALTQ support in kernel
ALTQ related functions disabled
1/1 addresses added.
To permanently add a machine to the whitelist, use -w with the IP:
/Applications/Server.app/Contents/ServerRoot/usr/libexec/afctl -w 192.168.210.88
And to remove a machine, use -x. To understand what is going on under the hood, consider this. The blacklisted computers are stored in plain text in /var/db/af/blacklist and the whitelisted computers are stored in the same path in a file called whitelist. The afctl binary itself is stored in /usr/libexec/afctl and can also be enabled with the /System/LIbrary/LaunchDaemons/com.apple.afctl.plist, meaning to force-stop the service outright, use launchctl:
The configuration file for afctl is at /etc/af.plist. Here you can change the path to the blacklist and whitelist files, change the interval with which it is run, etc. Overall, the adaptive firewall is a nice little tool for macOS Server security, but also something a number of open source tools can do as well. But for something built-in and easy, worth using.
There’s a nice little command called hb_summary located in /Applications/Server.app/Contents/ServerRoot/System/Library/CoreServices/AdaptiveFirewall.bundle/Contents/MacOS that provides statistics for blocked hosts. To see statistics about how much the Adaptive Firewall is being used, just run the command with no options:
The output provides the following information (helpful if plugging this information into a tool like Splunk):
- Date statistics start
- Number of hosts blocked
- Addresses blocked
- Number of times each address was blocked
- Last time a host was blocked
- Total number of times a block was issued
Finally, there are scripts located in /Applications/Server.app/Contents/ServerRoot/usr/libexec that can be used to manage the firewall as well. These include ServerFirewallPromotion.sh (a simple bash script) and ServerFirewallServiceCleanser, a compiled binary.
krypted September 26th, 2017
Posted In: Mac OS X Server, Mac Security
adaptive firewall, afctl, apple server, com.apple.afctl, CoreServices, macos server, securing servers, server
In Leopard, the Kerberos application got mad because the other utilities were making fun of him. So he went and hid in /System/Library/CoreServices and became an application that was summoned by other applications (ie – Keychain Utility) when they couldn’t do their own work and needed him. Directory Utility saw this and decided it looked like a pretty darn appealing way to go. So Directory Utility has now moved into /System/Library/CoreServices. Not that you will always need to use her. You see, if you open the Accounts System Preference pane and click on Login Options you’ll see Network Account Server. Here you can click on Join. With more space in the /Applications/Utilities playground it’s now possible for others to join in the fun. Especially since there are a few developers (such as DeployStudio) who now like to go there to hang out (even if they are uninvited, being from the wrong side of the development tracks and all).
krypted August 29th, 2009
Posted In: Active Directory, Mac OS X, Mac OS X Server, Mass Deployment
/Applications/Utilities, CoreServices, Directory Utility, Mac OS X 10.6, SL, Snow Leopard
When a computer has ARD open, by default you cannot log into it using Remote Desktop from another host. To fix this, use the following command:
defaults write /Library/Preferences/com.apple.RemoteDesktop AdminConsoleAllowsRemoteControl -bool false
And then run the kickstart -restart -agent command from /System/Library/CoreServices/ARD Agent.app/Contents/Resources
/System/Library/CoreServices/ARD Agent.app/Contents/Resources/kickstart’ -restart -agent
krypted October 2nd, 2006
Posted In: Mac OS X, Mac OS X Server, Mac Security, Mass Deployment
ARD, ARD Agent.app, CoreServices, kickstart