Figure 1. Default configuration of Mac OS X firewall with everything disabled
root# ipfw list 02000 allow ip from any to any via lo* 02010 deny ip from 127.0.0.0/8 to any in 02020 deny ip from any to 127.0.0.0/8 in 02030 deny ip from 224.0.0.0/3 to any in 02040 deny tcp from any to 224.0.0.0/3 in 02050 allow tcp from any to any out 02060 allow tcp from any to any established 02065 allow tcp from any to any frag 12190 deny log tcp from any to any 20000 deny log icmp from any to me in icmptypes 8 20310 allow udp from any to any dst-port 53 in 20320 allow udp from any to any dst-port 68 in 20321 allow udp from any 67 to me in 20322 allow udp from any 5353 to me in 20340 allow udp from any to any dst-port 137 in 20350 allow udp from any to any dst-port 427 in 20360 allow udp from any to any dst-port 631 in 20370 allow udp from any to any dst-port 5353 in 30510 allow udp from me to any out keep-state 30520 allow udp from any to any in frag 35000 deny log udp from any to any in 65535 allow ip from any to any