Setup guide

UNCLASSIFIED
UNCLASSIFIED
41
Chapter 4-
Configuring System Settings
left enabled, you will need to allow them
through the firewall here.
3. Click the Start button to turn on the firewall. The button’s label should
change to Stop, and the text above the button should state Firewall On.
The rationale for whether the ports should be opened for incoming access is the
same as given above for Services. There are two ports that may be included in this
list that do not appear as services in the Services panel. These ports are “iChat:
(5297, 5298)” and “iTunes Music Sharing (3689).” These ports should not be
necessary in a normal operational environment.
For a complete list of ports used by Apple Software and Services, see: Well Known
TCP and UDP Ports Used by Apple Software Products”
(
http://docs.info.apple.com/article.html?artnum=106439
) or the Mac OS X Server
manuals (
http://www.apple.com/server/documentation/
).
The firewall should always be enabled, and incoming ports should be enabled only if
absolutely necessary based on operational requirements. The entire firewall should
never be disabled to allow for use of only specific ports.
The Internet section of the Sharing panel is used to allow multiple machines to
share a single Internet connection. Use of this option is out of scope for this
guidance. Internet sharing is disabled by default, and it should not be enabled. To
ensure it is disabled:
1. Click on the Internet button on the Sharing panel (Figure 15).