Configuring Mac OS X Firewall for iChat

I understand that one must configure the firewall in Mac OS X Tiger before using iChat. It is a mystery to me that Apple does not provide a pre-configured Firewall rule for iChat AV that the user can easily just turn on or off. (Apple does have a pre-configured rule for iChat Bonjour).
There is a How-To article on Apple's web site (see http://docs.info.apple.com/article.html?artnum=93208 ) but this article appears to be out of date. The article tells you to open up certain ports but it does not tell you whether the ports are TCP or UDP.
From what I am been able to figure out, one needs to open up the following ports in the Mac OS X Firewall for iChat to work:
TCP Ports -- 5190, 5297, 5298
UDP Ports -- 5060, 5190, 5676, 16384-16403
Is this correct? Do I need to open up these ports in the Mac OS X Tiger Firewall before I can get iChat AV to work?
(I prefer not to open uo any unnecessary ports).
RobK

By default the Mac OS X firewall doesn't block UDP traffic. So unless you have clicked on the "Advanced" button in your firewall settings and told the firewall to block UDP you don't need to bother with the UDP ports (and indeed, including them in your firewall rule they wont even be used).
There is absolutely no need whatsoever to open up TCP ports 5222 or 5223.
While ports 5222 and 5223 are used by XMPP/Jabber SERVERS iChat doesn't receive inbound connections on those ports. iChat will make an outbound connection on a random high port (mine's currently using port 54804 to connect to Google Talk on port 5223) and there's no need for a firewall rule for these (and it's impossible to predict what port iChat will use anyway).
Port 5190 (TCP) is used for AIM server connection. Just like above iChat will use a random high port to connect to the AIM server on this port so this does not need to be opened.
Port 5190 (UDP) is used for AIM file transfers i believe. It may be that iChat also uses it for XMPP/Jabber and Bonjour file transfers too (though i suspect not since the Bonjour firewall rule doesn't open up this port). If you haven't blocked UDP traffic you wont need to open this port.
Port 5220. As far as i know this port has nothing to do with XMPP/Jabber. The only thing i can think of is that perhaps iChat uses it as a custom file transfer port (though since Bonjour is just serverless XMPP/Jabber and this port isn't opened the Bonjour rule i suspect not). There is probably no need to open this port.
Port 5298. I believe this is used for message exchange via Bonjour. If you're not planning on using Bonjour you shouldn't need to open it.
Anyway, after this long rambling post the conclusion is:
So long as you haven't blocked UDP traffic in the Advanced section of your Mac OS X firewall you shouldn't need to open up any ports for iChat to work (on your Mac anyway. Gateway/router is another story).
If you have blocked UDP you will need to open the following:
UDP: 5060, 5190, 5297, 5298, 5353, 5678, 16384-16403
No TCP ports should need to be opened.
Forwarding the above UDP ports to your machine on your gateway or router should enable things to work perfectly.

Similar Messages

  • How to configure Mac Mini (Late 2014) for Seiki 39in at 4K (3840x2160)?

    Other users have successfully configured Seiki 50in 4K monitors, but (Yosemite 10.10.1) Preferences does not display any 4K resolutions, even when Option-Clicking the Scale Display choice.  Mac Mini and monitor can be returned in next few days if solution can't be found.  Any tips?

    Mac Mini and monitor can be returned in next few days if solution can't be found.
    According to every report I've seen, there is no way to drive a 4K monitor from a mini at more than 30 Hz refresh, which is usually considered inadequate for use as a desktop. Even if you can get the display to work, you likely won't be satisfied with it.

  • .mac account setup problem for iChat

    I was setting up my sisters new iMac today and tried to setup iChat. So I went through the setup and told it to create a .mac account. It did but then would not accept the password. Tried it many times. So finally reset the password and same thing, it keeps saying the password is not valid. Finally set a completely different and much simpler password for the account but still says it's not a valid password.
    I am wondering if this has something to do with the switch over from .mac to mobile me??
    Any ideas?

    Try setting up a free AIM account instead; it can be used with iChat for any purpose that the .Mac account can be used for except for encrypted chats.
    (33552)

  • I know my Apple Id (not .mac) and password but I can't logon to ichat.  I keep getting a message of password not matched.  Do I need to create a new account for Ichat?

    I know my Apple Id (it isn't ".mac") and password but I can't log on to ichat.  I keep getting a message of password not matched.  I saw somewhere that my Apple id is the same as my ichat account.  Do I need to create a new account for Ichat?  I've already reset my Apple id password 3 times in the last 2 days.  What am I doing wrong?

    Hi,
    At one time only Email IDs from Apple (when it was just @Mac.com) were referred to as "Apple IDs"
    Other IDs such as to log in to Discussions were know as Discussion IDs
    Things like the Online Store and iTunes and Apple realising that people would prefer one ID to have access to Everything tended to move things together.
    There can be a variety of combos now
    iChat Name
    @mac.com before MobileMe
    @mac.com post MobileMe
    AIM Names
    AIM names current
    MobileMe (@Me.com)
    Style
    Email Address valid with the .Mac service prior MobileMe Note 1
    Email style Name Valid with AIM
    May or may not be an Email address
    Can be AIM issued or third party Email address
    Valid Email with MobileMe Service
    Other Abilities
    May also be Currently valid email linked to a MobileMe account
    Maybe Valid Apple ID
    Is a Valid AIM Screen Name
    May Not be a Valid Apple ID (was an option choice at one stage)
    Is a Valid AIM Screen Name
    May not look like an Email (No @whatever.com) but may be linked to either an AOL email account or AIM one
    Current Registration seems to be pushing Email registration (@AIM.com)or asking to use another you currently use.
    Trial Accounts are limited to the Trial Period Only as Emails, Valid AIM Screen Names and Apple IDs.
    Apple ID
    Possibly (likely)
    Possibly (depends when Registered)
    More currently Yes.
    No
    No
    Yes
    Glad I could help.
    8:39 PM      Thursday; September 15, 2011
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro 2Gb( 10.6.8)
     Mac OS X (10.6.8),
    "Limit the Logs to the Bits above Binary Images."  No, Seriously

  • Is there a download for iChat AV 2.0 available for Mac OS X?

    I think I have just the Mac OS X and there is a iChat program, but other people cannot see my buddy icon. The help section told me to get the iChat AV 2.0 stand alone, but I can't seem to find it.

    Hello ooomeehwow
    Welcome to Apple Discussions
    Are you really using Mac OS X 10.4.2? If so, you should be using iChat AV 3.0.1.
    iChat AV 2.x is older than Tiger. iChat AV 2.0 will NOT run on any Mac that is using 10.4.x as its operating system.
    You can check your version by selecting the
    b iChat > About iChat
    menu choice. If it shows iChat AV 3.0.1, you have the latest version, and the iChat AV 2.0 help does NOT apply to your system.
    If the Mac OS X (10.4.2) info you posted is correct, try the suggestions in Help for iChat AV 3 Problems. That should help you get going.
    If you are new to iChat AV and or iSight, you may find some useful tips in Using iSight with iChat AV.
    If your "other people" use PCs, check out Mac Video Chat with PCs.
    For more instructions, complete with pictures, of setting up iChat from the very beginning, see Ralph Johns' iChat Pages or Ryan's Basic Setup for iChatAV
    EZ Jim

  • HT204053 How do I get a Mobile Me address for iChat and e-mail using Mac OS 10.4 ?

    How do I get a Mobile Me e-mail address for iChat and messagingl on Mac OS 10.4

    MobileMe has been replaced by iCloud: unfortunately you can't access any of iCloud's facility on Tiger (except to access email, but you would have to have set the iCloud account up on another, compliant, device first - you can't open an iCloud account on Tiger).

  • .mac account for iChat

    do i have to buy a .mac membership for iChat or is there a way to get a .mac account restrected to using iChat for free?

    Hi Thomas,
    Please mark the thread as finished please.
    New Discussions ReponsesThe new system for discussions asks that after you mark your question as Solved. You should take the time to mark any posts that have aided you with the tag and the post that provided your answer with the tag. This not only gives points to the posters, but points anyone searching for answers to similar problems to the proper posts.
    Alternatively, you can change the status to Answered.
    If we use the forums properly they will work well...
    11:24 AM Monday; January 22, 2007

  • Configure SA520 firewall for 2 ISP (cable & ADSL)

    hi
    Is it possible and howto configure Cisco SA520 firewall for 2 ISP (cable & ADSL) to get load balancing between these ISP?
    THX

    Hello,
    Load-balancing is not suported as the ASA does not supports PBR. You can  try to do some work-arounds to send some traffic from one link but this is not cisco supported. I have seen scenarios about this working so if you really need it you can give it a try.
    Regards,
    Julio
    Do rate all the helpful posts

  • HT200259 Configuring adaptive firewall for VNC and RDP connections

    Hello, I'm using Yosemite with OSX Server.  Is there a way of configuring adaptive firewall for VNC and RDP connections?

    Apple has never documented what the adaptive firewall really does, as far as I know. It seems that the built-in network services send it some kind of notification whenever there is a connection attempt. The Screen Sharing service is one of those, so it should be protected. There is no built-in RDP service, so if you somehow added one, it would not be protected.

  • Verizon DSL Firewall settings & iChat

    I currently use Verizon DSL utilizing a wireless Westell Versalink (Model #327W) modem. My current firewall setting is:
    *Typical Security (Medium)*
    *The medium security setting only allows basic Internet functionality by default, just like High level security. Medium security, however, allows customization through Port Forwarding configuration so certain traffic can pass.*
    Utilizing this setting I can not use iChat, however if I lower the firewall setting to:
    *Minimum Security (Low)*
    *The low security setting will allow all traffic except for known attacks. With low, your modem is visible by other computers on the Internet.*
    I can then use iChat.
    Is there a work around to this? I do not want to have minimum security for my firewall and I want to use iChat more often.
    Any suggestions, ideas, etc would be much appreciated.
    Oh! my Mac Firewall is currently active

    Hi Ian,
    The answer is yes.
    Much like the way getting email is a risk from getting stuff you don't want, to being offended by something, or even getting a virus/tojan.
    Blocking all Incoming connection means you would not be able to iChat to anyone.
    Particularly if they tried to call you.
    It is more like email and understanding what is a risk and what the risk is.
    Ping based attacks may bring down your Internet connection needing the modem to be reset.
    Discovering your Public IP is not really that difficult even if Ping Blocking is ON
    There are websites that will tell you. yours http://www.whatsmyip.org/
    http://www.google.com/search?q=myIP&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:en-US :official&client=firefox-a
    Whether someone would move up to a Ping of Death attack depends some what on how malicious they are and whether you present a "Big Enough" target to someone.
    As a Screen Name can be logged in on a web site, from a phone or several computers it pays to check that the Buddy who responded is in the "right" place.
    If you want to worry more
    http://www.pixelitt.com.au/internet-security/internet-security-p2.htm
    From Google Search
    It may pay to read some more on this.
    Essentially Not having Ping Blocking allows the routing device to respond to Pings.
    This reveals your Public Address as being valid.
    It does not tell them the IPs the router uses for the LAN side or the LAN IPs that your computer have.
    Like Emails to a certain extent you have to set up things yourself to allow further penetration.
    Which ports are open and in some cases for how long can be part of the solution.
    You have to remember that the first 1024 ports are open anyway.
    Web Browsing and email apps use ports below this threshold which is why most routing device work Out of the Box for web browsing and mail.
    Web Browsing uses port 80 with some secure login sites using port 443
    Some mail apps also use port 443 along with many others depending on the server type and whether it is Outgoing or Incoming mail.
    As these ports are open any real intrusion attempt is going to be on those ports.
    Responding to a ping is more like a random phone number dialled by a 2 year old and you find someone is Australia is talking to them (validating that random number)
    Video and Audio chats (Including the audio chat alongside Screen Sharing in iChat) will not work without Pings being responded to.
    iChat will not work unless the ports it needs above the 1024 threshold are open.
    If your connection is not that fast you may get away with not disabling any DoS or SPI as you may not reach the threshold in download speed.
    I hope this helps a little
    10:25 PM Saturday; September 5, 2009
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"

  • Can I open a port range in the firewall for one host?

    Can I open a port range in the firewall for one host?  In other words, I want to be able to open ports 54001 to 54050 to allow one remote host in my LAN to access that port range in my Mac Server.  Is this possible?  Currently, the only option I see is to open individual ports for all external hosts (eg http or https)
    Thanks in advance!

    Which version of OS X Server are you using?
    Server 2.2 and earlier includes an interface to a software firewall that can be configured to open specific ports very easily. Descriptions of how to configure the firewall can be found in the documentation for these versions.
    Server 3.x no longer has an interface to the software firewall - it is still there, but you need to use other methods do configure it.  A popular example of such a method is the icefloor utility.
    Apple suggest that for Server 3 you delegate firewall duties to an external router.  Server 3 includes the ability to configure the firewall component of Apple Airport routers 'automatically'
    if you connect a machine running Server 3 directly to an Airport Router the router appears in the LH pane in the Server.app window (usually second line, below the entry for the server itself), and you can control what services are 'enabled' through the firewall there.
    a more common solution perhaps is to use a non-apple router, and configure the firewall (and so open specific ports) through whatever control interface is provided for that router.  There are many many kinds of hardware router you could use, and the control interfaces used vary widely - so you will have to consulting the documentation for your own router to work out how to do this.
    If you post information about your software versions, and hardware configuration, it is possible that you can get more specific help with the tasks involved in opening the ports.
    Hope this helps.

  • Why can't I access preferences or account settings for iChat

    Let me start by saying I'm a newbie. I would like to use iChat. I set up a .mac account, a Google/Gmail account and an AIM account.
    However, I cannot seem to log-in or use iChat using any of the accounts. I get to the Account Set Up page, enter the log-in info, get to the "Encrypted Chat" window, but cannot see any "Done" button that iChat says I have to select to start using iChat. Nor can I access any of the iChat account settings or preferences.
    It doesn't matter if I'm on my wireless network (linksys WRt54G) or connected via ethernet. My firewall settings in System Preferences is open.
    What am I doing wrong?
    thanks in advance.

    Hi,
    Welcome to the    Discussions
    I am a bit confused as to what stage you are up to.
    I think it is the difference in the words you had used (and where you have used them) compared to how I tend to think about iChat
    I would like to use iChat. I set up a .mac account, a Google/Gmail account and an AIM account.
    I take this means that you have Registered Screen Names at the required places.
    I get to the Account Set Up page, enter the log-in info, get to the "Encrypted Chat" window, but cannot see any "Done" button that iChat says I have to select to start using iChat.
    I am therefore assuming this mean you are stuck in the Start Up Screens ?
    Start Up Screens
    You get a Welcome Screen First
    A place to Add ("set up" in my speak) an AIM or Apple Screen name. It has a place to Add your First Name Last name details - which may be pre-filled from the Address Book.
    This pic is from iChat 4 but should be the same in iChat 5
    You need to use the middle Drop down to select which type of account you are using/setting Up.
    The option to Enable Bonjour Chats is the next screen followed by the option to Set Up Jabber (Or Google) IDs
    In iChat 5 there are optional items under the Text Fields to set up Server Names if different to the ending of your Jabber ID and the Server Port to use.
    This is followed by a Video Snapshot option/Preview of Video Screen.
    The Last is the Done Screen which tends to list the Names you are setting up.
    If I have summarised correctly this is where you have got to then Open the Folder with the Little House iCon (Hard Drive/Users/(your account)
    In here then open the Library one and the Preferences one in there.
    Use either List View or CoverFlow (Also a List) an find anything that starts com.apple.ichat..... and ends .plist and drag it to the Trash.
    Try setting up just one Name (You can add more in iChat Later).
    If that does not work can you click though all the screen without adding any details at all ?
    Longer version of this here http://www.ralphjohns.co.uk/versions/ichatvers4/howtoStartiChat.html
    As I provided a link to my Site I am required to place this:-
    I may receive some form of compensation, financial or otherwise, from my recommendation or link.
    9:59 PM Tuesday; November 9, 2010
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"

  • Setting up firewall for 10.10 Server

    I know in the past I was using firewall under WGM which gives me access to setup firewall for different VLANs
    now its not available unless I enable Stealth mode and firewall on/off..
    Is there away to setup firewall the old way ?

    Hi
    AFAIK the "Magic Triangle" applies to an environment that also includes OSX Server providing mac-style GPOs - mostly. There's another option called "Cylinder of Destiny" that takes this slightly further although it's still essentially the same. Ultimately what you decide rests on what you want to achieve.
    If all you want is SSO for Users working on mac workstations and nothing else, use what Apple provides in the Client OS. You don't necessarily need OSX Server.
    It's even possible to alter the AD Schema itself and add Apple specific object classes, attributes and values to provide a means for managing users on mac workstations that way. Again you don't necessarily need OSX Server. In addition there are 3rd-Party solutions that don't involve OSX Server you could consider depending on budget and how hard you want to work? Likewise, Centrify and AdmitMAC are three I can think of.
    There's plenty of documentation all over the internet on how to achieve Integration. Its been going on for a few years now. Ultimately how 'successful' it all is will rest primarily on how well your AD is configured. Apple's built-in Active Directory Plug-in in many ways assumes an 'out-of-the-box' AD and ideally an environment that follows Microsoft's Best Practices for AD. I've yet to see one AD that fits that criteria. In some rare cases Integration may not even be possible. You won't really know until you try.
    Tony

  • Connecting a macbook to a tv for ichat?

    Hi,
    I am wondering if there is a way to use a macbook connected to a tv with a dvi or similar cable to ichat.  My Mom is throwing a 70th birthday party for my dad and we usually chat macbook to imac, but I know there is a way to connect to a tv so I can 'attend' the party.  I can't seem to find what I am looking for, but it seems like it would be simple.  The problem is that my Mom isn't too savvy in this area, and it is hard to walk her through this.  I would think once she connects to the tv, a simple switch in Displays prefs would do it.  Any suggestions?
    Thanks,
    Greg

    Hi,
    My MacBook Pro has a DVI Output and came with an Apple DVI to VGA cable.
    It is very short at about 6 inches.
    My TV has VGA Input.
    For me this would need a longer cable to be able to place the Computer in a position to still use the camera (it would be useless for them to see you but you not see them because the camera was facing the wrong way) then in System Preferences > Displays Mirroring can be turned On.
    I would then go Full Screen in iChat so that the iChat Video chat was the whole display on the TV.
    I would also get iGlasses (A System Add-on) that can be used by iChat to do various Adjustments to the Macs Video pic  (Pan and Zoom is one thing that may be useful for a shot of a room when people are further back than normal).
    For Sound to the TV she would probably have to use a 3.5mm jack to whatever the TV has.
    (And chose System Preferences > Sound > Output  and then Line Out (it may read Headphones if something is Plugged in) - she may also have the option for the Digital feed).
    Obviously if her Mac or her TV have other connections then some inter cabling will be needed.
    10:27 PM      Saturday; July 9, 2011
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro 2Gb( 10.6.8)
     Mac OS X (10.6.7),
    "Limit the Logs to the Bits above Binary Images."  No, Seriously

  • Final Cut Timeline Feed as video source for iChat?

    I was at the Apple NAB presentation in Vegas a few weeks ago, and one of the things they showcased in regard to iChat AV was the ability for an editor to videoconference with several other people at once and one of the video feeds in the chat window was actually the output from the editor's Final Cut Pro timeline. As he made changes in the FCP timeline, he could play it out in real time and all the people in the chat could see the video feed and make comments on the edit.
    OK- so we were excited because that's a workflow issue we have here. So, we bought some iSight cameras and Tiger and started to do some testing here. The only problem is that it doesn't seem very easy to set up. At first I just thought, "well, they are just playing the timeline out of the firewire port on the FCP machine and another computer is ingesting that firewire stream as a video source for iChat." except when you connect 2 Macs together with a firewire cable, the FCP system doesn't detect a DV video device to output to and the iChat system doesn't detect the incoming firewire stream as a "camera". I spoke to tech support and they said it's not something they support so no luck there.
    I did find an article on Creative Cow about someone doing something similar, but it involved exporting the FCP timeline out through a Kona analog video card into an external tape deck that does analog to DV conversion which then can be imported back into iChat as a DV stream, but last time I checked, a Kona card would run me around 1500 bucks.
    Anyone have any other ideas?

    HI Jeremy,
    Welcome to the Aple Discussion Pages.
    Based on the Auto Responding iChat Accounts that play films I would guess they were either using an AppleScript to import FCP as the Video sourdce or usiing an Add-On like iChatUSBCam that also alows you to change the video source to the desktop.
    iChatUSBcam has a new beta for Tiger http://www.ecamm.com/mac/ichatusbcam/
    Ralph

Maybe you are looking for

  • 2851 router vpn to 851 router lan clients cannot ping

    Greets - I'm expanding my lab experience by adding a 2851 router to my mix of 18xx and 851/871 units. Some of this infrastructure is in production, some just lab work. I have established good connectivity between 18xx's and 851/871's with IPSEC VPNs

  • OS X keeps crashing/kernel panics

    In the last week I have noticed a sudden increase (from like 'never' to daily/every other day) in kernel panics/OS X crashes. The only things I have done in that time frame has been updating iTunes and Safari. I'm usually using one or the other when

  • Access @Variable('DBUSER') in a JSP Page

    Is there a way to access the @Variable('DBUSER') within a JSP page.  We are using this variable as the client ID in our WEBi reports and Analytics.  We would also like a way to tell what client is logged in when using a Web Page analytic on a dashboa

  • Smart Albums Not So Smart

    I'm trying to set up Smart albums to show my kids and their friends. However, when I organized the photos, sometimes I used Face recognition and other times I just used keywords via hotkey. This was because sometimes it wasn't worth the trouble to ad

  • Please help.  Optical drive won't take disc, imac won't boot up!

    I installed Tiger 10.4.6 and it was working just fine, had done several restarts. Then I put in an office for mac cd and it wouldn't boot up. I tried ejecting it wouldn't work. I finally got the disc out, but the computer wouldn't start. I booted up