How to add specific ports to OS X Lion firewall

I need to add specific ports/port ranges to the OS X Lion clients' firewalls, any ideas?
OS X Lion firewall settings only allow adding applications.  There is no "LDAP" application, it's built into the Network preferences settings.  The LDAP server is an OS X Lion Server running Open Directory.

iosw wrote:
I guess the flexibility in the regular Lion clients with ports is not possible.  It's only possible with OS X Lion Server, fair enough.
No, you can configure both the client and server as much as you want. The only issue is that most people just don't understand what a firewall does (they think it is the same as anti-virus) so neither Apple nor I will bother explaining all the nitty-gritty details right off the bat.
The client version of Lion doesn't need to be providing any services at all. Hence, there is really no need to run the firewall. If you are doing something fancy that the application firewall doesn't quite support, then you might want to run the real ipfw firewall instead. It is also installed on the client, but isn't a tool for the great unwashed.
Personally, I find the fancy stuff pretty interesting, but I don't think you are doing that.
We're trying to configure SSL within the Lion clients and didn't know if there was an incoming requirement.  There's a bug (logged even by Apple) when Lion client's attempt to bind to an SSL enabled Open Directory server.  So the firewall preferences wasn't the reason for this failure.  We're resorting to non-SSL binding until Apple fixes the problem, although we running on a private network and can get away with non-SSL for the time being.
You might want to ask about this in the Server forums. This could be a situation where Apple isn't going to bother explaining the details on how to fix it because it would just confuse most people and they may already have it fixed in-house. It has already been discussed and some people say they have fixes. See the details in this thread.

Similar Messages

  • How to add a port for a IP cam in the airport extreme setting? thx!

    I has buy a IP cam, but I don't know how to add a port for a IP cam in the airport extreme setting? (I can see the IP cam in local, but not the internet.) Many Thanks!

    atwoodjordan, Welcome to the discussion area!
    See Steve Newstrum's user tip "How do I use Port Mapping (Part I)". When it talks about giving your Mac a static IP address just substitute camera instead.

  • How to add a static route permanently in Lion

    Hi, pls help to fix the problem.
    How to add a static route permanently in Lion.
    All methods for previous MAC OS are not working

    Hi,
    Not sure if you have fixed this, but I'd use launchd to create the route on startup.
    If you create a text file in /Library/LaunchDaemons/local.imac.route.plist
    with:
    <?xml version="1.0" encoding="UTF-8"?>
    <!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN"
    "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
    <plist version="1.0">
    <dict>
      <key>Label</key>
      <string>local.imac.route</string>
      <key>OnDemand</key>
      <false/>
      <key>ProgramArguments</key>
      <array>
      <string>route</string>
      <string>add</string>
      <string>224.0.0.0/4</string>
      <string>[GATEWAY]</string>
      </array>
      <key>KeepAlive</key>
      <false/>
      <key>RunAtLoad</key>
      <true/>
      <key>ServiceIPC</key>
      <false/>
      <key>UserName</key>
      <string>root</string>
    </dict>
    </plist>
    You need to replace [GATEWAY] with the IP address of the gateway to use like 10.11.12.13
    Then as root (login as an admin user and use "sudo su -" to become root) type:
    launchctl load /Library/LaunchDaemons/local.imac.route.plist
    You should be up and running.

  • How to add licensed ports to essbase olap server for as400

    Does anybody know how to add aditional licensed port to essbase olap server for as400 without having to reinstall the product, or reinstall the fixpack? thanks in advanced!

    On Unix / Linux you should be able to leverage the response from Raphael and change:
    Location=%BOBJDIR%/bobje/data/.bobj/registry/software/business objects/suite 11.5/sap/keycode/.registry
    For more information verify the below link
    [How do you update the SAP Integration Kit license?;
    Regrads
    Pardhu

  • How to open specific port using java program

    Hello,
    I want to open ,close port using java comm.plz help me how can i do it.is it possible
    by using java program.later i want to use that specific port to accept the server socket connection .plz
    help me.

    i try this java program.*but it get block in accept method*.tht mean i m not able to make connection with port.
    import java.sql.SQLException;
    import java.io.IOException;
    import java.net.ServerSocket;
    import java.util.logging.Level;
    import java.util.logging.Logger;
    class MakeConn
         public final static int PORT = 7788;
    public static java.net.Socket clientSocket = null;
    public static java.io.PrintWriter pw = null; // socket output stream
    public static java.io.BufferedReader br = null;
    public static ServerSocket server_socket;
         public static void main(String[] args) throws SQLException
         try {
              server_socket = new ServerSocket(PORT);
    clientSocket = server_socket.accept();
    System.out.println("CLIENT>>>" + clientSocket);
         br = new java.io.BufferedReader(new java.io.InputStreamReader(clientSocket.getInputStream()));
    pw = new java.io.PrintWriter(clientSocket.getOutputStream(), true);
    String message = br.readLine().trim();
    System.out.println("message is"+message);
    pw.close(); // close everything
    br.close();
    clientSocket.close();
         catch (Exception ex) {
    ex.printStackTrace();
    }

  • How to add specific help to home made vi or labview standalone applicatio​n ??

    Hi, i want to add help for my application, build using labview. so that the application becomes user friendly.
    in my application there is one main VI and other 8-10 sub/sub-sub VI's. i want to place handling instructions and other help in the main VI's help menu.
    Can anyone help me out for this issue?? how to add that help. currently that "search this vi's help" option is shown disabled in the application.
    Solved!
    Go to Solution.

    Besides adding description and tip to each control and indicator, filling in the description in VI properties>Documentation, the LabVIEW Help (of all places) has information on using Microsoft tools to compile a help file. Just search for the topic 'Help'. As we have just seen, the hard part is getting the user to actually use the help.

  • How to add OKI dotmatrix printer in Mountain Lion

    How to add OKI 790 Printer using MAC X 10.0.8 ?
    OKI does not develop any MAC driver. Any suggestion ?

    Did you try this - http://www.okidata.com/mkt/html/nf/MacSupport.html -?
    Clinton

  • How to add static port in Mac OS X?

    Dear All,
    I need to add a static route in my Mac OS X
    In windows I used to run: route add 10.0.50.0 mask 255.255.255.0 10.9.0.254 -p
    Please, how can I do the same in MAc OS X?
    Thanks in advance.
    Marcelo

    Mission Control – Work in Multiple Spaces  
    If you want to keep the desktops in a specific order, go to System Preferences/Mission Control and uncheck the box " Automatically rearrange spaces based on most recent use." You can also select the box below that so if you open an application, you'll be taken to that space.
    If you want to cut down the number of desktops, there is also an option to remove the Dashboard as a desktop and have it work like it did in Snow Leopard. That can be set in System Preferences/Mission Control by deselecting Show Dashboard as a  space. You can access the Dashboard by clicking on the Dashboard icon in the dock or using the FN 12 key.

  • How to add specific ringtone in messages os x

    i remember in mountain lion you could do this because I have a made iphone ringtone.. I forgot how to do it now and can't find how.
    Does anyone know how to put a specific ringtone, made yourself into the Messages app for OS X?

    Hi,
    Messages 8 in Mavericks is less able to do this than Messagers 7 and iChat versions.
    However one sound can be changed.
    That is the one for "Message Received"
    The setting is in Messages > Preference > General Section (There is no Alerts pane now)
    The default is the iChat sound for Messages Received.
    It can be changed to any System Sound (they appear in the drop down) and anything stored in your ~/Library/Sounds folder.
    To access this folder you have to use the Finder > Go Menu and Hold down the ALT key to see then select the Library.
    Navigate to Sounds after that.
    All the other iChat/Messages 7 sounds are in the app and linked to their default functions.
    So you have A/V invites, File transfers sent, File Transfers Received, Buddy Available and so on.
    You can't turn these Off in the app like you could before.
    And some don't seem to play even though present such as a Buddy going Off line.
    8:20 pm      Sunday; December 22, 2013
      iMac 2.5Ghz 5i 2011 (Mavericks 10.9)
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro 2Gb (Snow Leopard 10.6.8)
     Mac OS X (10.6.8),
     Couple of iPhones and an iPad

  • How do I open up a specific port in the Application Level Firewall?

    Currently, my system blocks port 2336 and I want to open this up. To be precise: port 2336 is listening on the local system, both on 127.0.0.1 and its 192.168.x.x address, but no client on the LAN can connect to port 2336.
    IPFW and PF are not running. When I turn ALF off in System Preferences, I can connect to port 2336 from a LAN client. So ALF is blocking port 2336. How can I open this up?

    Linc, thatnks for the reply. I dived into this a bit more and studied the setup of the ALF. I find it confusing, on the one hand it is mentioned in the packet filter firewall setup in /etc/pf.anchors/com.apple:
    # Application Firewall anchor point.
    anchor "250.ApplicationFirewall/*"
    OTOH, such an entry is nowhere to be found on my system and the ALF command socketfilterfw somehow seems to suggest it is a socket filter and not a packet filter and that it is indeed working at a different level, namely the level that decides which executable is allowed to listen on which socket (port).
    I am trying to find out what program is being started when I connect to port 2336 (service appleugcontrol according to /etc/services) so I can enable it with socketfilterfw. But I can't find out which program I have to enable.
    I can turn off my ALF altogether, but I am used to running a firewall on my system, even if it is behind a NAT and ports are not as easily reached from the outside. I want my internal network to have some security too. In the 10.6 days, that was ipfw. Now it is PF which is off by default. I tried IceFloor to manage the PF firewall (so I can turn the ALF off) but the result was negative. Whatever I put in the settings, it blocked about everything.
    The reason I want to open this port is that without it server-side file tracking for mobile home sync does not work and mobile home syncing by clients becomes very slow. Server-side file tracking for mobile home syncing requires that the FileSyncAgent on the client is able to create a SSH connection to port 2336 on the server. But as it stands now, ALF is blocking that.

  • How to add Ethernet ports to an Airport Extreme Base Station?

    I have successfully connected an HP Office Jet 6310 to the Airport Extreme Base Station, after downloading the latest software from HP. It is printing wirelessly, and it is great so far.
    The only problem is that the cable modem connected to ADSL has only one Ethernet port, and the Airport Extreme Base Station also has one Ethernet port. However, I need one more port to connect a phone (Vonage Telephone Adapter = VTA).
    What is the easiest way to achieve this? I saw several other messages discussing hubs and routers, but the answer is not clear yet. If I purchase an additional router, should it be connected between the cable modem and the Airport Extreme Base Station, or the other way round?
    Any help or advice would be appreciated!
    Thank you in advance for your time.
    MacBook Pro with 1.83 GHz Intel Core Duo   Mac OS X (10.4.7)  

    One final vital piece of information, which should be my conclusion on this topic.
    Following the advice received, I purchased a Switch from Linksys. Since the device didn't work for my purpose (dividing the Ethernet connexion into an Ethernet line for the HP printer and the Vonage phone), I called the Linksys support.
    I was told that what I needed was not a switch, but a router. I thus had to get reimbursed for the switch and hunt for the proper router.
    Finally, today, I have been able to find the item corresponding to my needs:
    A Belkin Wireless G Router F5D7230-4
    It costs less than 50 US$ and has all the necessary Ethernet ports. The setup is very simple, and I got it operational within a couple of minutes, despite some small problems getting the setup Wizard to work. It is Mac OS X compatible.
    Thus, at the end, I have got the HP 6310 Office printer and the Vonage VTA phone working together, with a robust Wireless network including WPA security. I would recommend this type of setting.
    The only trouble is that the AirMac Extreme Base Station has become completely useless! I will perhaps keep it as a souvenir, or as a decoration in the living room... This wouldn't have happened if the creators of this nice object, which is extremely expensive for what it provides, would have thought of including at least two Ethernet ports!
    The unexpected reply to my query could thus be ironically formulated by saying: "replace the Airport Extreme Base Station with a cheaper an more efficient device." Sorry for that!
    With my best regards to those who took the trouble to read this thread to the end.
    Yours, Hotaru

  • How to add specific header and footer to flat file using SSIS 2008

    The SSIS package need to create file  with headers, totals and adds a status to position one of the records.
    Header: "$$ADD ID=ENTK0557 BID='IA   HBZAC14HBZACHRYCORP' PASSWORD='CUSTOMER        ' %AU HBZAC14" is added.
    $$ADD = Static
    ID=ENTK0557 = Static
    BID='IA   HBZAC14HBZACHRYCORP' = "HBZAC14" is the company, "HBZACHRYCORP" is company name
    PASSWORD='CUSTOMER        '  = static
    HBZAC14 = company
    Control Totals:
    T010533343 000050 0002659604 000000 0000000000
    T = Totals
    010533343 = Account Number
    000050 = Total records
    0002659604 = Total checks
    000000 = TBD
    0000000000 = TBD
    Data for the file
    DECLARE
    @T AS
    TABLE
    [BR-ISSUE-VOID-IND] [char]
    (1)
    NULL,
    [BR-ACCT-NBR] [varchar]
    (9)
    NULL,
    [FILLER1] [char]
    (1)
    NULL,
    [BR-SERIAL-NBR] [varchar]
    (8000)
    NULL,
    [BR-CHECK-AMT] [varchar]
    (8000)
    NULL,
    [BR-CK-ISSUE-DATE] [varchar]
    (6)
    NULL
    INSERT
    INTO @T
    [BR-ISSUE-VOID-IND]
    [BR-ACCT-NBR]
    [FILLER1]
    [BR-SERIAL-NBR]
    [BR-CHECK-AMT]
    [BR-CK-ISSUE-DATE]
    SELECT
    'C'
    ,NULL,' ',30090072,2114.39,100502
    UNION
    ALL
    SELECT
    'C'
    ,NULL,' ',30090190,430.58,100502
    UNION
    ALL
    SELECT
    'C'
    ,NULL,' ',30092371,589.93,100502
    UNION
    ALL
    SELECT
    'C'
    ,NULL,' ',30092550,1198.6,100502
    SELECT
    FROM @T
    File SnapShot.

    Using SSIS its difficult unless you use a script task after the data flow to add the header footer bits.
    A much better option in this case would be bcp as you can generate query with values in the order you want and bcp it out
    http://msdn.microsoft.com/en-us/library/ms162802.aspx
    Please Mark This As Answer if it solved your issue
    Please Mark This As Helpful if it helps to solve your issue
    Visakh
    My MSDN Page
    My Personal Blog
    My Facebook Page

  • How to add a file to sidebar in Lion?

    Hi!
    In Snow Leopard it was possible to drag&drop any file or folder to the sidebar (under "PLACES").
    I recently upgraded to Lion - and it doesn't allow me to drag&drop any file to the sidebar under "FAVORITES" (or any other section) - they just won't "drop" there. When I drag folders to the sidebar - everything works fine. But not with files.
    I'm wondering if it's a feature of Lion or if something's wrong with my computer.
    Does anyone know the solution?
    Thank you!

    I noticed a weird thing.
    When I open a file from the sidebar - it sometimes disappears from the sidebar!
    Sometimes it stays (like it's supposed to).
    I experimented a little bit to find out when it disappears and when it stays.
    Here's what I found:
    If I open a file from the sidebar and do NOT save it before closing - it remains on the sidebar. I can open it as many times as I want - it stays, as long as I don't press "save" before quitting.
    (So, for example, there is no problem with non-editable pdf files).
    But if I open a file from the sidebar (e.g. xlsx or rtf file) and SAVE it before closing - then:
    - if it's the first time that the file is saved - everything is ok, it remains on the sidebar
    - if it's the second time that the file saved - then the file disappears from the sidebar!
    I'm sure it's a glitch, what's the point of having an item on the sidebar if it disappers from it all the time and you have to add it manually back again & again!
    Do you come across the same problem or is it just me?

  • How to add link in full screen email Lion?

    Hi all
    I've been using the full-screen versions of most apps since istalling Lion. Not perfect but I like being able to swipe between screens. However the email function in full screen doesn't allow you to add a link to your message. When you hit compose new message the toolbar functions don't drop down. Am I missing something here?
    thanks
    WG
    Ps - I also have had the Wifi problem which was resolved by setting up network again. Time Machine does seem to take longer to backup with Lion. Finally, also have problems with email where it can't send emails sometimes. None of these dealbreakers for me but hopefully new release version will deal with them!

    You should have a limited toolbar, but the add link button isn't part of it.
    You can add a link using the Edit menu (or cmd-k), or select text and right-click (Link>Add Link…)

  • How to add certificate in mac os x lion for all users

    Hi hello
    I want just add certificate in the session Admin, but i want when one user connect in her session can have this certificate
    thanks for reply

    It's already installed. To start it, run the following shell command:
    sudo launchctl load -w /System/Library/LaunchDaemons/org.postgresql.postgres_alt.plist
    There is a lot more that needs to be done to make it useful for anything, but that's beyond the scope of this forum.

Maybe you are looking for

  • My images do not show up on my published website.

    I am a beginner in Dreamweaver (having only made one other website 3 years ago in college). I have my images in my Assets folder, I place the image in dreamweaver, save it, test it, and it works fine. But when I "put" my website on the internet, my i

  • Please tell me the T.codes

    Hi please tell me the t.codes for the following. 1)Creditors payable Reports 2)Creditors Ageing Reports 3)Debtors Ageing Reports 4)TDS register 5)Vat Register i will give full points

  • Web service check error

    Hi, Is this a bug? A web service (C#) runs well, but the System Health Monitor is showing error 500 for it. It looks like a strange space appears in the link on position 27, when the monitor is checking the web service. Any clue? error example: Portl

  • I need to display separate bar for totals at the end of the barchart.

    Hi All, My scenario is similar to the one described below http://siebel.ittoolbox.com/groups/technical-functional/siebel-analytics-l/displaying-grand-total-column-as-a-seperate-vertical-bar-in-a-bar-chart-report-3351958 I didn't understand how the co

  • Mighty mouse: installing it in windows requires a "passkey"

    i just bought a mighty mouse and it works fine in os x 10.5.7. trying to install it in windows on the same mac, i am asked to enter the passkey for the mouse. you can get far by choosing the option "no passkey", but to complete the installation they