Hello,
Struggling quite a bit with the Firewall features in JAMF and I'm wondering how others are working with or around it. The configuration options are very basic either Block Everything or Control incoming connections for specific apps which looks like you'd then need to populate the list with any application that could possibly receive incoming connection which seems like an impossible task. Also the fact that if you have a policy applied to the machine with the Firewall payload its locked to whether that policy says the Firewall is enabled or not.
In our environment, we do not allow incoming connections nor server services to be running on user workstations. Being able to easily block this with a policy is nice, but then we have cases where someone wants to use AirPlay which needs incoming connections to work.
Allowing 1 application through the firewall does not appear to be an option so the alternative is to not apply the Security and Privacy policy to their machine. Definitely not a good solution considering the other settings this configures.
Given that the configuration options are extremely poor, how do you manage the firewall to have some control over what is allowed through without pushing that responsibility to the user?
