Which ports are open on my hosted Mac?
What we filter at the network edge, and why your ARD details look thin.
What we don't restrict
Any TCP port, any protocol, every standard UDP port that isn't on the well-known amplification blocklist. Run web servers, SSH, Xcode build farms, VPN endpoints, game servers, CI runners — we don't inspect your traffic and we don't rate-limit normal use.
What we do restrict
To keep our network out of reflection / amplification DDoS attacks, we filter a short list of UDP ports that are routinely abused. None of these affect a normal Mac workload.
The one a Mac admin can notice:
- UDP 5353 (mDNS / Bonjour) is blocked inbound. Apart from the DDoS angle, this stops your server from broadcasting its Bonjour name and advertised services to the open internet, which is also a privacy win.
Apple Remote Desktop and Screen Sharing
ARD and VNC on your public IP work normally. Because macOS uses Bonjour to enrich the connection (hostname, model, logged-in user), and we filter mDNS at the edge, ARD shows the host with limited metadata. The session itself is unaffected.
Tightening things up
If you don't want your Mac directly reachable, or you want to push the brute-force noise off SSH and VNC, you can:
- Run PF on the Mac itself. Built in, free, flexible — see our Firewall guide.
- Tunnel VNC through SSH and close 5900 — see VNC over SSH.
- Restrict SSH to known IPs with PF or with
AllowUsers/Match Addressinsshd_config.
If you want a managed firewall in front of your Mac (separate appliance in your rack), open a ticket — we can quote that on the Naaldwijk and Amsterdam locations.