If you enable stealth mode in the Application Firewall, pf will be enabled via the com.apple/250.ApplicationFirewall anchor with a very limited set of rules: scrub in all fragment reassembleīlock drop in inet proto icmp all icmp-type echoreqīlock drop in inet6 proto ipv6-icmp all icmp6-type echoreqĮxcept incoming IPv4/6 ICMP echo request, pf won't block anything. By default pf is disabled and doesn't block anything. You simply can't open a port in a firewall.