Geo Firewall Module Documentation
Table of Contents
Section titled βTable of Contentsβ- Module Overview (Technical)
- Module Overview (Commercial & Business Value)
- π― User Roles & Key Capabilities
- Visual Interface & Form Structure
- Architectural Flow & Security Governance
- Common Scenarios & Operational Playbooks
- Troubleshooting & Diagnostic Commands
- Model Context Protocol (MCP) AI Integration
- Glossary
1. Module Overview (Technical)
Section titled β1. Module Overview (Technical)βThe Geo Firewall module (public.geo_firewall_rules, public.geo_ip_ranges) provides country-level geographical IP filtering for Ring2All Billing. In telecommunications and billing operations, malicious connection attempts, credential attacks, and toll fraud schemes frequently originate from specific geographic regions where the operating company maintains no legitimate business presence, carrier interconnects, or customer accounts.
By leveraging an integrated MaxMind GeoLite2 / DB-IP database and high-performance Linux kernel sets (nftables sets / ipset), the Geo Firewall evaluates the geographic origin of every inbound packet at wire speed. Countries can be marked as Allowed (emerald green) or Blocked (crimson red). Blocked countries are dropped at the kernel PREROUTING stage before consuming application server memory or Fastify event-loop cycles.
Data Model & Architecture Diagram
Section titled βData Model & Architecture Diagramβ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ β Geo Firewall Entity (public.geo_firewall_rules) β β β’ id: bigint (Primary Key) β β β’ country_code: CHAR(2) (ISO 3166-1 Alpha-2, e.g. 'RU', 'CN', 'US') β β β’ country_name: VARCHAR(100) β β β’ action: 'allow' | 'block' β β β’ notes: text β β β’ enabled: boolean β β β’ updated_at: timestamptz β βββββββββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββ β βββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββ βΌ βΌ βββββββββββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββββββββββ β MaxMind GeoIP Database β β Linux Kernel nftables Set β β β’ Binary lookup / CIDR blocks β β β’ nft add set inet filter geo_dropβ β β’ Updated weekly via cron β β β’ O(1) hash lookup per packet β βββββββββββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββββββββββPostgreSQL Schema Architecture
Section titled βPostgreSQL Schema Architectureβpublic.geo_firewall_rules:id: Numeric primary key (bigserial).country_code: Standard ISO 3166-1 Alpha-2 two-character country code.country_name: Full formal geographic name.action: Enforcement directive ('allow'or'block').enabled: Active state flag.updated_at: Timestamp recording when the regional policy was modified.
2. Module Overview (Commercial & Business Value)
Section titled β2. Module Overview (Commercial & Business Value)β- 95%+ Attack Surface Reduction: Blocking countries outside the carrierβs operating footprint immediately eliminates the vast majority of automated botnet scans, unauthorized SIP registrations, and SSH brute-force campaigns.
- Toll Fraud & IRSF Mitigation: Prevents rogue actors in offshore jurisdictions from scanning billing self-care portals or intercepting online rating mechanisms.
- Server Resource Preservation: Dropping unwanted geographical traffic in the kernel eliminates up to 90% of useless socket allocations, ensuring the Fastify API and OCS balance deduction engines run with minimal latency.
3. π― User Roles & Key Capabilities
Section titled β3. π― User Roles & Key Capabilitiesβ| User Role | Key Permissions | Core Responsibilities & Workflows |
|---|---|---|
| Super Administrator | Full Control (RW on Geo-Firewall) |
Configures national allow/block lists, toggles regional access policies, and saves changes to kernel netfilter tables. |
| Security Officer / SecOps | Geographic Threat Analysis | Analyzes attack origins on the AI Perimeter Guard dashboard, identifies malicious clusters, and updates Geo-Firewall rules accordingly. |
| Billing Operations Lead | Read-Only (Territorial Coverage) | Verifies that countries where new enterprise customers or carrier interconnects are located are properly marked as Allowed. |
4. Visual Interface & Form Structure
Section titled β4. Visual Interface & Form StructureβLevel 1 β Geo Firewall Interactive World Map
Section titled βLevel 1 β Geo Firewall Interactive World MapβThe interface presents an interactive vector world map (WorldMap.tsx / jsvectormap) rendering global geographical boundaries. Allowed countries are rendered in emerald green, while blocked regions illuminate in vivid crimson red.

Controls & Parameters Reference
Section titled βControls & Parameters Referenceβ- Interactive World Map: Click any nation to toggle its filtering status between Allowed and Blocked. Hovering displays the country name, two-letter code, and current state.
- Search Country Selector: Dropdown search box in the header toolbar allowing rapid lookup and centering of any nation.
- Map Zoom Controls: Bottom-left floating controls providing Zoom In (+), Zoom Out (-), and Reset View.
- Sticky Action Bar: Floating bottom toolbar featuring the Save button to persist modified country lists and recompile kernel sets.
5. Architectural Flow & Security Governance
Section titled β5. Architectural Flow & Security Governanceβ ββββββββββββββββ 1. Inbound Network Packet ββββββββββββββββββββββββββ β Foreign Host βββββββββββββββββββββββββββββββββββββββββββββββββΊβ Linux Kernel Netfilter β ββββββββββββββββ βββββββββββββ¬βββββββββββββ β 2. O(1) Set Lookup Against GeoIP Subnets (nftables) βΌ βββββββββββββββββββββββββββββββββββββββββββββ β Match in Blocked Regional CIDR Set? β βββββββ¬ββββββββββββββββββββββββββββββββ¬ββββββ β Yes β No βΌ βΌ βββββββββββββββββββββββ βββββββββββββββββββββββ β Silent Kernel DROP β β Fastify 5 API / Web β β (0 CPU overhead) β β Session Evaluation β βββββββββββββββββββββββ βββββββββββββββββββββββ- Ingress Arrival: A packet arrives from an external IP address.
- Kernel Set Inspection: The Linux
nftablesnetfilter chain references the compiledgeo_dropset. - Instant Mitigation: If the IP belongs to a blocked countryβs CIDR ranges, the packet is silently dropped at
PREROUTINGbefore any application code executes. - Allowed Path: Packets from permitted countries proceed to standard port filtering and authentication.
6. Common Scenarios & Operational Playbooks
Section titled β6. Common Scenarios & Operational PlaybooksβPlaybook 1: Blocking High-Risk Jurisdictions Following a Brute-Force Surge
Section titled βPlaybook 1: Blocking High-Risk Jurisdictions Following a Brute-Force Surgeβ- Review the AI Perimeter Guard telemetry to identify the top attack origins (e.g., Russian Federation, Eastern Asia).
- Navigate to ADMIN > Firewall > Geo Firewall.
- Use the search selector in the top toolbar to locate the offending country (e.g.,
Russian Federation). - Click on the country on the world map to toggle its state from Allowed (Green) to Blocked (Red).
- Repeat for any other target regions (e.g.,
China). - Click Save in the bottom-right action bar.
- The system regenerates the kernel IP set and applies the block immediately.
Playbook 2: Unblocking a Country for International Expansion
Section titled βPlaybook 2: Unblocking a Country for International Expansionβ- When onboarding a new customer or carrier interconnect in a previously blocked country (e.g., Germany or Brazil):
- Navigate to ADMIN > Firewall > Geo Firewall.
- Locate the country on the map or type its name in the search bar.
- Click the territory so it changes to Allowed (Green).
- Click Save to commit the changes and remove the countryβs IP subnets from the kernel drop set.
7. Troubleshooting & Diagnostic Commands
Section titled β7. Troubleshooting & Diagnostic CommandsβInspecting Configured Geo Rules in Database
Section titled βInspecting Configured Geo Rules in Databaseβsudo -u postgres psql -d ss_billing -c \ "SELECT country_code, country_name, action, enabled, updated_at \ FROM geo_firewall_rules WHERE action = 'block' ORDER BY country_name ASC;"Checking Linux nftables Geo Drop Sets
Section titled βChecking Linux nftables Geo Drop Setsβ# Count total CIDR elements loaded into the geo drop setnft list set inet filter geo_drop | grep -c "elements"
# Verify if a specific IP belongs to a blocked geo setnft "get element inet filter geo_drop { 198.51.100.1 }"8. Model Context Protocol (MCP) AI Integration
Section titled β8. Model Context Protocol (MCP) AI IntegrationβThe Geo Firewall module connects directly to the Ring2All BSS MCP Server, providing security copilots and network automation tools with instant visibility into geographic filtering policies and blocked territory counts.
Available MCP Tools
Section titled βAvailable MCP Toolsβ| Tool Name | Access Role | Description & Primary Function | Example Arguments |
|---|---|---|---|
get_geo_firewall_status |
Super Administrator |
Retrieves geographical IP blocking status, blocked country count, and database version. | {} |
Sample MCP Tool Execution: get_geo_firewall_status
Section titled βSample MCP Tool Execution: get_geo_firewall_statusβRequest Payload
Section titled βRequest Payloadβ{ "name": "get_geo_firewall_status", "arguments": {}}Response Payload
Section titled βResponse Payloadβ{ "geoFirewallEnabled": true, "blockedCountriesCount": 18, "allowedCountriesCount": 231, "geoDbVersion": "GeoLite2-Country-2026.09", "kernelSetLoaded": true, "topBlockedCountries": ["RU", "CN", "IR", "KP", "NG"]}Conversational AI Prompts for Copilot
Section titled βConversational AI Prompts for Copilotβ- βWhat is the status of the Geo Firewall and how many countries are blocked?β
- βList the top blocked country codes enforced at the kernel level.β
- βVerify if the GeoIP database is current and loaded into nftables.β
9. Glossary
Section titled β9. Glossaryβ- ISO 3166-1 Alpha-2: Two-letter country codes representing countries and dependent territories (e.g.,
US,DE,MX). - GeoIP Database: A structured mapping table connecting public IPv4 and IPv6 address ranges to geographic countries, cities, and autonomous system numbers (ASNs).
- PREROUTING: The earliest stage in the Linux network stack where incoming packets can be evaluated before routing decisions are made.
- O(1) Set Lookup: Constant-time algorithmic lookup provided by kernel hash tables (
nftablessets /ipset), ensuring zero latency impact regardless of table size. - Model Context Protocol (MCP): Open protocol standard that enables secure, controlled integration between Large Language Models and external tools, databases, and telecom rating engines.

