--- title: "Firewall Rules Module Documentation" description: "Documentation for Firewall Rules" --- ## Table of Contents 1. [Navigation & Access](#navigation--access) 2. [Screenshots & Visual Interface](#screenshots--visual-interface) 3. [Module Overview (Technical)](#1-module-overview-technical) 4. [Module Overview (Commercial/Business)](#2-module-overview-commercialbusiness) 5. [Module Overview (End User/Administrator)](#3-module-overview-end-useradministrator) 6. [User Roles & Key Capabilities](#-user-roles--key-capabilities) 7. [Configuration Sections](#4-configuration-sections) 8. [Settings Reference](#5-settings-reference) 9. [Common Scenarios & Examples](#6-common-scenarios--examples) 10. [Model Context Protocol (MCP) AI Integration](#model-context-protocol-mcp-ai-integration) 11. [Limitations & Important Notes](#7-limitations--important-notes) 12. [Troubleshooting Tips](#8-troubleshooting-tips) 13. [Glossary](#9-glossary) --- ## Navigation & Access To access the Firewall Rules module: 1. Log in to the Ring2All Web Portal (`https:///login`) with administrative credentials. 2. In the left navigation sidebar, locate and expand **Admin**. 3. Under the **Firewall** section, click **Rules** (`/admin/firewall/rules`). 4. To add a new packet filtering rule, click the **+ Add** button at the top right of the toolbar. 5. To apply all active database rules directly into the host operating system's nftables firewall tables, click **Apply Rules**. 6. To modify or delete an existing rule, use the edit or trash icons in the corresponding table row. --- ## Screenshots & Visual Interface ### Firewall Rules List View The Firewall Rules interface displays all active packet filtering policies with their rule names, dispositions (`ACCEPT`, `DROP`, `REJECT`), traffic directions, associated services, rule priorities, operational states, and action triggers. ![Firewall Rules List](/screenshots/admin/firewall/firewall-rules-list.png) ### Add / Edit Firewall Rule Modal The rule configuration dialog enables administrators to define rule labels, select disposition actions (`Accept`, `Drop`, `Reject`), traffic direction (`Input`, `Forward`, `Output`), target service definitions, rule priorities, source/destination CIDRs, network interface constraints, and enabled states. ![Add Firewall Rule Modal](/screenshots/admin/firewall/firewall-rules-form.png) --- ## 1. Module Overview (Technical) ### What Are Firewall Rules? Firewall Rules is a **traffic control module** that creates nftables rules for accepting, dropping, or rejecting network traffic. Rules reference Firewall Services and are evaluated in priority order. ### Architecture ``` ┌─────────────────────────────────────────────────────────────────┐ │ Firewall Rules Architecture │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Rule Definitions │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ │ │ │ │ Priority: 10 Priority: 20 │ │ │ │ ┌────────────────────┐ ┌────────────────────┐ │ │ │ │ │ Allow Admin SSH │ │ Allow HTTP │ │ │ │ │ │ Action: Accept │ │ Action: Accept │ │ │ │ │ │ Direction: Input │ │ Direction: Input │ │ │ │ │ │ Service: SSH │ │ Service: HTTP │ │ │ │ │ │ Source: 10.0.0.5 │ │ Source: any │ │ │ │ │ └────────────────────┘ └────────────────────┘ │ │ │ │ │ │ │ │ Priority: 100 Priority: 200 │ │ │ │ ┌────────────────────┐ ┌────────────────────┐ │ │ │ │ │ Allow SIP LAN │ │ Block SSH External │ │ │ │ │ │ Action: Accept │ │ Action: Drop │ │ │ │ │ │ Direction: Input │ │ Direction: Input │ │ │ │ │ │ Service: SIP │ │ Service: SSH │ │ │ │ │ │ Source: 192.168.x │ │ Source: any │ │ │ │ │ └────────────────────┘ └────────────────────┘ │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ │ │ ▼ [Apply Rules] │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ nftables Configuration │ │ │ │ │ │ │ │ table inet filter { │ │ │ │ chain input { │ │ │ │ # Priority 10: Allow Admin SSH │ │ │ │ ip saddr 10.0.0.5 tcp dport 22 accept │ │ │ │ # Priority 20: Allow HTTP │ │ │ │ tcp dport 80 accept │ │ │ │ # Priority 100: Allow SIP LAN │ │ │ │ ip saddr 192.168.0.0/16 udp dport 5060 accept │ │ │ │ # Priority 200: Block SSH External │ │ │ │ tcp dport 22 drop │ │ │ │ } │ │ │ │ } │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` --- ## 2. Module Overview (Commercial/Business) ### Business Value Firewall Rules provides **network traffic control**: | Without Rules | With Rules | |---------------|------------| | Open access | Controlled traffic | | No priority | Ordered evaluation | | Manual nftables | Web interface | | Complex syntax | Simple forms | ### Use Cases 1. **Allow Services** - Web traffic (HTTP/HTTPS) - SIP/RTP for telephony 2. **Block Attacks** - Drop external SSH - Reject scanners 3. **LAN Access Only** - SIP from internal only - Admin from VPN only 4. **Priority Control** - Allow before block - Specific before general ### Feature Highlights | Feature | Benefit | |---------|---------| | **Accept/Drop/Reject** | Flexible actions | | **Priority Order** | Controlled evaluation | | **Service Reference** | Reusable definitions | | **Source/Dest Filter** | IP-based access | | **Interface Binding** | Per-interface rules | | **Apply Button** | Controlled deployment | --- ## 3. Module Overview (End User/Administrator) ### What Can You Do? - Create traffic rules - Allow or block traffic - Set priority order - Filter by IP address - Bind to interfaces - Apply rules to nftables - Enable/disable rules ### Firewall Rules Interface ``` ┌─────────────────────────────────────────────────────────────────┐ │ Firewall Rules │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Manage firewall rules for nftables (Debian 13) │ │ │ │ [+ Add Rule] [Apply Rules] │ │ │ │ [🔍 Search rules...] │ │ │ │ ┌───────────────────────────────────────────────────────────┐ │ │ │ Name │ Action│ Direction│ Service│ Priority│ St │ │ │ ├───────────────┼───────┼──────────┼────────┼─────────┼────┤ │ │ │ Allow Admin │ Accept│ Input │ SSH │ 10 │ ● │ │ │ │ Allow HTTP │ Accept│ Input │ HTTP │ 20 │ ● │ │ │ │ Allow HTTPS │ Accept│ Input │ HTTPS │ 30 │ ● │ │ │ │ Allow SIP LAN │ Accept│ Input │ SIP │ 100 │ ● │ │ │ │ Allow RTP │ Accept│ Input │ RTP │ 110 │ ● │ │ │ │ Block SSH Ext │ Drop │ Input │ SSH │ 200 │ ● │ │ │ │ Block All │ Drop │ Input │ - │ 9999 │ ○ │ │ │ └───────────────────────────────────────────────────────────┘ │ │ │ │ ⚠️ Click "Apply Rules" after changes │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Add/Edit Rule ``` ┌─────────────────────────────────────────────────────────────────┐ │ Add Firewall Rule │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Rule Name: [Allow SIP from LAN ] │ │ Descriptive name for the rule (must be unique) │ │ │ │ Action: [Accept ▼] │ │ Accept (allow) | Drop (silent block) | Reject (block+respond)│ │ │ │ Direction: [Input ▼] │ │ Input (to server) | Output (from server) | Forward (routed) │ │ │ │ Service: [SIP ▼] │ │ Associated firewall service (required) │ │ The rule will use the selected service's protocol and port │ │ │ │ Priority: [100 ] │ │ Rule priority (0-9999). Lower numbers are evaluated first │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ Source Address: [192.168.1.0/24 ] │ │ Optional: Source IP address or CIDR network │ │ │ │ Destination Address: [ ] │ │ Optional: Destination IP address or CIDR network │ │ │ │ Interface: [eth0 ] │ │ Optional: Network interface (e.g., eth0, ens33) │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ Enabled: ✓ │ │ Disabled rules will not be applied to nftables │ │ │ │ [Save] [Cancel] │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Quick Tips > [!TIP] > **Priority**: Lower numbers execute first. Allow admin access at low priority! > [!TIP] > **Apply Rules**: Always click after making changes. > [!CAUTION] > **Don't Block Yourself**: Create allow rule for your IP before blocking! --- ## 🎯 User Roles & Key Capabilities The Firewall Rules module manages kernel packet filtering policies, delineating capabilities across administrative tiers: | User Role | Key Permissions & Responsibilities | Common Tasks & Workflows | |:---|:---|:---| | **System Super Administrator** | Total control over host `nftables` tables, rule chains, and packet admission/rejection actions. | Create and delete packet filtering rules, reorder rule evaluation priorities, apply database rules to host kernel tables, safeguard administrative SSH/HTTPS access. | | **VoIP / Network Engineer** | Constructing fine-grained packet filters for telephony carriers, inter-PBX trunks, and remote office SBCs. | Allow SIP 5060 traffic from carrier subnets, open RTP port ranges (`16384-32768`) to media gateways, drop unauthenticated SIP probes on public interfaces. | | **NOC / Support Engineer** | Troubleshooting blocked audio/signaling and monitoring dropped packet metrics. | Inspect rule hit counters, verify rule execution order (allow rules before default drop), test IP subnet reachability, temporarily disable rules during troubleshooting. | | **Information Security Auditor** | Validating that network boundary defenses adhere to the principle of least privilege. | Audit firewall rules against CIS benchmarks, verify that public interfaces enforce a default `DROP` policy, check that administrative ports are restricted to management subnets. | --- ## 4. Configuration Sections ### Rule Fields | Field | Description | |-------|-------------| | **Rule Name** | Unique identifier | | **Action** | Accept, Drop, Reject | | **Direction** | Input, Output, Forward | | **Service** | Service reference (required) | | **Priority** | Order (0-9999) | | **Source Address** | Source IP/CIDR (optional) | | **Destination Address** | Dest IP/CIDR (optional) | | **Interface** | Network interface (optional) | | **Enabled** | Active/Inactive | --- ## 5. Settings Reference ### Actions | Action | Behavior | Response | Use Case | |--------|----------|----------|----------| | **Accept** | Allow traffic | - | Permitted traffic | | **Drop** | Block silently | None | Stealth blocking | | **Reject** | Block with response | ICMP error | Inform sender | ### Directions | Direction | Description | Example | |-----------|-------------|---------| | **Input** | Traffic TO server | Web requests | | **Output** | Traffic FROM server | API calls | | **Forward** | Routed traffic | NAT/routing | ### Priority Guidelines | Priority Range | Use | |----------------|-----| | 1-50 | Critical allows (admin access) | | 51-100 | Standard allows (web, API) | | 101-200 | Service allows (SIP, RTP) | | 201-500 | Specific blocks | | 501-9999 | Broad blocks, catch-all | ### Priority Examples ``` Priority 10: Allow Admin SSH (source: admin IP) Priority 20: Allow HTTP (any source) Priority 100: Allow SIP LAN (source: 192.168.x) Priority 200: Block SSH External (any source) Priority 9999: Block All (catch-all) ``` --- ## 6. Common Scenarios & Examples ### Scenario 1: Allow HTTP/HTTPS 1. Add Rule 2. Name = "Allow HTTP" 3. Action = Accept 4. Direction = Input 5. Service = HTTP 6. Priority = 20 7. Save 8. Repeat for HTTPS (Priority 30) 9. Apply Rules ### Scenario 2: Allow SIP from LAN Only 1. Add Rule 2. Name = "Allow SIP LAN" 3. Action = Accept 4. Direction = Input 5. Service = SIP 6. Priority = 100 7. Source = 192.168.1.0/24 8. Save 9. Apply Rules ### Scenario 3: Block External SSH 1. First: Create "Allow Admin SSH" (Priority 10, Source: your IP) 2. Add Rule 3. Name = "Block SSH External" 4. Action = Drop 5. Direction = Input 6. Service = SSH 7. Priority = 200 8. (No source = all sources) 9. Save 10. Apply Rules ### Scenario 4: Complete PBX Ruleset ``` Priority 10: Allow Admin SSH (Source: admin IP) Priority 20: Allow HTTP (Any - redirect to HTTPS) Priority 30: Allow HTTPS (Any - includes WebRTC WSS proxy) Priority 100: Allow SIP UDP (Source: LAN + Trunks) Priority 110: Allow SIP TLS (Source: LAN + Trunks) Priority 120: Allow RTP (Any) Priority 130: Allow STUN (Any - NAT traversal) Priority 131: Allow TURN TLS (Any - NAT traversal) Priority 200: Block SSH External (Any) Priority 300: Block SIP External (Any) ``` --- ## 7. Limitations & Important Notes ### Technical Notes > [!NOTE] > **Apply Required**: Rules don't take effect until applied. > [!NOTE] > **Priority Order**: Lower numbers are processed first. > [!CAUTION] > **Lock-Out Risk**: Always allow admin access before blocking! ### Best Practices 1. **Admin First**: Always create allow rule for admin access first 2. **Specific Before General**: Narrow rules before broad blocks 3. **Meaningful Names**: Clear, descriptive rule names 4. **Document Purpose**: Use consistent naming convention 5. **Test Changes**: Verify access after applying 6. **Backup Access**: Have console/IPMI access available ### Rule Evaluation Order ``` 1. Enabled rules only 2. Sorted by priority (ascending) 3. First matching rule wins 4. If no match, default policy applies ``` ### Common Mistakes | Mistake | Result | Prevention | |---------|--------|------------| | Block before allow | Locked out | Lower priority for blocks | | No admin allow | Can't access | Priority 1-10 admin rules | | Forgot Apply | Rules inactive | Always click Apply | | Wrong direction | Not matching | Verify Input vs Output | --- ## Model Context Protocol (MCP) AI Integration The Firewall Rules module connects directly to the **Ring2All Platform Copilot MCP Server**, enabling natural language network packet filtering operations: ### 🛠️ Available MCP Tools | Tool Name | Operation | Access Level | Description | Key Parameters | |:---|:---|:---|:---|:---| | `list_firewall_rules` | Read | SuperAdmin / Auditor | Lists all network Firewall Rules (port, protocol: TCP/UDP, action: ACCEPT/DROP, source IP/CIDR subnet). | `search` (string, optional) | | `create_firewall_rule` | Write | SuperAdmin Only | Creates a new network firewall rule to allow or block access to specific PBX ports (SIP 5060, Web 443, RTP ranges). | `name` (string), `action` (`accept`, `drop`, `reject`), `protocol` (`tcp`, `udp`, `all`), `port` (string), `sourceIp` (string) | | `delete_firewall_rule` | Delete (Guarded) | SuperAdmin Only | Deletes a firewall rule from the PBX database and unbinds it from the running nftables kernel filter. | `ruleId` (string/number, required) | | `get_firewall_settings` | Read | SuperAdmin / Auditor | Returns overarching host firewall state and intrusion detection parameters. | None | | `diagnose_ip_security` | Diagnostic / Query | Security Operator | Performs comprehensive perimeter security diagnosis on an IP address: inspects Fail2ban jails (telephony, sip, web, sshd), kernel nftables drop rules, DB firewall rules, ACL deny lists, and threat reputation feeds. | `ipAddress` (string, required) | ### 📋 JSON Tool Schemas & Sample Executions #### `list_firewall_rules` ```json { "name": "list_firewall_rules", "arguments": { "search": "Carrier" } } ``` *Sample Successful Response:* ```json { "success": true, "data": { "total": 1, "rules": [ { "id": 4, "name": "Allow SIP Carrier Trunks", "action": "accept", "protocol": "udp", "port": "5060", "sourceIp": "198.51.100.0/24", "enabled": true } ] } } ``` #### `create_firewall_rule` ```json { "name": "create_firewall_rule", "arguments": { "name": "Allow Branch PBX SIP", "action": "accept", "protocol": "udp", "port": "5060", "sourceIp": "192.0.2.50/32" } } ``` *Sample Successful Response:* ```json { "success": true, "data": { "message": "Firewall rule \"Allow Branch PBX SIP\" (ACCEPT from 192.0.2.50/32) created successfully!", "name": "Allow Branch PBX SIP", "id": 8 } } ``` ### 💬 Natural Language Prompt Examples #### English Prompts - *"List all firewall rules configured for SIP port 5060."* - *"Show all active rules that drop or reject inbound traffic."* - *"Create an ACCEPT rule for branch office IP '192.0.2.50/32' on port 5060 UDP."* - *"Delete firewall rule with ID 8."* - *"Verify if any firewall rule permits SSH traffic from 0.0.0.0/0."* #### Ejemplos en Español (Spanish Prompts) - *"Lista todas las reglas del firewall configuradas para el puerto SIP 5060."* - *"Muestra todas las reglas activas que descartan (DROP) o rechazan (REJECT) tráfico entrante."* - *"Crea una regla de ACEPTAR para la IP de la sucursal '192.0.2.50/32' en el puerto 5060 UDP."* - *"Elimina la regla de firewall con ID 8."* - *"Comprueba si alguna regla de firewall permite tráfico SSH desde cualquier origen (0.0.0.0/0)."* #### `diagnose_ip_security` ```json { "name": "diagnose_ip_security", "arguments": { "ipAddress": "198.51.100.50" } } ``` *Sample Successful Response:* ```json { "success": true, "data": { "ipAddress": "198.51.100.50", "isBanned": true, "jails": ["sip-auth-failure"], "nftablesStatus": "Blocked by filter input", "threatReputation": "Listed on VoIPBL (high malicious score)", "recommendation": "Review IP authentication logs before unbanning via unban_ip_address" } } ``` ### 🛡️ Enterprise Safeguards & Best Practices 1. **Protected System Rules**: Core protection rules marked as `is_system = true` (such as anti-lockout SSH rules or localhost loopback rules) cannot be deleted via MCP. 2. **Rule Priority Hierarchy**: Rules are assigned numerical priorities (1-1000). Lower numbers are evaluated first in `nftables`, ensuring explicit ACCEPT overrides take precedence before DROP rules. 3. **CIDR Subnet Validation**: Any source IP provided must be a valid IPv4 host (`1.2.3.4`) or CIDR subnet (`1.2.3.0/24`); invalid notations are rejected before touching kernel tables. --- ## 8. Troubleshooting Tips ### Common Issues | Symptom | Possible Cause | Solution | |---------|---------------|----------| | Rule not working | Not applied | Click Apply Rules | | Blocked traffic | Priority wrong | Check priority order | | Can't connect | Locked out | Console access | | Service not in list | Disabled service | Enable in Services | ### Check Rules ```sql SELECT name, action, direction, priority, source_address, is_enabled FROM public.firewall_rules ORDER BY priority; ``` ### nftables Commands ```bash # View current rules nft list ruleset # View input chain nft list chain inet filter input # Flush rules (emergency) nft flush ruleset ``` ### Emergency Recovery ```bash # If locked out via SSH: # 1. Access server console (IPMI, KVM, physical) # 2. Disable firewall temporarily systemctl stop nftables # 3. Fix rules via admin panel # 4. Re-enable firewall systemctl start nftables ``` --- ## 9. Glossary | Term | Definition | |------|------------| | **Rule** | Traffic control statement | | **Action** | What to do (accept/drop/reject) | | **Direction** | Traffic flow direction | | **Priority** | Rule evaluation order | | **nftables** | Linux firewall framework | | **Chain** | Rule processing group | --- *Documentation last updated: January 2026*