Skip to content

Firewall Rules Module Documentation

15 min readUpdated: Sep 26, 2026
View as Markdown
  1. Navigation & Access
  2. Screenshots & Visual Interface
  3. Module Overview (Technical)
  4. Module Overview (Commercial/Business)
  5. Module Overview (End User/Administrator)
  6. User Roles & Key Capabilities
  7. Configuration Sections
  8. Settings Reference
  9. Common Scenarios & Examples
  10. Model Context Protocol (MCP) AI Integration
  11. Limitations & Important Notes
  12. Troubleshooting Tips
  13. Glossary

To access the Firewall Rules module:

  1. Log in to the Ring2All Web Portal (https://<domain-or-ip>/login) with administrative credentials.
  2. In the left navigation sidebar, locate and expand Admin.
  3. Under the Firewall section, click Rules (/admin/firewall/rules).
  4. To add a new packet filtering rule, click the + Add button at the top right of the toolbar.
  5. To apply all active database rules directly into the host operating system’s nftables firewall tables, click Apply Rules.
  6. To modify or delete an existing rule, use the edit or trash icons in the corresponding table row.

The Firewall Rules interface displays all active packet filtering policies with their rule names, dispositions (ACCEPT, DROP, REJECT), traffic directions, associated services, rule priorities, operational states, and action triggers. Firewall Rules List

The rule configuration dialog enables administrators to define rule labels, select disposition actions (Accept, Drop, Reject), traffic direction (Input, Forward, Output), target service definitions, rule priorities, source/destination CIDRs, network interface constraints, and enabled states. Add Firewall Rule Modal


Firewall Rules is a traffic control module that creates nftables rules for accepting, dropping, or rejecting network traffic. Rules reference Firewall Services and are evaluated in priority order.

┌─────────────────────────────────────────────────────────────────┐
│ Firewall Rules Architecture │
├─────────────────────────────────────────────────────────────────┤
│ │
│ Rule Definitions │
│ ┌──────────────────────────────────────────────────────────┐ │
│ │ │ │
│ │ Priority: 10 Priority: 20 │ │
│ │ ┌────────────────────┐ ┌────────────────────┐ │ │
│ │ │ Allow Admin SSH │ │ Allow HTTP │ │ │
│ │ │ Action: Accept │ │ Action: Accept │ │ │
│ │ │ Direction: Input │ │ Direction: Input │ │ │
│ │ │ Service: SSH │ │ Service: HTTP │ │ │
│ │ │ Source: 10.0.0.5 │ │ Source: any │ │ │
│ │ └────────────────────┘ └────────────────────┘ │ │
│ │ │ │
│ │ Priority: 100 Priority: 200 │ │
│ │ ┌────────────────────┐ ┌────────────────────┐ │ │
│ │ │ Allow SIP LAN │ │ Block SSH External │ │ │
│ │ │ Action: Accept │ │ Action: Drop │ │ │
│ │ │ Direction: Input │ │ Direction: Input │ │ │
│ │ │ Service: SIP │ │ Service: SSH │ │ │
│ │ │ Source: 192.168.x │ │ Source: any │ │ │
│ │ └────────────────────┘ └────────────────────┘ │ │
│ │ │ │
│ └──────────────────────────────────────────────────────────┘ │
│ │ │
│ ▼ [Apply Rules] │
│ ┌──────────────────────────────────────────────────────────┐ │
│ │ nftables Configuration │ │
│ │ │ │
│ │ table inet filter { │ │
│ │ chain input { │ │
│ │ # Priority 10: Allow Admin SSH │ │
│ │ ip saddr 10.0.0.5 tcp dport 22 accept │ │
│ │ # Priority 20: Allow HTTP │ │
│ │ tcp dport 80 accept │ │
│ │ # Priority 100: Allow SIP LAN │ │
│ │ ip saddr 192.168.0.0/16 udp dport 5060 accept │ │
│ │ # Priority 200: Block SSH External │ │
│ │ tcp dport 22 drop │ │
│ │ } │ │
│ │ } │ │
│ │ │ │
│ └──────────────────────────────────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────┘

Firewall Rules provides network traffic control:

Without Rules With Rules
Open access Controlled traffic
No priority Ordered evaluation
Manual nftables Web interface
Complex syntax Simple forms
  1. Allow Services

    • Web traffic (HTTP/HTTPS)
    • SIP/RTP for telephony
  2. Block Attacks

    • Drop external SSH
    • Reject scanners
  3. LAN Access Only

    • SIP from internal only
    • Admin from VPN only
  4. Priority Control

    • Allow before block
    • Specific before general
Feature Benefit
Accept/Drop/Reject Flexible actions
Priority Order Controlled evaluation
Service Reference Reusable definitions
Source/Dest Filter IP-based access
Interface Binding Per-interface rules
Apply Button Controlled deployment

3. Module Overview (End User/Administrator)

Section titled “3. Module Overview (End User/Administrator)”
  • Create traffic rules
  • Allow or block traffic
  • Set priority order
  • Filter by IP address
  • Bind to interfaces
  • Apply rules to nftables
  • Enable/disable rules
┌─────────────────────────────────────────────────────────────────┐
│ Firewall Rules │
├─────────────────────────────────────────────────────────────────┤
│ │
│ Manage firewall rules for nftables (Debian 13) │
│ │
│ [+ Add Rule] [Apply Rules] │
│ │
│ [🔍 Search rules...] │
│ │
│ ┌───────────────────────────────────────────────────────────┐ │
│ │ Name │ Action│ Direction│ Service│ Priority│ St │ │
│ ├───────────────┼───────┼──────────┼────────┼─────────┼────┤ │
│ │ Allow Admin │ Accept│ Input │ SSH │ 10 │ ● │ │
│ │ Allow HTTP │ Accept│ Input │ HTTP │ 20 │ ● │ │
│ │ Allow HTTPS │ Accept│ Input │ HTTPS │ 30 │ ● │ │
│ │ Allow SIP LAN │ Accept│ Input │ SIP │ 100 │ ● │ │
│ │ Allow RTP │ Accept│ Input │ RTP │ 110 │ ● │ │
│ │ Block SSH Ext │ Drop │ Input │ SSH │ 200 │ ● │ │
│ │ Block All │ Drop │ Input │ - │ 9999 │ ○ │ │
│ └───────────────────────────────────────────────────────────┘ │
│ │
│ ⚠️ Click "Apply Rules" after changes │
│ │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ Add Firewall Rule │
├─────────────────────────────────────────────────────────────────┤
│ │
│ Rule Name: [Allow SIP from LAN ] │
│ Descriptive name for the rule (must be unique) │
│ │
│ Action: [Accept ▼] │
│ Accept (allow) | Drop (silent block) | Reject (block+respond)│
│ │
│ Direction: [Input ▼] │
│ Input (to server) | Output (from server) | Forward (routed) │
│ │
│ Service: [SIP ▼] │
│ Associated firewall service (required) │
│ The rule will use the selected service's protocol and port │
│ │
│ Priority: [100 ] │
│ Rule priority (0-9999). Lower numbers are evaluated first │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ Source Address: [192.168.1.0/24 ] │
│ Optional: Source IP address or CIDR network │
│ │
│ Destination Address: [ ] │
│ Optional: Destination IP address or CIDR network │
│ │
│ Interface: [eth0 ] │
│ Optional: Network interface (e.g., eth0, ens33) │
│ │
│ ──────────────────────────────────────────────────────────────│
│ │
│ Enabled: ✓ │
│ Disabled rules will not be applied to nftables │
│ │
│ [Save] [Cancel] │
│ │
└─────────────────────────────────────────────────────────────────┘

[!TIP] Priority: Lower numbers execute first. Allow admin access at low priority!

[!TIP] Apply Rules: Always click after making changes.

[!CAUTION] Don’t Block Yourself: Create allow rule for your IP before blocking!


The Firewall Rules module manages kernel packet filtering policies, delineating capabilities across administrative tiers:

User Role Key Permissions & Responsibilities Common Tasks & Workflows
System Super Administrator Total control over host nftables tables, rule chains, and packet admission/rejection actions. Create and delete packet filtering rules, reorder rule evaluation priorities, apply database rules to host kernel tables, safeguard administrative SSH/HTTPS access.
VoIP / Network Engineer Constructing fine-grained packet filters for telephony carriers, inter-PBX trunks, and remote office SBCs. Allow SIP 5060 traffic from carrier subnets, open RTP port ranges (16384-32768) to media gateways, drop unauthenticated SIP probes on public interfaces.
NOC / Support Engineer Troubleshooting blocked audio/signaling and monitoring dropped packet metrics. Inspect rule hit counters, verify rule execution order (allow rules before default drop), test IP subnet reachability, temporarily disable rules during troubleshooting.
Information Security Auditor Validating that network boundary defenses adhere to the principle of least privilege. Audit firewall rules against CIS benchmarks, verify that public interfaces enforce a default DROP policy, check that administrative ports are restricted to management subnets.

Field Description
Rule Name Unique identifier
Action Accept, Drop, Reject
Direction Input, Output, Forward
Service Service reference (required)
Priority Order (0-9999)
Source Address Source IP/CIDR (optional)
Destination Address Dest IP/CIDR (optional)
Interface Network interface (optional)
Enabled Active/Inactive

Action Behavior Response Use Case
Accept Allow traffic - Permitted traffic
Drop Block silently None Stealth blocking
Reject Block with response ICMP error Inform sender
Direction Description Example
Input Traffic TO server Web requests
Output Traffic FROM server API calls
Forward Routed traffic NAT/routing
Priority Range Use
1-50 Critical allows (admin access)
51-100 Standard allows (web, API)
101-200 Service allows (SIP, RTP)
201-500 Specific blocks
501-9999 Broad blocks, catch-all
Priority 10: Allow Admin SSH (source: admin IP)
Priority 20: Allow HTTP (any source)
Priority 100: Allow SIP LAN (source: 192.168.x)
Priority 200: Block SSH External (any source)
Priority 9999: Block All (catch-all)

  1. Add Rule
  2. Name = “Allow HTTP”
  3. Action = Accept
  4. Direction = Input
  5. Service = HTTP
  6. Priority = 20
  7. Save
  8. Repeat for HTTPS (Priority 30)
  9. Apply Rules
  1. Add Rule
  2. Name = “Allow SIP LAN”
  3. Action = Accept
  4. Direction = Input
  5. Service = SIP
  6. Priority = 100
  7. Source = 192.168.1.0/24
  8. Save
  9. Apply Rules
  1. First: Create “Allow Admin SSH” (Priority 10, Source: your IP)
  2. Add Rule
  3. Name = “Block SSH External”
  4. Action = Drop
  5. Direction = Input
  6. Service = SSH
  7. Priority = 200
  8. (No source = all sources)
  9. Save
  10. Apply Rules
Priority 10: Allow Admin SSH (Source: admin IP)
Priority 20: Allow HTTP (Any - redirect to HTTPS)
Priority 30: Allow HTTPS (Any - includes WebRTC WSS proxy)
Priority 100: Allow SIP UDP (Source: LAN + Trunks)
Priority 110: Allow SIP TLS (Source: LAN + Trunks)
Priority 120: Allow RTP (Any)
Priority 130: Allow STUN (Any - NAT traversal)
Priority 131: Allow TURN TLS (Any - NAT traversal)
Priority 200: Block SSH External (Any)
Priority 300: Block SIP External (Any)

[!NOTE] Apply Required: Rules don’t take effect until applied.

[!NOTE] Priority Order: Lower numbers are processed first.

[!CAUTION] Lock-Out Risk: Always allow admin access before blocking!

  1. Admin First: Always create allow rule for admin access first
  2. Specific Before General: Narrow rules before broad blocks
  3. Meaningful Names: Clear, descriptive rule names
  4. Document Purpose: Use consistent naming convention
  5. Test Changes: Verify access after applying
  6. Backup Access: Have console/IPMI access available
1. Enabled rules only
2. Sorted by priority (ascending)
3. First matching rule wins
4. If no match, default policy applies
Mistake Result Prevention
Block before allow Locked out Lower priority for blocks
No admin allow Can’t access Priority 1-10 admin rules
Forgot Apply Rules inactive Always click Apply
Wrong direction Not matching Verify Input vs Output

Model Context Protocol (MCP) AI Integration

Section titled “Model Context Protocol (MCP) AI Integration”

The Firewall Rules module connects directly to the Ring2All Platform Copilot MCP Server, enabling natural language network packet filtering operations:

Tool Name Operation Access Level Description Key Parameters
list_firewall_rules Read SuperAdmin / Auditor Lists all network Firewall Rules (port, protocol: TCP/UDP, action: ACCEPT/DROP, source IP/CIDR subnet). search (string, optional)
create_firewall_rule Write SuperAdmin Only Creates a new network firewall rule to allow or block access to specific PBX ports (SIP 5060, Web 443, RTP ranges). name (string), action (accept, drop, reject), protocol (tcp, udp, all), port (string), sourceIp (string)
delete_firewall_rule Delete (Guarded) SuperAdmin Only Deletes a firewall rule from the PBX database and unbinds it from the running nftables kernel filter. ruleId (string/number, required)
get_firewall_settings Read SuperAdmin / Auditor Returns overarching host firewall state and intrusion detection parameters. None
diagnose_ip_security Diagnostic / Query Security Operator Performs comprehensive perimeter security diagnosis on an IP address: inspects Fail2ban jails (telephony, sip, web, sshd), kernel nftables drop rules, DB firewall rules, ACL deny lists, and threat reputation feeds. ipAddress (string, required)

📋 JSON Tool Schemas & Sample Executions

Section titled “📋 JSON Tool Schemas & Sample Executions”
{
"name": "list_firewall_rules",
"arguments": {
"search": "Carrier"
}
}

Sample Successful Response:

{
"success": true,
"data": {
"total": 1,
"rules": [
{
"id": 4,
"name": "Allow SIP Carrier Trunks",
"action": "accept",
"protocol": "udp",
"port": "5060",
"sourceIp": "198.51.100.0/24",
"enabled": true
}
]
}
}
{
"name": "create_firewall_rule",
"arguments": {
"name": "Allow Branch PBX SIP",
"action": "accept",
"protocol": "udp",
"port": "5060",
"sourceIp": "192.0.2.50/32"
}
}

Sample Successful Response:

{
"success": true,
"data": {
"message": "Firewall rule \"Allow Branch PBX SIP\" (ACCEPT from 192.0.2.50/32) created successfully!",
"name": "Allow Branch PBX SIP",
"id": 8
}
}
  • “List all firewall rules configured for SIP port 5060.”
  • “Show all active rules that drop or reject inbound traffic.”
  • “Create an ACCEPT rule for branch office IP ‘192.0.2.50/32’ on port 5060 UDP.”
  • “Delete firewall rule with ID 8.”
  • “Verify if any firewall rule permits SSH traffic from 0.0.0.0/0.”
  • “Lista todas las reglas del firewall configuradas para el puerto SIP 5060.”
  • “Muestra todas las reglas activas que descartan (DROP) o rechazan (REJECT) tráfico entrante.”
  • “Crea una regla de ACEPTAR para la IP de la sucursal ‘192.0.2.50/32’ en el puerto 5060 UDP.”
  • “Elimina la regla de firewall con ID 8.”
  • “Comprueba si alguna regla de firewall permite tráfico SSH desde cualquier origen (0.0.0.0/0).”
{
"name": "diagnose_ip_security",
"arguments": {
"ipAddress": "198.51.100.50"
}
}

Sample Successful Response:

{
"success": true,
"data": {
"ipAddress": "198.51.100.50",
"isBanned": true,
"jails": ["sip-auth-failure"],
"nftablesStatus": "Blocked by filter input",
"threatReputation": "Listed on VoIPBL (high malicious score)",
"recommendation": "Review IP authentication logs before unbanning via unban_ip_address"
}
}

🛡️ Enterprise Safeguards & Best Practices

Section titled “🛡️ Enterprise Safeguards & Best Practices”
  1. Protected System Rules: Core protection rules marked as is_system = true (such as anti-lockout SSH rules or localhost loopback rules) cannot be deleted via MCP.
  2. Rule Priority Hierarchy: Rules are assigned numerical priorities (1-1000). Lower numbers are evaluated first in nftables, ensuring explicit ACCEPT overrides take precedence before DROP rules.
  3. CIDR Subnet Validation: Any source IP provided must be a valid IPv4 host (1.2.3.4) or CIDR subnet (1.2.3.0/24); invalid notations are rejected before touching kernel tables.

Symptom Possible Cause Solution
Rule not working Not applied Click Apply Rules
Blocked traffic Priority wrong Check priority order
Can’t connect Locked out Console access
Service not in list Disabled service Enable in Services
SELECT
name,
action,
direction,
priority,
source_address,
is_enabled
FROM public.firewall_rules
ORDER BY priority;
Terminal window
# View current rules
nft list ruleset
# View input chain
nft list chain inet filter input
# Flush rules (emergency)
nft flush ruleset
Terminal window
# If locked out via SSH:
# 1. Access server console (IPMI, KVM, physical)
# 2. Disable firewall temporarily
systemctl stop nftables
# 3. Fix rules via admin panel
# 4. Re-enable firewall
systemctl start nftables

Term Definition
Rule Traffic control statement
Action What to do (accept/drop/reject)
Direction Traffic flow direction
Priority Rule evaluation order
nftables Linux firewall framework
Chain Rule processing group

Documentation last updated: January 2026