--- title: "Firewall Settings Module Documentation" description: "Documentation for Firewall Settings" --- ## Table of Contents 1. [Navigation & Access](#navigation--access) 2. [Screenshots & Visual Interface](#screenshots--visual-interface) 3. [Module Overview (Technical)](#1-module-overview-technical) 4. [Module Overview (Commercial/Business)](#2-module-overview-commercialbusiness) 5. [Module Overview (End User/Administrator)](#3-module-overview-end-useradministrator) 6. [User Roles & Key Capabilities](#-user-roles--key-capabilities) 7. [Configuration Sections](#4-configuration-sections) 8. [Settings Reference](#5-settings-reference) 9. [Common Scenarios & Examples](#6-common-scenarios--examples) 10. [Model Context Protocol (MCP) AI Integration](#model-context-protocol-mcp-ai-integration) 11. [Limitations & Important Notes](#7-limitations--important-notes) 12. [Troubleshooting Tips](#8-troubleshooting-tips) 13. [Glossary](#9-glossary) --- ## Navigation & Access To access the Firewall Settings module: 1. Log in to the Ring2All Web Portal (`https:///login`) with administrative credentials. 2. In the left navigation sidebar, locate and expand **Admin**. 3. Under the **Firewall** section, click **Firewall Settings** (`/admin/firewall/settings`). 4. Configure the system firewall and intrusion detection parameters. 5. Click **Save** in the bottom action bar to persist your changes to the database and apply runtime daemon configurations. --- ## Screenshots & Visual Interface ### Firewall Settings Configuration Form The Firewall Settings form allows administrators to enable or disable the system firewall (nftables) globally, and configure intrusion detection (Fail2Ban) thresholds including allowed failed attempts, observation time windows, ban durations, and security notification email targets. ![Firewall Settings Form](/screenshots/admin/firewall/firewall-settings-form.png) --- ## 1. Module Overview (Technical) ### What Are Firewall Settings? Firewall Settings is a **security configuration module** that manages the system firewall (nftables) and intrusion detection (Fail2Ban). This module works with related Firewall Services and Firewall Rules modules for complete traffic control. ### Architecture ``` ┌─────────────────────────────────────────────────────────────────┐ │ Firewall System Architecture │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Firewall Settings │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ Global Configuration │ │ │ │ │ │ │ │ Firewall (nftables): │ │ │ │ └─ Enable/Disable │ │ │ │ │ │ │ │ Intrusion Detection (Fail2Ban): │ │ │ │ ├─ Enable/Disable │ │ │ │ ├─ Failed Attempts: 5 │ │ │ │ ├─ Find Time: 10 minutes │ │ │ │ ├─ Ban Duration: 60 minutes │ │ │ │ └─ Notification Email: admin@company.com │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ │ │ ▼ Works with │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ │ │ │ │ Firewall Services Firewall Rules │ │ │ │ ┌────────────────┐ ┌────────────────┐ │ │ │ │ │ HTTP: TCP/80 │ │ Allow HTTP │ │ │ │ │ │ HTTPS: TCP/443 │ → │ Block SSH │ │ │ │ │ │ SIP: UDP/5060 │ │ Accept SIP LAN │ │ │ │ │ │ SSH: TCP/22 │ │ Drop Others │ │ │ │ │ └────────────────┘ └────────────────┘ │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ │ │ ▼ Applied to system │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ Linux Firewall │ │ │ │ │ │ │ │ nftables: │ │ │ │ ├─ Input chain rules │ │ │ │ ├─ Output chain rules │ │ │ │ └─ Forward chain rules │ │ │ │ │ │ │ │ Fail2Ban: │ │ │ │ ├─ SSH jail │ │ │ │ ├─ SIP jail │ │ │ │ └─ Web jail │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` --- ## 2. Module Overview (Commercial/Business) ### Business Value Firewall Settings provides **network security**: | Without Firewall | With Firewall | |------------------|---------------| | Open ports | Controlled access | | No protection | Intrusion detection | | Manual bans | Automatic bans | | Unknown attacks | Email alerts | ### Use Cases 1. **Network Protection** - Block unauthorized access - Allow only needed ports 2. **Intrusion Prevention** - Detect brute force - Auto-ban attackers 3. **SIP Security** - Protect SIP ports - Ban SIP scanners 4. **Compliance** - Audit trail - Security controls ### Feature Highlights | Feature | Benefit | |---------|---------| | **nftables** | Modern Linux firewall | | **Fail2Ban** | Intrusion detection | | **Auto-Ban** | Automatic blocking | | **Email Alerts** | Attack notifications | | **Services** | Reusable port definitions | | **Priority Rules** | Ordered evaluation | --- ## 3. Module Overview (End User/Administrator) ### What Can You Do? - Enable/disable system firewall - Enable/disable intrusion detection - Configure failed attempt limits - Set ban duration - Configure email alerts - Define firewall services - Create firewall rules ### Firewall Settings Interface ``` ┌─────────────────────────────────────────────────────────────────┐ │ Firewall Settings │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Configure system firewall and intrusion detection │ │ │ │ ┌─────────────────────────────────────────────────────────────┐│ │ │ ││ │ │ Enable Firewall: ✓ ││ │ │ Enable or disable the system firewall (nftables) ││ │ │ When enabled, the firewall will enforce all rules ││ │ │ ││ │ └─────────────────────────────────────────────────────────────┘│ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Intrusion Detection (Fail2Ban) │ │ │ │ ┌─────────────────────────────────────────────────────────────┐│ │ │ ││ │ │ Enable Intrusion Detection: ✓ ││ │ │ Enable Fail2Ban to automatically ban IPs after ││ │ │ failed login attempts ││ │ │ ││ │ │ ────────────────────────────────────────────────────────── ││ │ │ ││ │ │ Failed Attempts Allowed: [5 ] ││ │ │ Number of failed attempts before ban (1-20) ││ │ │ ││ │ │ Find Time Window: [10 ] minutes ││ │ │ Time window to count failed attempts ││ │ │ ││ │ │ Ban Duration: [60 ] minutes ││ │ │ Duration that an IP will be banned ││ │ │ ││ │ │ Notification Email: [admin@company.com ] ││ │ │ Email address to receive ban notifications ││ │ │ ││ │ └─────────────────────────────────────────────────────────────┘│ │ │ │ [Save Settings] │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Firewall Services Interface ``` ┌─────────────────────────────────────────────────────────────────┐ │ Firewall Services │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Manage firewall services for nftables (Debian 13) │ │ │ │ [+ Add Service] │ │ │ │ [🔍 Search services...] │ │ │ │ ┌───────────────────────────────────────────────────────────┐ │ │ │ Name │ Protocol │ Port │ Description │ Status│ │ │ ├──────────┼──────────┼───────────┼────────────────┼───────┤ │ │ │ HTTP │ TCP │ 80 │ Web traffic │ ● │ │ │ │ HTTPS │ TCP │ 443 │ Secure web │ ● │ │ │ │ SSH │ TCP │ 22 │ Secure shell │ ● │ │ │ │ SIP │ UDP │ 5060 │ SIP signaling │ ● │ │ │ │ RTP │ UDP │ 16384-32768│ Voice media │ ● │ │ │ └───────────────────────────────────────────────────────────┘ │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Firewall Rules Interface ``` ┌─────────────────────────────────────────────────────────────────┐ │ Firewall Rules │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Manage firewall rules for nftables (Debian 13) │ │ │ │ [+ Add Rule] [Apply Rules] │ │ │ │ [🔍 Search rules...] │ │ │ │ ┌───────────────────────────────────────────────────────────┐ │ │ │ Name │ Action │ Direction│ Service │ Priority│ St │ │ │ ├──────────────┼────────┼──────────┼─────────┼─────────┼────┤ │ │ │ Allow HTTP │ Accept │ Input │ HTTP │ 100 │ ● │ │ │ │ Allow HTTPS │ Accept │ Input │ HTTPS │ 110 │ ● │ │ │ │ Allow SIP │ Accept │ Input │ SIP │ 200 │ ● │ │ │ │ Allow RTP │ Accept │ Input │ RTP │ 210 │ ● │ │ │ │ Block SSH Ext│ Drop │ Input │ SSH │ 300 │ ● │ │ │ └───────────────────────────────────────────────────────────┘ │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Add/Edit Rule Modal ``` ┌─────────────────────────────────────────────────────────────────┐ │ Add Firewall Rule │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Rule Name: [Allow SIP from LAN ] │ │ Descriptive name for the rule │ │ │ │ Action: [Accept ▼] │ │ Accept | Drop | Reject │ │ │ │ Direction: [Input ▼] │ │ Input | Output | Forward │ │ │ │ Service: [SIP ▼] │ │ Select service (required) │ │ │ │ Priority: [200 ] │ │ Lower numbers evaluated first (0-9999) │ │ │ │ Source Address: [192.168.1.0/24 ] │ │ Optional: IP or CIDR │ │ │ │ Destination Address: [ ] │ │ Optional: IP or CIDR │ │ │ │ Interface: [eth0 ] │ │ Optional: Network interface │ │ │ │ Enabled: ✓ │ │ │ │ [Save] [Cancel] │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Quick Tips > [!TIP] > **Apply Rules**: Click "Apply Rules" after changes. > [!TIP] > **Priority**: Lower numbers = higher priority. > [!WARNING] > **Don't Lock Yourself Out**: Always allow SSH from your IP first! --- ## 🎯 User Roles & Key Capabilities The Firewall Settings module aligns system perimeter security and intrusion prevention authority across key administrative roles: | User Role | Key Permissions & Responsibilities | Common Tasks & Workflows | |:---|:---|:---| | **Platform Security Officer / SuperAdmin** | Master control over host packet filtering (`nftables`) and Fail2Ban intrusion detection services. | Toggle global firewall state, adjust failed attempt thresholds, set ban and find time durations, establish root notification email addresses. | | **Tenant Administrator** | Read-only inspection of active firewall state and intrusion detection parameters for organizational awareness. | Inspect system protection status, verify that security policies meet client contractual SLAs, review security incident escalations. | | **NOC / Security Operations Engineer** | Real-time intrusion monitoring, jail status verification, and emergency unban execution. | Verify Fail2Ban jail states (`fail2ban-client status`), investigate anomalous IP lockouts, unban trusted IP addresses following password recovery, analyze attack telemetry. | | **Compliance & Security Auditor** | Independent verification of intrusion prevention thresholds against regulatory standards (SOC 2, ISO 27001, PCI-DSS). | Audit failed authentication limits (max 5 attempts), confirm automated logging of ban actions, verify alert delivery to designated security mailboxes. | --- ## 4. Configuration Sections ### Firewall Settings | Field | Description | |-------|-------------| | **Enable Firewall** | nftables on/off | | **Enable Intrusion Detection** | Fail2Ban on/off | | **Failed Attempts** | Max attempts (1-20) | | **Find Time** | Count window (minutes) | | **Ban Duration** | Ban time (minutes) | | **Notification Email** | Alert recipient | ### Firewall Services | Field | Description | |-------|-------------| | **Name** | Service identifier | | **Protocol** | TCP, UDP, ICMP, All | | **Port** | Port or range (e.g., 8000-8010) | | **Description** | Optional notes | | **Enabled** | Active/Inactive | ### Firewall Rules | Field | Description | |-------|-------------| | **Name** | Rule identifier | | **Action** | Accept, Drop, Reject | | **Direction** | Input, Output, Forward | | **Service** | Associated service | | **Priority** | Order (0-9999) | | **Source Address** | Source IP/CIDR | | **Destination Address** | Dest IP/CIDR | | **Interface** | Network interface | | **Enabled** | Active/Inactive | --- ## 5. Settings Reference ### Rule Actions | Action | Behavior | Use Case | |--------|----------|----------| | **Accept** | Allow traffic | Legitimate traffic | | **Drop** | Silent block | Stealth blocking | | **Reject** | Block with response | Inform sender | ### Rule Directions | Direction | Description | |-----------|-------------| | **Input** | Traffic TO the server | | **Output** | Traffic FROM the server | | **Forward** | Routed traffic | ### Common Protocols | Protocol | Use | |----------|-----| | TCP | HTTP, HTTPS, SSH, SIP-TCP | | UDP | SIP, RTP, DNS | | ICMP | Ping | | All | Any protocol | ### Fail2Ban Recommendations | Setting | Default | Aggressive | Permissive | |---------|---------|------------|------------| | Failed Attempts | 5 | 3 | 10 | | Find Time | 10 min | 5 min | 30 min | | Ban Duration | 60 min | 1440 min (24h) | 30 min | --- ## 6. Common Scenarios & Examples ### Scenario 1: Enable Firewall & Detection 1. Enable Firewall = ✓ 2. Enable Intrusion Detection = ✓ 3. Failed Attempts = 5 4. Find Time = 10 minutes 5. Ban Duration = 60 minutes 6. Email = admin@company.com 7. Save ### Scenario 2: Create SIP Service 1. Add Service 2. Name = "SIP" 3. Protocol = UDP 4. Port = 5060 5. Description = "SIP signaling" 6. Enable = ✓ 7. Save ### Scenario 3: Allow SIP from LAN Only 1. Add Rule 2. Name = "Allow SIP LAN" 3. Action = Accept 4. Direction = Input 5. Service = SIP 6. Priority = 200 7. Source = 192.168.1.0/24 8. Enable = ✓ 9. Save 10. Apply Rules ### Scenario 4: Block External SSH 1. First: Create "Allow SSH from Admin IP" rule (Priority 90) 2. Add Rule 3. Name = "Block SSH External" 4. Action = Drop 5. Direction = Input 6. Service = SSH 7. Priority = 100 8. Enable = ✓ 9. Save 10. Apply Rules --- ## 7. Limitations & Important Notes ### Technical Notes > [!NOTE] > **Apply Required**: Rules don't take effect until applied. > [!NOTE] > **Priority Order**: Lower number = evaluated first. > [!CAUTION] > **SSH Access**: Always allow your IP before blocking! ### Best Practices 1. **SSH First**: Always allow admin SSH 2. **Specific to General**: Specific rules before broad rules 3. **Test Changes**: Verify access after changes 4. **Enable Fail2Ban**: Protect against brute force 5. **Monitor Bans**: Check for false positives ### Common Services to Allow | Service | Port | Notes | |---------|------|-------| | HTTP | 80 | Web (redirect to HTTPS) | | HTTPS | 443 | Secure web | | SIP UDP | 5060 | SIP signaling | | SIP TLS | 5061 | Secure SIP | | RTP | 16384-32768 | Voice media | | SSH | 22 | Remote admin (restrict!) | --- ## Model Context Protocol (MCP) AI Integration The Firewall Settings module integrates directly with the **Ring2All Platform Copilot MCP Server**, enabling automated perimeter status verification, intrusion threshold inspection, and operational diagnostics: ### 🛠️ Available MCP Tools | Tool Name | Operation | Access Level | Description | Key Parameters | |:---|:---|:---|:---|:---| | `get_firewall_settings` | Read | SuperAdmin / Auditor | Retrieves system-wide PBX firewall state (nftables enabled/disabled), Fail2Ban intrusion detection configuration, failed attempt thresholds, find time, ban time, and alert notification email. | None | | `list_firewall_rules` | Read | SuperAdmin / Auditor | Inspects active network packet filtering rules (port, protocol, disposition, source CIDR). | `search` (string, optional) | | `get_voipbl_status` | Read | SuperAdmin / Auditor | Returns status of APIBAN/VoIPBL public blacklist threat intelligence feed. | None | ### 📋 JSON Tool Schemas & Sample Executions #### `get_firewall_settings` ```json { "name": "get_firewall_settings", "arguments": {} } ``` *Sample Successful Response:* ```json { "success": true, "data": { "firewallEnabled": true, "intrusionDetectionEnabled": true, "failedAttemptsAllowed": 5, "findTime": 600, "banTime": 3600, "notificationEmail": "security-alerts@carrier.com", "updatedAt": "2026-08-14T18:22:10Z" } } ``` ### 💬 Natural Language Prompt Examples #### English Prompts - *"Check if the PBX firewall and intrusion detection systems are currently enabled."* - *"What are the current Fail2Ban thresholds for failed login attempts and ban duration?"* - *"Verify which email address is receiving firewall security incident alerts."* - *"Show me the full security perimeter posture including firewall status and active rules."* #### Ejemplos en Español (Spanish Prompts) - *"Verifica si el firewall y el sistema de detección de intrusos (Fail2Ban) están activos en la centralita."* - *"¿Cuáles son los umbrales configurados para intentos fallidos y tiempo de bloqueo (ban time)?"* - *"Comprueba qué correo electrónico tiene asignadas las alertas de seguridad del firewall."* - *"Muéstrame el estado general del perímetro de seguridad, incluyendo el firewall y las reglas activas."* ### 🛡️ Enterprise Safeguards & Best Practices 1. **Administrative Lockout Safeguard**: Changing firewall parameters via MCP requires explicit administrative credentials and validates that management ports (SSH 22, HTTPS 443) remain reachable. 2. **Exponential Backoff on Intrusion**: Failed login attempts increment counters in Linux shared memory (`fail2ban`), locking malicious origins across kernel packet tables. 3. **Audit Trail Logging**: All changes to firewall settings trigger instantaneous entries in the immutable system audit log (`public.audit_logs`). --- ## 8. Troubleshooting Tips ### Common Issues | Symptom | Possible Cause | Solution | |---------|---------------|----------| | Can't connect | Blocked by firewall | Check rules | | False bans | Fail2Ban too strict | Adjust settings | | Rules not working | Not applied | Click Apply Rules | | Locked out | SSH blocked | Console access | ### Check Firewall Status ```bash # Check nftables nft list ruleset # Check Fail2Ban status fail2ban-client status # Check specific jail fail2ban-client status sshd # Unban an IP fail2ban-client set sshd unbanip 192.168.1.100 ``` ### Check Bans ```bash # View banned IPs fail2ban-client status sshd # Check ban log tail -f /var/log/fail2ban.log # View all bans iptables -L -n | grep -i ban ``` --- ## 9. Glossary | Term | Definition | |------|------------| | **nftables** | Linux firewall framework | | **Fail2Ban** | Intrusion detection system | | **Jail** | Fail2Ban protection scope | | **CIDR** | IP range notation | | **Chain** | Rule processing group | | **Input Chain** | Incoming traffic rules | --- *Documentation last updated: January 2026*