--- title: "Firewall Services & Port Definitions" description: "Documentation for Firewall Services" --- ## Table of Contents 1. [Overview & Service Architecture](#1-overview--service-architecture) 2. [Business & Operational Significance](#2-business--operational-significance) 3. [🎯 User Roles & Key Capabilities](#3--user-roles--key-capabilities) 4. [Visual Interface & Layout](#4-visual-interface--layout) 5. [Field Reference & Pre-Configured Services Catalog](#5-field-reference--pre-configured-services-catalog) 6. [Service Abstraction & nftables Mapping](#6-service-abstraction--nftables-mapping) 7. [Operational Best Practices & Security Hardening](#7-operational-best-practices--security-hardening) 8. [Verification & Diagnostics](#8-verification--diagnostics) 9. [Model Context Protocol (MCP) AI Integration](#9-model-context-protocol-mcp-ai-integration) 10. [Glossary](#10-glossary) --- ## 1. Overview & Service Architecture In **Ring2All SBC**, the **Firewall Services** module provides an object-oriented network service abstraction layer. Rather than requiring network engineers to memorize and enter raw port numbers and protocol numbers when writing firewall rules, services define standardized, named entities (e.g., *SIP External (UDP)*, *RTP Media*, *WireGuard VPN*, *SSH*) that encapsulate transport protocols, port assignments, and port ranges. ``` β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ FIREWALL SERVICES CATALOG β”‚ β”‚ (Stored in sbc_admin.firewall_services) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β–Ό β–Ό β–Ό β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ SIP SIGNALING β”‚ β”‚ MEDIA & VPN β”‚ β”‚ ADMINISTRATIVE β”‚ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”‚ β€’ SIP UDP 5060 β”‚ β”‚ β€’ RTP Media β”‚ β”‚ β€’ SSH (22) β”‚ β”‚ β€’ SIP TCP 5060 β”‚ β”‚ (10000-20000)β”‚ β”‚ β€’ HTTPS (443) β”‚ β”‚ β€’ SIP TLS 5061 β”‚ β”‚ β€’ WireGuard β”‚ β”‚ β€’ SBC Admin APIβ”‚ β”‚ β€’ Public 5080 β”‚ β”‚ (UDP 51820) β”‚ β”‚ β€’ Postgres 5432β”‚ β”‚ β€’ Public TLS β”‚ β”‚ β€’ ICMP Echo β”‚ β”‚ β€’ Prometheus β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β–Ό β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ FIREWALL RULES ABSTRACTION LAYER β”‚ β”‚ (Rules reference named services rather than literal ports) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ ``` These service definitions are referenced directly by the **Firewall Rules** engine, ensuring configuration consistency, simplifying security audits, and preventing port collision mistakes across cluster instances. --- ## 2. Business & Operational Significance * **Error-Proof Rule Authoring**: Eliminates costly typos in critical telecom ports (e.g., entering 5006 instead of 5060) that can silently disrupt voice traffic or leave management ports exposed. * **Standardized Telecom Profile**: Pre-configures carrier-grade port standards out of the box, including Kamailio default signaling ports, RTPEngine RTP proxy ranges, and Prometheus telemetry ports. * **Rapid Port Range Updates**: Changing a service definition (e.g., expanding the RTP media range from `10000–20000` to `10000–30000`) automatically updates all associated firewall rules upon rule re-application. * **Audit & Compliance Readability**: Security auditors can immediately inspect named service definitions rather than deciphering raw iptables port syntax in obscure script files. --- ## 3. 🎯 User Roles & Key Capabilities | Role | Primary Use Case | Key Capabilities | | :--- | :--- | :--- | | **Network Infrastructure Engineer** | Service Definition & Port Allocation | Define custom telephony services, allocate non-standard SIP/TLS listening ports, and configure RTP media boundaries. | | **SBC Administrator** | Service Catalog Maintenance | Enable or disable specific service definitions, update service descriptions, and verify active port bindings. | | **SecOps Auditor** | Attack Surface Review | Review all defined listening ports, ensure non-essential ports are disabled, and verify internal-only restrictions. | | **DevOps Automation Lead** | Infrastructure As Code Integration | Export service definitions to declarative deployment manifests and verify cluster uniformity. | | **AI Network Systems Agent / NOC Copilot** | Automated Service Catalog Inspection | Query defined firewall services, inspect port assignments and protocols, and verify telemetry or media port alignment via MCP tools. | --- ## 4. Visual Interface & Layout The Firewall Services interface provides a comprehensive DataGrid view displaying all defined services, transport protocols, port assignments, descriptive roles, and operational statuses. ### 4.1 Firewall Services List View Displays pre-configured and custom system services, port ranges, and status toggles. ![Firewall Services List View](/screenshots/sbc/admin/firewall-services/firewall-services-list.png) --- ## 5. Field Reference & Pre-Configured Services Catalog ### 5.1 Service Data Fields | Field | Type | Description | | :--- | :--- | :--- | | **Name** | String | Human-readable service identifier (e.g., `SIP Internal (UDP)`, `RTP Media`). | | **Protocol** | Badge | Transport layer protocol: `TCP`, `UDP`, or `ICMP`. | | **Port** | String / Range | Specific port number (e.g., `5060`, `443`), port range (`10000–20000`), or `-1` for protocol-wide filtering (ICMP). | | **Description** | String | Detailed explanation of the service's role within the SBC architecture. | | **Status** | Status Dot | Active (Green) or Disabled (Grey) status indicator. | | **Actions** | Action Icons | Edit service parameters or delete custom service objects. | ### 5.2 Pre-Configured Services Catalog | Service Name | Protocol | Port / Range | Primary Telecom Function | | :--- | :--- | :--- | :--- | | **HTTP Redirect** | `TCP` | `80` | Automatic redirect of plain HTTP requests to HTTPS. | | **HTTPS** | `TCP` | `443` | Secure Web UI and REST API administrative interface. | | **ICMP Ping** | `ICMP` | `-1` | Network diagnostics and latency monitoring via ICMP Echo Request. | | **PostgreSQL** | `TCP` | `5432` | Relational database access (restricted strictly to internal cluster networks). | | **Prometheus Metrics**| `TCP` | `9100` | Node Exporter and system performance metric scraping. | | **RTP Media** | `UDP` | `10000–20000` | Real-time audio and video streams relayed by RTPEngine. | | **SBC Admin API** | `TCP` | `3000` | Node.js Fastify backend API daemon. | | **SIP External (TCP)**| `TCP` | `5080` | Public-facing SIP carrier signaling over TCP. | | **SIP External (UDP)**| `UDP` | `5080` | Public-facing SIP carrier signaling over UDP. | | **SIP Internal (TCP)**| `TCP` | `5060` | Core PBX and internal extension signaling over TCP. | | **SIP Internal (UDP)**| `UDP` | `5060` | Core PBX and internal extension signaling over UDP. | | **SIP TLS External** | `TCP` | `5081` | Encrypted public-facing SIP signaling via TLS. | | **SIP TLS Internal** | `TCP` | `5061` | Encrypted core PBX and private trunk signaling via TLS. | | **SSH** | `TCP` | `22` | Secure Shell for host-level remote system administration. | | **WireGuard VPN** | `UDP` | `51820` | Secure encrypted tunnel interface for inter-node communication. | --- ## 6. Service Abstraction & nftables Mapping Services defined in `sbc_admin.firewall_services` translate dynamically into Linux `nftables` syntax when firewall rules are applied: ``` # Single port translation service: "SIP Internal (UDP)" (UDP, 5060) nftables: udp dport 5060 accept # Port range translation service: "RTP Media" (UDP, 10000-20000) nftables: udp dport 10000-20000 accept # Protocol without port (ICMP) service: "ICMP Ping" (ICMP, -1) nftables: ip protocol icmp accept ``` --- ## 7. Operational Best Practices & Security Hardening * **Isolate Database & Metrics**: Ensure services such as `PostgreSQL` (5432) and `SBC Admin API` (3000) are never exposed to public source addresses. Always bind rules referencing these services to private management subnets (e.g., `10.0.0.0/8` or `192.168.10.0/24`). * **Match RTP Ranges with RTPEngine**: Always verify that the port range specified in the `RTP Media` service (`10000-20000`) exactly matches the `port-min` and `port-max` parameters configured in `/etc/rtpengine/rtpengine.conf`. * **Separate External from Internal SIP**: Keep internal PBX signaling (5060/5061) separated from public carrier signaling (5080/5081) to maintain clean architectural boundary isolation. * **Minimize Open Administrative Services**: Disable services like `Prometheus Metrics` or `HTTP Redirect` if external scraping or plaintext redirects are not required by your infrastructure policy. --- ## 8. Verification & Diagnostics ### 8.1 Inspect Services in Database Query all active services and their allocated ports: ```bash sudo -u postgres psql -d sbc_admin -c " SELECT name, protocol, port, description, is_active FROM firewall_services ORDER BY id; " ``` ### 8.2 Verify Listening Sockets on Host Verify that the host kernel is actively listening on the defined service ports: ```bash ss -tulwn | grep -E ':22|:80|:443|:3000|:5060|:5080|:5061|:5081|:51820' ``` --- ## 9. Model Context Protocol (MCP) AI Integration The **Ring2All SBC MCP Server** exposes dedicated service catalog introspection tools under the `firewall_services` tool category. Autonomous infrastructure agents and the Ring2All SBC NOC Copilot can query available service templates, inspect allocated port boundaries, and ensure compliance before writing or adjusting packet filtering policies. ### 9.1 Available MCP Tools | Tool Name | Operation Type | Risk Level | Description | | :--- | :--- | :--- | :--- | | `list_sbc_firewall_services` | Read-only | `read_only` | Lists all defined network service objects in the SBC catalog, including protocols, port numbers/ranges, and system flags. | | `get_sbc_firewall_service` | Read-only | `read_only` | Retrieves full technical details for a specific firewall service by numerical ID or canonical name. | ### 9.2 Tool Schemas & Parameter Definitions #### `list_sbc_firewall_services` * **Description**: List all defined firewall services (ports and protocols) in Ring2All SBC. * **Input Schema**: ```json { "type": "object", "properties": {} } ``` #### `get_sbc_firewall_service` * **Description**: Retrieve detailed port and protocol specifications for a specific firewall service. * **Input Schema**: ```json { "type": "object", "properties": { "id": { "type": "number", "description": "Numerical primary key ID of the firewall service" }, "name": { "type": "string", "description": "Canonical name of the service (e.g., 'RTP Media', 'SIP Internal (UDP)')" } } } ``` ### 9.3 Sample Tool Execution Payloads #### Example 1: Listing All Pre-Configured Telephony Services **Request Payload:** ```json { "tool": "list_sbc_firewall_services", "parameters": {} } ``` **Response Payload:** ```json { "success": true, "data": { "total": 15, "services": [ { "id": 1, "name": "SIP Internal (UDP)", "protocol": "UDP", "port": "5060", "description": "Core PBX and internal extension signaling over UDP", "enabled": true, "isSystem": true }, { "id": 6, "name": "RTP Media", "protocol": "UDP", "port": "10000-20000", "description": "Real-time audio and video streams relayed by RTPEngine", "enabled": true, "isSystem": true }, { "id": 14, "name": "WireGuard VPN", "protocol": "UDP", "port": "51820", "description": "Secure encrypted tunnel interface for inter-node communication", "enabled": true, "isSystem": true } ] } } ``` #### Example 2: Inspecting Specific RTP Media Service **Request Payload:** ```json { "tool": "get_sbc_firewall_service", "parameters": { "name": "RTP Media" } } ``` **Response Payload:** ```json { "success": true, "data": { "service": { "id": 6, "name": "RTP Media", "protocol": "UDP", "port": "10000-20000", "description": "Real-time audio and video streams relayed by RTPEngine", "enabled": true, "isSystem": true } } } ``` ### 9.4 Bilingual Natural Language Copilot Prompts #### English Prompts * *"List all defined firewall services to see what ports are allocated for SIP and RTP."* β†’ Agent calls `list_sbc_firewall_services()`. * *"What is the configured port range for the 'RTP Media' firewall service?"* β†’ Agent calls `get_sbc_firewall_service({"name": "RTP Media"})`. #### Spanish Prompts (EspaΓ±ol) * *"Lista todos los servicios del firewall para ver quΓ© puertos estΓ‘n asignados a SIP y RTP."* β†’ Agente invoca `list_sbc_firewall_services()`. * *"ΒΏCuΓ‘l es el rango de puertos configurado para el servicio de firewall 'RTP Media'?"* β†’ Agente invoca `get_sbc_firewall_service({"name": "RTP Media"})`. ### 9.5 Enterprise Security & Execution Safeguards 1. **System Service Protection**: System services (`isSystem: true`) are flagged as immutable templates to prevent accidental disruption of core SBC signaling or SSH administrative channels. 2. **Read-Only Discovery**: Both `list_sbc_firewall_services` and `get_sbc_firewall_service` are safe, non-mutating query tools that can be executed freely across monitoring and administrative roles. 3. **Lookup Resiliency**: Lookups support either numerical ID or case-insensitive name matching, returning structured error diagnostics if an invalid service reference is provided. --- ## 10. Glossary * **Port Range**: A contiguous sequence of port numbers (e.g., 10000 through 20000) reserved for dynamic media streams (RTP/RTCP). * **WireGuard**: Modern, high-performance VPN protocol operating over UDP, used in Ring2All SBC to establish secure site-to-site tunnels with core PBX clusters. * **RTPEngine**: High-throughput media relay proxy used by Kamailio to bridge and transcode RTP packets between networks. * **ICMP**: Internet Control Message Protocol used by network devices to send error messages and operational information like ping responses. * **Model Context Protocol (MCP)**: An open standard enabling autonomous AI assistants and NOC copilots to securely discover and invoke SBC operational tools.