Skip to content

Firewall Services & Port Definitions

10 min readUpdated: Sep 26, 2026
View as Markdown
  1. Overview & Service Architecture
  2. Business & Operational Significance
  3. 🎯 User Roles & Key Capabilities
  4. Visual Interface & Layout
  5. Field Reference & Pre-Configured Services Catalog
  6. Service Abstraction & nftables Mapping
  7. Operational Best Practices & Security Hardening
  8. Verification & Diagnostics
  9. Model Context Protocol (MCP) AI Integration
  10. Glossary

In Ring2All SBC, the Firewall Services module provides an object-oriented network service abstraction layer. Rather than requiring network engineers to memorize and enter raw port numbers and protocol numbers when writing firewall rules, services define standardized, named entities (e.g., SIP External (UDP), RTP Media, WireGuard VPN, SSH) that encapsulate transport protocols, port assignments, and port ranges.

┌─────────────────────────────────────────────────────────────┐
│ FIREWALL SERVICES CATALOG │
│ (Stored in sbc_admin.firewall_services) │
└──────────────────────────────┬──────────────────────────────┘
│
┌──────────────────────────┼──────────────────────────┐
▼ ▼ ▼
┌────────────────┐ ┌────────────────┐ ┌────────────────┐
│ SIP SIGNALING │ │ MEDIA & VPN │ │ ADMINISTRATIVE │
├────────────────┤ ├────────────────┤ ├────────────────┤
│ • SIP UDP 5060 │ │ • RTP Media │ │ • SSH (22) │
│ • SIP TCP 5060 │ │ (10000-20000)│ │ • HTTPS (443) │
│ • SIP TLS 5061 │ │ • WireGuard │ │ • SBC Admin API│
│ • Public 5080 │ │ (UDP 51820) │ │ • Postgres 5432│
│ • Public TLS │ │ • ICMP Echo │ │ • Prometheus │
└────────────────┘ └────────────────┘ └────────────────┘
│ │ │
└──────────────────────────┼──────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ FIREWALL RULES ABSTRACTION LAYER │
│ (Rules reference named services rather than literal ports) │
└─────────────────────────────────────────────────────────────┘

These service definitions are referenced directly by the Firewall Rules engine, ensuring configuration consistency, simplifying security audits, and preventing port collision mistakes across cluster instances.


  • Error-Proof Rule Authoring: Eliminates costly typos in critical telecom ports (e.g., entering 5006 instead of 5060) that can silently disrupt voice traffic or leave management ports exposed.
  • Standardized Telecom Profile: Pre-configures carrier-grade port standards out of the box, including Kamailio default signaling ports, RTPEngine RTP proxy ranges, and Prometheus telemetry ports.
  • Rapid Port Range Updates: Changing a service definition (e.g., expanding the RTP media range from 10000–20000 to 10000–30000) automatically updates all associated firewall rules upon rule re-application.
  • Audit & Compliance Readability: Security auditors can immediately inspect named service definitions rather than deciphering raw iptables port syntax in obscure script files.

Role Primary Use Case Key Capabilities
Network Infrastructure Engineer Service Definition & Port Allocation Define custom telephony services, allocate non-standard SIP/TLS listening ports, and configure RTP media boundaries.
SBC Administrator Service Catalog Maintenance Enable or disable specific service definitions, update service descriptions, and verify active port bindings.
SecOps Auditor Attack Surface Review Review all defined listening ports, ensure non-essential ports are disabled, and verify internal-only restrictions.
DevOps Automation Lead Infrastructure As Code Integration Export service definitions to declarative deployment manifests and verify cluster uniformity.
AI Network Systems Agent / NOC Copilot Automated Service Catalog Inspection Query defined firewall services, inspect port assignments and protocols, and verify telemetry or media port alignment via MCP tools.

The Firewall Services interface provides a comprehensive DataGrid view displaying all defined services, transport protocols, port assignments, descriptive roles, and operational statuses.

Displays pre-configured and custom system services, port ranges, and status toggles.

Firewall Services List View


5. Field Reference & Pre-Configured Services Catalog

Section titled “5. Field Reference & Pre-Configured Services Catalog”
Field Type Description
Name String Human-readable service identifier (e.g., SIP Internal (UDP), RTP Media).
Protocol Badge Transport layer protocol: TCP, UDP, or ICMP.
Port String / Range Specific port number (e.g., 5060, 443), port range (10000–20000), or -1 for protocol-wide filtering (ICMP).
Description String Detailed explanation of the service’s role within the SBC architecture.
Status Status Dot Active (Green) or Disabled (Grey) status indicator.
Actions Action Icons Edit service parameters or delete custom service objects.
Service Name Protocol Port / Range Primary Telecom Function
HTTP Redirect TCP 80 Automatic redirect of plain HTTP requests to HTTPS.
HTTPS TCP 443 Secure Web UI and REST API administrative interface.
ICMP Ping ICMP -1 Network diagnostics and latency monitoring via ICMP Echo Request.
PostgreSQL TCP 5432 Relational database access (restricted strictly to internal cluster networks).
Prometheus Metrics TCP 9100 Node Exporter and system performance metric scraping.
RTP Media UDP 10000–20000 Real-time audio and video streams relayed by RTPEngine.
SBC Admin API TCP 3000 Node.js Fastify backend API daemon.
SIP External (TCP) TCP 5080 Public-facing SIP carrier signaling over TCP.
SIP External (UDP) UDP 5080 Public-facing SIP carrier signaling over UDP.
SIP Internal (TCP) TCP 5060 Core PBX and internal extension signaling over TCP.
SIP Internal (UDP) UDP 5060 Core PBX and internal extension signaling over UDP.
SIP TLS External TCP 5081 Encrypted public-facing SIP signaling via TLS.
SIP TLS Internal TCP 5061 Encrypted core PBX and private trunk signaling via TLS.
SSH TCP 22 Secure Shell for host-level remote system administration.
WireGuard VPN UDP 51820 Secure encrypted tunnel interface for inter-node communication.

Services defined in sbc_admin.firewall_services translate dynamically into Linux nftables syntax when firewall rules are applied:

# Single port translation
service: "SIP Internal (UDP)" (UDP, 5060)
nftables: udp dport 5060 accept
# Port range translation
service: "RTP Media" (UDP, 10000-20000)
nftables: udp dport 10000-20000 accept
# Protocol without port (ICMP)
service: "ICMP Ping" (ICMP, -1)
nftables: ip protocol icmp accept

7. Operational Best Practices & Security Hardening

Section titled “7. Operational Best Practices & Security Hardening”
  • Isolate Database & Metrics: Ensure services such as PostgreSQL (5432) and SBC Admin API (3000) are never exposed to public source addresses. Always bind rules referencing these services to private management subnets (e.g., 10.0.0.0/8 or 192.168.10.0/24).
  • Match RTP Ranges with RTPEngine: Always verify that the port range specified in the RTP Media service (10000-20000) exactly matches the port-min and port-max parameters configured in /etc/rtpengine/rtpengine.conf.
  • Separate External from Internal SIP: Keep internal PBX signaling (5060/5061) separated from public carrier signaling (5080/5081) to maintain clean architectural boundary isolation.
  • Minimize Open Administrative Services: Disable services like Prometheus Metrics or HTTP Redirect if external scraping or plaintext redirects are not required by your infrastructure policy.

Query all active services and their allocated ports:

Terminal window
sudo -u postgres psql -d sbc_admin -c "
SELECT name, protocol, port, description, is_active
FROM firewall_services
ORDER BY id;
"

Verify that the host kernel is actively listening on the defined service ports:

Terminal window
ss -tulwn | grep -E ':22|:80|:443|:3000|:5060|:5080|:5061|:5081|:51820'

9. Model Context Protocol (MCP) AI Integration

Section titled “9. Model Context Protocol (MCP) AI Integration”

The Ring2All SBC MCP Server exposes dedicated service catalog introspection tools under the firewall_services tool category. Autonomous infrastructure agents and the Ring2All SBC NOC Copilot can query available service templates, inspect allocated port boundaries, and ensure compliance before writing or adjusting packet filtering policies.

Tool Name Operation Type Risk Level Description
list_sbc_firewall_services Read-only read_only Lists all defined network service objects in the SBC catalog, including protocols, port numbers/ranges, and system flags.
get_sbc_firewall_service Read-only read_only Retrieves full technical details for a specific firewall service by numerical ID or canonical name.
  • Description: List all defined firewall services (ports and protocols) in Ring2All SBC.
  • Input Schema:
{
"type": "object",
"properties": {}
}
  • Description: Retrieve detailed port and protocol specifications for a specific firewall service.
  • Input Schema:
{
"type": "object",
"properties": {
"id": {
"type": "number",
"description": "Numerical primary key ID of the firewall service"
},
"name": {
"type": "string",
"description": "Canonical name of the service (e.g., 'RTP Media', 'SIP Internal (UDP)')"
}
}
}

Example 1: Listing All Pre-Configured Telephony Services

Section titled “Example 1: Listing All Pre-Configured Telephony Services”

Request Payload:

{
"tool": "list_sbc_firewall_services",
"parameters": {}
}

Response Payload:

{
"success": true,
"data": {
"total": 15,
"services": [
{
"id": 1,
"name": "SIP Internal (UDP)",
"protocol": "UDP",
"port": "5060",
"description": "Core PBX and internal extension signaling over UDP",
"enabled": true,
"isSystem": true
},
{
"id": 6,
"name": "RTP Media",
"protocol": "UDP",
"port": "10000-20000",
"description": "Real-time audio and video streams relayed by RTPEngine",
"enabled": true,
"isSystem": true
},
{
"id": 14,
"name": "WireGuard VPN",
"protocol": "UDP",
"port": "51820",
"description": "Secure encrypted tunnel interface for inter-node communication",
"enabled": true,
"isSystem": true
}
]
}
}

Example 2: Inspecting Specific RTP Media Service

Section titled “Example 2: Inspecting Specific RTP Media Service”

Request Payload:

{
"tool": "get_sbc_firewall_service",
"parameters": {
"name": "RTP Media"
}
}

Response Payload:

{
"success": true,
"data": {
"service": {
"id": 6,
"name": "RTP Media",
"protocol": "UDP",
"port": "10000-20000",
"description": "Real-time audio and video streams relayed by RTPEngine",
"enabled": true,
"isSystem": true
}
}
}

9.4 Bilingual Natural Language Copilot Prompts

Section titled “9.4 Bilingual Natural Language Copilot Prompts”
  • “List all defined firewall services to see what ports are allocated for SIP and RTP.” → Agent calls list_sbc_firewall_services().
  • “What is the configured port range for the ‘RTP Media’ firewall service?” → Agent calls get_sbc_firewall_service({"name": "RTP Media"}).
  • “Lista todos los servicios del firewall para ver qué puertos están asignados a SIP y RTP.” → Agente invoca list_sbc_firewall_services().
  • “¿Cuál es el rango de puertos configurado para el servicio de firewall ‘RTP Media’?” → Agente invoca get_sbc_firewall_service({"name": "RTP Media"}).

9.5 Enterprise Security & Execution Safeguards

Section titled “9.5 Enterprise Security & Execution Safeguards”
  1. System Service Protection: System services (isSystem: true) are flagged as immutable templates to prevent accidental disruption of core SBC signaling or SSH administrative channels.
  2. Read-Only Discovery: Both list_sbc_firewall_services and get_sbc_firewall_service are safe, non-mutating query tools that can be executed freely across monitoring and administrative roles.
  3. Lookup Resiliency: Lookups support either numerical ID or case-insensitive name matching, returning structured error diagnostics if an invalid service reference is provided.

  • Port Range: A contiguous sequence of port numbers (e.g., 10000 through 20000) reserved for dynamic media streams (RTP/RTCP).
  • WireGuard: Modern, high-performance VPN protocol operating over UDP, used in Ring2All SBC to establish secure site-to-site tunnels with core PBX clusters.
  • RTPEngine: High-throughput media relay proxy used by Kamailio to bridge and transcode RTP packets between networks.
  • ICMP: Internet Control Message Protocol used by network devices to send error messages and operational information like ping responses.
  • Model Context Protocol (MCP): An open standard enabling autonomous AI assistants and NOC copilots to securely discover and invoke SBC operational tools.