Firewall Services & Port Definitions
Table of Contents
Section titled “Table of Contents”- Overview & Service Architecture
- Business & Operational Significance
- 🎯 User Roles & Key Capabilities
- Visual Interface & Layout
- Field Reference & Pre-Configured Services Catalog
- Service Abstraction & nftables Mapping
- Operational Best Practices & Security Hardening
- Verification & Diagnostics
- Model Context Protocol (MCP) AI Integration
- Glossary
1. Overview & Service Architecture
Section titled “1. Overview & Service Architecture”In Ring2All SBC, the Firewall Services module provides an object-oriented network service abstraction layer. Rather than requiring network engineers to memorize and enter raw port numbers and protocol numbers when writing firewall rules, services define standardized, named entities (e.g., SIP External (UDP), RTP Media, WireGuard VPN, SSH) that encapsulate transport protocols, port assignments, and port ranges.
┌─────────────────────────────────────────────────────────────┐ │ FIREWALL SERVICES CATALOG │ │ (Stored in sbc_admin.firewall_services) │ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────┼──────────────────────────┐ ▼ ▼ ▼ ┌────────────────┐ ┌────────────────┐ ┌────────────────┐ │ SIP SIGNALING │ │ MEDIA & VPN │ │ ADMINISTRATIVE │ ├────────────────┤ ├────────────────┤ ├────────────────┤ │ • SIP UDP 5060 │ │ • RTP Media │ │ • SSH (22) │ │ • SIP TCP 5060 │ │ (10000-20000)│ │ • HTTPS (443) │ │ • SIP TLS 5061 │ │ • WireGuard │ │ • SBC Admin API│ │ • Public 5080 │ │ (UDP 51820) │ │ • Postgres 5432│ │ • Public TLS │ │ • ICMP Echo │ │ • Prometheus │ └────────────────┘ └────────────────┘ └────────────────┘ │ │ │ └──────────────────────────┼──────────────────────────┘ │ ▼ ┌─────────────────────────────────────────────────────────────┐ │ FIREWALL RULES ABSTRACTION LAYER │ │ (Rules reference named services rather than literal ports) │ └─────────────────────────────────────────────────────────────┘These service definitions are referenced directly by the Firewall Rules engine, ensuring configuration consistency, simplifying security audits, and preventing port collision mistakes across cluster instances.
2. Business & Operational Significance
Section titled “2. Business & Operational Significance”- Error-Proof Rule Authoring: Eliminates costly typos in critical telecom ports (e.g., entering 5006 instead of 5060) that can silently disrupt voice traffic or leave management ports exposed.
- Standardized Telecom Profile: Pre-configures carrier-grade port standards out of the box, including Kamailio default signaling ports, RTPEngine RTP proxy ranges, and Prometheus telemetry ports.
- Rapid Port Range Updates: Changing a service definition (e.g., expanding the RTP media range from
10000–20000to10000–30000) automatically updates all associated firewall rules upon rule re-application. - Audit & Compliance Readability: Security auditors can immediately inspect named service definitions rather than deciphering raw iptables port syntax in obscure script files.
3. 🎯 User Roles & Key Capabilities
Section titled “3. 🎯 User Roles & Key Capabilities”| Role | Primary Use Case | Key Capabilities |
|---|---|---|
| Network Infrastructure Engineer | Service Definition & Port Allocation | Define custom telephony services, allocate non-standard SIP/TLS listening ports, and configure RTP media boundaries. |
| SBC Administrator | Service Catalog Maintenance | Enable or disable specific service definitions, update service descriptions, and verify active port bindings. |
| SecOps Auditor | Attack Surface Review | Review all defined listening ports, ensure non-essential ports are disabled, and verify internal-only restrictions. |
| DevOps Automation Lead | Infrastructure As Code Integration | Export service definitions to declarative deployment manifests and verify cluster uniformity. |
| AI Network Systems Agent / NOC Copilot | Automated Service Catalog Inspection | Query defined firewall services, inspect port assignments and protocols, and verify telemetry or media port alignment via MCP tools. |
4. Visual Interface & Layout
Section titled “4. Visual Interface & Layout”The Firewall Services interface provides a comprehensive DataGrid view displaying all defined services, transport protocols, port assignments, descriptive roles, and operational statuses.
4.1 Firewall Services List View
Section titled “4.1 Firewall Services List View”Displays pre-configured and custom system services, port ranges, and status toggles.

5. Field Reference & Pre-Configured Services Catalog
Section titled “5. Field Reference & Pre-Configured Services Catalog”5.1 Service Data Fields
Section titled “5.1 Service Data Fields”| Field | Type | Description |
|---|---|---|
| Name | String | Human-readable service identifier (e.g., SIP Internal (UDP), RTP Media). |
| Protocol | Badge | Transport layer protocol: TCP, UDP, or ICMP. |
| Port | String / Range | Specific port number (e.g., 5060, 443), port range (10000–20000), or -1 for protocol-wide filtering (ICMP). |
| Description | String | Detailed explanation of the service’s role within the SBC architecture. |
| Status | Status Dot | Active (Green) or Disabled (Grey) status indicator. |
| Actions | Action Icons | Edit service parameters or delete custom service objects. |
5.2 Pre-Configured Services Catalog
Section titled “5.2 Pre-Configured Services Catalog”| Service Name | Protocol | Port / Range | Primary Telecom Function |
|---|---|---|---|
| HTTP Redirect | TCP |
80 |
Automatic redirect of plain HTTP requests to HTTPS. |
| HTTPS | TCP |
443 |
Secure Web UI and REST API administrative interface. |
| ICMP Ping | ICMP |
-1 |
Network diagnostics and latency monitoring via ICMP Echo Request. |
| PostgreSQL | TCP |
5432 |
Relational database access (restricted strictly to internal cluster networks). |
| Prometheus Metrics | TCP |
9100 |
Node Exporter and system performance metric scraping. |
| RTP Media | UDP |
10000–20000 |
Real-time audio and video streams relayed by RTPEngine. |
| SBC Admin API | TCP |
3000 |
Node.js Fastify backend API daemon. |
| SIP External (TCP) | TCP |
5080 |
Public-facing SIP carrier signaling over TCP. |
| SIP External (UDP) | UDP |
5080 |
Public-facing SIP carrier signaling over UDP. |
| SIP Internal (TCP) | TCP |
5060 |
Core PBX and internal extension signaling over TCP. |
| SIP Internal (UDP) | UDP |
5060 |
Core PBX and internal extension signaling over UDP. |
| SIP TLS External | TCP |
5081 |
Encrypted public-facing SIP signaling via TLS. |
| SIP TLS Internal | TCP |
5061 |
Encrypted core PBX and private trunk signaling via TLS. |
| SSH | TCP |
22 |
Secure Shell for host-level remote system administration. |
| WireGuard VPN | UDP |
51820 |
Secure encrypted tunnel interface for inter-node communication. |
6. Service Abstraction & nftables Mapping
Section titled “6. Service Abstraction & nftables Mapping”Services defined in sbc_admin.firewall_services translate dynamically into Linux nftables syntax when firewall rules are applied:
# Single port translationservice: "SIP Internal (UDP)" (UDP, 5060)nftables: udp dport 5060 accept
# Port range translationservice: "RTP Media" (UDP, 10000-20000)nftables: udp dport 10000-20000 accept
# Protocol without port (ICMP)service: "ICMP Ping" (ICMP, -1)nftables: ip protocol icmp accept7. Operational Best Practices & Security Hardening
Section titled “7. Operational Best Practices & Security Hardening”- Isolate Database & Metrics: Ensure services such as
PostgreSQL(5432) andSBC Admin API(3000) are never exposed to public source addresses. Always bind rules referencing these services to private management subnets (e.g.,10.0.0.0/8or192.168.10.0/24). - Match RTP Ranges with RTPEngine: Always verify that the port range specified in the
RTP Mediaservice (10000-20000) exactly matches theport-minandport-maxparameters configured in/etc/rtpengine/rtpengine.conf. - Separate External from Internal SIP: Keep internal PBX signaling (5060/5061) separated from public carrier signaling (5080/5081) to maintain clean architectural boundary isolation.
- Minimize Open Administrative Services: Disable services like
Prometheus MetricsorHTTP Redirectif external scraping or plaintext redirects are not required by your infrastructure policy.
8. Verification & Diagnostics
Section titled “8. Verification & Diagnostics”8.1 Inspect Services in Database
Section titled “8.1 Inspect Services in Database”Query all active services and their allocated ports:
sudo -u postgres psql -d sbc_admin -c "SELECT name, protocol, port, description, is_activeFROM firewall_servicesORDER BY id;"8.2 Verify Listening Sockets on Host
Section titled “8.2 Verify Listening Sockets on Host”Verify that the host kernel is actively listening on the defined service ports:
ss -tulwn | grep -E ':22|:80|:443|:3000|:5060|:5080|:5061|:5081|:51820'9. Model Context Protocol (MCP) AI Integration
Section titled “9. Model Context Protocol (MCP) AI Integration”The Ring2All SBC MCP Server exposes dedicated service catalog introspection tools under the firewall_services tool category. Autonomous infrastructure agents and the Ring2All SBC NOC Copilot can query available service templates, inspect allocated port boundaries, and ensure compliance before writing or adjusting packet filtering policies.
9.1 Available MCP Tools
Section titled “9.1 Available MCP Tools”| Tool Name | Operation Type | Risk Level | Description |
|---|---|---|---|
list_sbc_firewall_services |
Read-only | read_only |
Lists all defined network service objects in the SBC catalog, including protocols, port numbers/ranges, and system flags. |
get_sbc_firewall_service |
Read-only | read_only |
Retrieves full technical details for a specific firewall service by numerical ID or canonical name. |
9.2 Tool Schemas & Parameter Definitions
Section titled “9.2 Tool Schemas & Parameter Definitions”list_sbc_firewall_services
Section titled “list_sbc_firewall_services”- Description: List all defined firewall services (ports and protocols) in Ring2All SBC.
- Input Schema:
{ "type": "object", "properties": {}}get_sbc_firewall_service
Section titled “get_sbc_firewall_service”- Description: Retrieve detailed port and protocol specifications for a specific firewall service.
- Input Schema:
{ "type": "object", "properties": { "id": { "type": "number", "description": "Numerical primary key ID of the firewall service" }, "name": { "type": "string", "description": "Canonical name of the service (e.g., 'RTP Media', 'SIP Internal (UDP)')" } }}9.3 Sample Tool Execution Payloads
Section titled “9.3 Sample Tool Execution Payloads”Example 1: Listing All Pre-Configured Telephony Services
Section titled “Example 1: Listing All Pre-Configured Telephony Services”Request Payload:
{ "tool": "list_sbc_firewall_services", "parameters": {}}Response Payload:
{ "success": true, "data": { "total": 15, "services": [ { "id": 1, "name": "SIP Internal (UDP)", "protocol": "UDP", "port": "5060", "description": "Core PBX and internal extension signaling over UDP", "enabled": true, "isSystem": true }, { "id": 6, "name": "RTP Media", "protocol": "UDP", "port": "10000-20000", "description": "Real-time audio and video streams relayed by RTPEngine", "enabled": true, "isSystem": true }, { "id": 14, "name": "WireGuard VPN", "protocol": "UDP", "port": "51820", "description": "Secure encrypted tunnel interface for inter-node communication", "enabled": true, "isSystem": true } ] }}Example 2: Inspecting Specific RTP Media Service
Section titled “Example 2: Inspecting Specific RTP Media Service”Request Payload:
{ "tool": "get_sbc_firewall_service", "parameters": { "name": "RTP Media" }}Response Payload:
{ "success": true, "data": { "service": { "id": 6, "name": "RTP Media", "protocol": "UDP", "port": "10000-20000", "description": "Real-time audio and video streams relayed by RTPEngine", "enabled": true, "isSystem": true } }}9.4 Bilingual Natural Language Copilot Prompts
Section titled “9.4 Bilingual Natural Language Copilot Prompts”English Prompts
Section titled “English Prompts”- “List all defined firewall services to see what ports are allocated for SIP and RTP.”
→ Agent calls
list_sbc_firewall_services(). - “What is the configured port range for the ‘RTP Media’ firewall service?”
→ Agent calls
get_sbc_firewall_service({"name": "RTP Media"}).
Spanish Prompts (Español)
Section titled “Spanish Prompts (Español)”- “Lista todos los servicios del firewall para ver qué puertos están asignados a SIP y RTP.”
→ Agente invoca
list_sbc_firewall_services(). - “¿Cuál es el rango de puertos configurado para el servicio de firewall ‘RTP Media’?”
→ Agente invoca
get_sbc_firewall_service({"name": "RTP Media"}).
9.5 Enterprise Security & Execution Safeguards
Section titled “9.5 Enterprise Security & Execution Safeguards”- System Service Protection: System services (
isSystem: true) are flagged as immutable templates to prevent accidental disruption of core SBC signaling or SSH administrative channels. - Read-Only Discovery: Both
list_sbc_firewall_servicesandget_sbc_firewall_serviceare safe, non-mutating query tools that can be executed freely across monitoring and administrative roles. - Lookup Resiliency: Lookups support either numerical ID or case-insensitive name matching, returning structured error diagnostics if an invalid service reference is provided.
10. Glossary
Section titled “10. Glossary”- Port Range: A contiguous sequence of port numbers (e.g., 10000 through 20000) reserved for dynamic media streams (RTP/RTCP).
- WireGuard: Modern, high-performance VPN protocol operating over UDP, used in Ring2All SBC to establish secure site-to-site tunnels with core PBX clusters.
- RTPEngine: High-throughput media relay proxy used by Kamailio to bridge and transcode RTP packets between networks.
- ICMP: Internet Control Message Protocol used by network devices to send error messages and operational information like ping responses.
- Model Context Protocol (MCP): An open standard enabling autonomous AI assistants and NOC copilots to securely discover and invoke SBC operational tools.

