--- title: "Firewall Global Settings & Intrusion Detection" description: "Documentation for Firewall Settings" --- ## Table of Contents 1. [Overview & Security Architecture](#1-overview--security-architecture) 2. [Business & Operational Significance](#2-business--operational-significance) 3. [🎯 User Roles & Key Capabilities](#3--user-roles--key-capabilities) 4. [Visual Interface & Layout](#4-visual-interface--layout) 5. [Field Reference & Firewall Parameters](#5-field-reference--firewall-parameters) 6. [Kernel Filtering & Fail2Ban Daemon Integration](#6-kernel-filtering--fail2ban-daemon-integration) 7. [Operational Security Hardening & Best Practices](#7-operational-security-hardening--best-practices) 8. [Verification & Diagnostics](#8-verification--diagnostics) 9. [Model Context Protocol (MCP) AI Integration](#9-model-context-protocol-mcp-ai-integration) 10. [Glossary](#10-glossary) --- ## 1. Overview & Security Architecture In **Ring2All SBC**, the **Firewall Settings** module serves as the primary control center for host-level packet filtering and automated host intrusion prevention. It bridges high-level web administration with Linux kernel networking technologiesβ€”specifically modern **nftables** packet filtering chains and the **Fail2Ban** intrusion defense framework. ``` β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ RING2ALL SBC FIREWALL SETTINGS ENGINE β”‚ β”‚ (Stored in sbc_admin.firewall_settings) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β–Ό β–Ό β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ GLOBAL PACKET FILTER β”‚ β”‚ INTRUSION DETECTION (F2B) β”‚ β”‚ (Linux nftables) β”‚ β”‚ (System Fail2Ban) β”‚ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”‚ β€’ Master Firewall Toggle β”‚ β”‚ β€’ Master Intrusion Toggle β”‚ β”‚ β€’ Default Chain Policy (DROP)β”‚ β”‚ β€’ Max Failed Attempts β”‚ β”‚ β€’ Established State Tracking β”‚ β”‚ β€’ Findtime Monitoring Window β”‚ β”‚ β€’ Loopback & ICMP Filtering β”‚ β”‚ β€’ Bantime Duration β”‚ β”‚ β€’ WireGuard / SIP Tunneling β”‚ β”‚ β€’ Alert Dispatch Email β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β–Ό β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ LINUX HOST KERNEL RUNTIME β”‚ β”‚ (/etc/nftables.conf & /etc/fail2ban/jail.local) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ ``` The system ensures that even if application-layer services experience unforeseen edge conditions, the underlying operating system kernel remains fortified against unauthorized network access, brute force attacks against administrative interfaces, and port scanning. --- ## 2. Business & Operational Significance * **Host-Level Zero Trust**: Guarantees that only explicitly permitted administrative and telecom ports (HTTPS, SSH, SIP, RTP, WireGuard) are accessible from untrusted networks. * **Automated Brute-Force Neutralization**: Protects SSH and Web API administrative access points by dynamically calculating authentication failure rates and banning hostile IPs at the socket level. * **Carrier Resilience & Compliance**: Satisfies telecommunications security audits (SOC 2, ISO 27001) by providing auditable host-level firewall governance with strict logging and notification capabilities. * **Single-Pane-of-Glass Governance**: Eliminates the need for manual, error-prone editing of `/etc/nftables.conf` or `/etc/fail2ban/jail.local` files across SBC cluster instances. --- ## 3. 🎯 User Roles & Key Capabilities | Role | Primary Use Case | Key Capabilities | | :--- | :--- | :--- | | **SBC Security Administrator** | Perimeter & Host Defense Policy | Toggle master firewall filtering, adjust Fail2Ban brute-force thresholds, and configure incident notification recipients. | | **DevOps & Infrastructure Lead** | Kernel Network Synchronization | Verify nftables rule persistence, coordinate cluster firewall baseline deployments, and monitor connection tracking table states. | | **NOC Systems Operator** | Service Availability Auditing | Inspect firewall operational statuses, monitor intrusion detection alerts, and verify system responsiveness. | | **Compliance Auditor** | Regulatory Verification | Audit failure windows, ban durations, and alert delivery destinations against corporate security baselines. | | **AI Host Security Analyst / Automation Copilot** | Policy Audit & Hardening Compliance | Inspect global firewall switches, audit intrusion detection metrics (failed attempts, findtime, bantime), and apply security baseline updates programmatically via MCP. | --- ## 4. Visual Interface & Layout The Firewall Settings view provides clean card-based controls for both the global packet filter status and the Fail2Ban intrusion detection subsystem. ### 4.1 Global Firewall & Intrusion Settings Configures master operational switches, authentication thresholds, monitoring windows, ban duration, and notification routing. ![Firewall Settings View](/screenshots/sbc/admin/firewall-settings/firewall-settings.png) --- ## 5. Field Reference & Firewall Parameters ### 5.1 Firewall Status Parameters | Field | Type | Default | Description | | :--- | :--- | :--- | :--- | | **Firewall Status** | Switch Toggle | `Yes` (Active) | Master toggle controlling Linux `nftables` packet filtering. When disabled, standard ACCEPT policies are applied across all input chains. | ### 5.2 Intrusion Detection (Fail2Ban) Parameters | Field | Type | Default | Description | | :--- | :--- | :--- | :--- | | **Intrusion Detection** | Switch Toggle | `Yes` (Active) | Master toggle enabling the `fail2ban-server` monitoring daemon across SSH, API, and Web login journals. | | **Max Failed Attempts** | Number | `5` | Maximum number of failed authentication attempts permitted from a single IP before an automatic ban is triggered. | | **Monitoring Window** | Number (Minutes) | `10` | The evaluation window (`findtime`) during which failed authentication attempts are accumulated. | | **Ban Duration** | Number (Minutes) | `60` | The duration (`bantime`) during which an offending IP remains blocked in the firewall ban set before automatic unbanning. | | **Notification Email** | Email String | `admin@example.com` | Destination email address to receive immediate automated alert dispatches whenever an intrusion ban is executed. | --- ## 6. Kernel Filtering & Fail2Ban Daemon Integration When changes are committed in the Firewall Settings module, the backend orchestrator updates the database and applies configuration to the host environment: ### 6.1 Database Transaction Parameters are saved to `sbc_admin.firewall_settings`: ```sql UPDATE firewall_settings SET firewall_enabled = TRUE, fail2ban_enabled = TRUE, max_failed_attempts = 5, find_time = 600, ban_time = 3600, notification_email = 'admin@example.com', updated_at = NOW() WHERE id = 1; ``` ### 6.2 Service Synchronization The backend executes non-blocking system calls to reconfigure the daemons: ```bash # Update Fail2Ban jail parameters fail2ban-client set sshd maxretry 5 fail2ban-client set sshd findtime 600 fail2ban-client set sshd bantime 3600 # Ensure nftables service is active systemctl is-active nftables || systemctl start nftables ``` --- ## 7. Operational Security Hardening & Best Practices * **Retain Conservative Thresholds**: A `Max Failed Attempts` of 5 and `Monitoring Window` of 10 minutes balances legitimate operator typos with rapid defense against automated credential stuffing. * **Notification Email Verification**: Ensure the `Notification Email` points to a monitored distribution list or SecOps ticket system rather than an individual engineer's personal inbox. * **Avoid Disabling Master Firewall**: The master `Firewall Status` should only be disabled in emergency maintenance scenarios or isolated lab environments; never disable it on public carrier-facing SBCs. * **Monitor Conntrack Tables**: On high-capacity SBCs handling tens of thousands of simultaneous RTP streams, ensure the Linux kernel `net.netfilter.nf_conntrack_max` is tuned appropriately. --- ## 8. Verification & Diagnostics ### 8.1 Inspect Firewall Daemon Status Verify that `nftables` and `fail2ban` are operational on the host: ```bash systemctl status nftables fail2ban --no-pager ``` ### 8.2 Verify Active Fail2Ban Jails Inspect active jails and current ban counts: ```bash fail2ban-client status fail2ban-client status sshd ``` ### 8.3 Query Database Settings Verify parameters stored in the database: ```bash sudo -u postgres psql -d sbc_admin -c "SELECT * FROM firewall_settings;" ``` --- ## 9. Model Context Protocol (MCP) AI Integration The **Ring2All SBC MCP Server** exposes dedicated host defense tools under the `firewall_settings` category. Autonomous SecOps agents and the Ring2All SBC NOC Copilot can audit the current host firewall state, verify Fail2Ban operational parameters, and execute controlled policy adjustments. ### 9.1 Available MCP Tools | Tool Name | Operation Type | Risk Level | Description | | :--- | :--- | :--- | :--- | | `get_sbc_firewall_settings` | Read-only | `read_only` | Retrieves global packet filter and intrusion detection parameters, including fail threshold, findtime, bantime, and notification routing. | | `update_sbc_firewall_settings` | Mutating / Operational | `critical` | Adjusts master firewall enablement, intrusion prevention status, brute force thresholds, ban durations, or alert recipient email. | ### 9.2 Tool Schemas & Parameter Definitions #### `get_sbc_firewall_settings` * **Description**: Retrieve current global firewall and host intrusion detection settings. * **Input Schema**: ```json { "type": "object", "properties": {} } ``` #### `update_sbc_firewall_settings` * **Description**: Update host firewall master switch, intrusion detection (Fail2Ban), threshold counters, ban timers, or notification email. * **Input Schema**: ```json { "type": "object", "properties": { "firewallEnabled": { "type": "boolean", "description": "Master switch to enable or disable Linux nftables packet filtering" }, "intrusionDetectionEnabled": { "type": "boolean", "description": "Master switch to enable or disable Fail2Ban intrusion detection" }, "failedAttemptsAllowed": { "type": "number", "description": "Max failed authentication attempts permitted before an automated host ban" }, "findTime": { "type": "number", "description": "Monitoring evaluation window in minutes" }, "banTime": { "type": "number", "description": "Ban duration in minutes" }, "notificationEmail": { "type": "string", "description": "Target email address to receive immediate security breach notifications" } } } ``` ### 9.3 Sample Tool Execution Payloads #### Example 1: Retrieving Firewall Settings **Request Payload:** ```json { "tool": "get_sbc_firewall_settings", "parameters": {} } ``` **Response Payload:** ```json { "success": true, "data": { "firewallEnabled": true, "intrusionDetectionEnabled": true, "failedAttemptsAllowed": 5, "findTime": 10, "banTime": 60, "notificationEmail": "secops@ring2all.com" } } ``` #### Example 2: Updating Ban Duration and Notification Email **Request Payload:** ```json { "tool": "update_sbc_firewall_settings", "parameters": { "banTime": 120, "notificationEmail": "alerts-sbc@ring2all.com" } } ``` **Response Payload:** ```json { "success": true, "data": { "message": "Firewall settings updated successfully", "settings": { "firewallEnabled": true, "intrusionDetectionEnabled": true, "failedAttemptsAllowed": 5, "findTime": 10, "banTime": 120, "notificationEmail": "alerts-sbc@ring2all.com" } } } ``` ### 9.4 Bilingual Natural Language Copilot Prompts #### English Prompts * *"Check if the SBC host firewall and intrusion detection are currently active."* β†’ Agent calls `get_sbc_firewall_settings()`. * *"Increase the Fail2Ban duration to 120 minutes and update notification email to alerts-sbc@ring2all.com."* β†’ Agent calls `update_sbc_firewall_settings({"banTime": 120, "notificationEmail": "alerts-sbc@ring2all.com"})`. #### Spanish Prompts (EspaΓ±ol) * *"Verifica si el firewall del host y la detecciΓ³n de intrusos estΓ‘n habilitados en el SBC."* β†’ Agente invoca `get_sbc_firewall_settings()`. * *"Aumenta la duraciΓ³n del bloqueo a 120 minutos y cambia el correo de notificaciΓ³n a alerts-sbc@ring2all.com."* β†’ Agente invoca `update_sbc_firewall_settings({"banTime": 120, "notificationEmail": "alerts-sbc@ring2all.com"})`. ### 9.5 Enterprise Security & Execution Safeguards 1. **Strict Role Authorization**: Changing global firewall state (`firewallEnabled: false`) or altering security thresholds requires `superadmin` or explicit `firewall_settings` administrative clearance. 2. **Email Syntax Sanitation**: The `notificationEmail` field must pass strict RFC 5322 validation to prevent command injection in mail delivery pipelines. 3. **Fail-Safe Disabling Confirmation**: Autonomous agents are programmed to prompt human operators with a confirmation warning whenever attempting to disable `firewallEnabled`. --- ## 10. Glossary * **nftables**: Modern Linux kernel packet classification framework that replaces legacy `iptables`, providing superior performance and atomic rule updates. * **Fail2Ban**: Intrusion prevention software framework that scans log files and bans IPs that show malicious signs like too many password failures. * **Findtime**: The time window in seconds or minutes during which consecutive failed login attempts are evaluated. * **Bantime**: The duration for which an offending host is denied network access after exceeding maximum failure counts. * **Model Context Protocol (MCP)**: An open standard enabling autonomous AI assistants and NOC copilots to securely discover and invoke SBC operational tools.