--- title: "Host Network, FQDN & System Integration Settings" description: "Documentation for Server Settings" --- ## Table of Contents 1. [Overview & Architecture](#1-overview--architecture) 2. [Business & Operational Significance](#2-business--operational-significance) 3. [🎯 User Roles & Key Capabilities](#3--user-roles--key-capabilities) 4. [Visual Interface & Layout](#4-visual-interface--layout) 5. [Field Reference & Parameter Specification](#5-field-reference--parameter-specification) 6. [Dual-Homed Network & NGINX Web Reverse Proxy Architecture](#6-dual-homed-network--nginx-web-reverse-proxy-architecture) 7. [SIP Device Auto-Provisioning Reverse Proxy Security](#7-sip-device-auto-provisioning-reverse-proxy-security) 8. [Verification & Diagnostics](#8-verification--diagnostics) 9. [Model Context Protocol (MCP) AI Integration](#9-model-context-protocol-mcp-ai-integration) 10. [Glossary](#10-glossary) --- ## 1. Overview & Architecture In **Ring2All SBC**, the **Server Settings** module governs system-level network identity, edge routing topologies, administrative web proxy bindings, and secure interconnectivity with core Ring2All PBX systems. It establishes the foundational operational boundary between external public networks (WAN) and trusted administrative networks (LAN/DMZ). ``` PUBLIC INTERNET (WAN) β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β–Ό (SIP Signaling / RTP Media) β–Ό (HTTPS Admin & Provisioning) β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ Kamailio 6.x β”‚ β”‚ NGINX Reverse β”‚ β”‚ (Public IP) β”‚ β”‚ Proxy (443) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β–Ό β–Ό β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ SBC Admin Portal β”‚ β”‚ SIP Provisioning β”‚ β”‚ β”‚ (Fastify REST / β”‚ β”‚ Security Filter β”‚ β”‚ β”‚ React SPA) β”‚ β”‚ (User-Agent Reg) β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β–Ό SECURE INTERNAL LAN / DMZ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ Ring2All PBX β”‚ β”‚ (Core Cluster) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ ``` The configuration is maintained in `sbc_admin.server_settings` and directly synchronizes with host services, NGINX upstream definitions, and Kamailio socket bindings. --- ## 2. Business & Operational Significance * **Dual-Homed Edge Isolation**: Explicit separation of Public IP and Internal IP addresses guarantees that administrative interfaces and core PBX interconnects remain invisible to public network vulnerability scanners. * **Unified Domain Routing**: Supports multi-domain administrative routing, allowing operators to map canonical Fully Qualified Domain Names (FQDNs) and alternative subdomains (`admin_domain`, `admin_aliases`) to the secure web console. * **Automated Cryptographic Association**: Seamlessly binds managed X.509 SSL/TLS certificates to the NGINX web server, eliminating manual configuration edits and certificate path errors. * **Hardened IP Phone Provisioning Proxy**: Built-in reverse proxy forwarding allows external IP phones to securely retrieve provisioning XML/cfg templates from the PBX backend while actively rejecting unauthorized web browsers and bot scrapers via User-Agent enforcement. --- ## 3. 🎯 User Roles & Key Capabilities | Role | Administrative Permissions | Operational Responsibilities | | :--- | :--- | :--- | | **System Administrator** | Full Read & Write | Configures host networking, FQDNs, NGINX SSL certificates, and PBX provisioning bridge settings. | | **Network & Security Engineer** | Read & Write | Audits public/internal IP assignments, validates reverse proxy cipher suites, and manages User-Agent filters. | | **Telecom NOC Operator** | Read-Only | Inspects active host FQDNs, public IP bindings, and validates PBX provisioning connectivity status. | | **AI Host Network Engineer / Automation Copilot** | Programmatic Audit & Governance | Inspects network bindings, validates host FQDN configuration, and coordinates dynamic reverse proxy parameter updates via MCP. | --- ## 4. Visual Interface & Layout The **Server Settings** interface provides a streamlined, card-based configuration form organized into three logical operational sections: ![Server Settings View](/screenshots/sbc/admin/server-settings/server-settings.png) 1. **Network Configuration**: Hostname, Public IP, and Internal IP definitions. 2. **Web Admin (NGINX)**: Primary administrative domain, alternative aliases, and SSL certificate selector. 3. **Ring2All PBX Integration & Provisioning**: Core PBX backend URL and User-Agent security filtering toggle. --- ## 5. Field Reference & Parameter Specification | Field Name | Type | Constraints | Description | | :--- | :---: | :--- | :--- | | **Hostname** | `string` | FQDN or hostname format | System host identifier advertised in SIP Via headers, syslog messages, and administrative banners. | | **Public IP** | `IPv4/IPv6` | Valid IP Address | External WAN address bound to Kamailio edge sockets, RTPEngine public interfaces, and public DNS records. | | **Internal IP** | `IPv4/IPv6` | Valid IP Address | Private LAN/DMZ address used for intra-cluster communication, PBX trunking, and database access. | | **Admin Domain** | `string` | Valid FQDN | Primary canonical domain used to access the Ring2All SBC administrative portal (e.g., `sbc.ring2all.net`). | | **Additional Aliases** | `string` | Comma/space-separated FQDNs | Secondary domain aliases accepted by the NGINX `server_name` directive (e.g., `sbc01.ring2all.net`). | | **SSL Certificate** | `dropdown` | Active Certificate | Bound X.509 certificate used by NGINX for HTTPS administrative termination and SIP provisioning endpoints. | | **Ring2All PBX Server (IP / Host)** | `string` | Valid URL / FQDN | HTTPS endpoint of the core Ring2All PBX provisioning service (e.g., `https://192.168.10.31`). | | **User-Agent Security Filter** | `boolean` | `true` / `false` | When enabled, NGINX restricts `/provisioning/` requests strictly to recognized telecom manufacturer hardware. | --- ## 6. Dual-Homed Network & NGINX Web Reverse Proxy Architecture The SBC operates as an edge boundary device, typically configured with two distinct network interfaces: 1. **Edge Interface (`eth0` / WAN)**: Assigned the **Public IP**. Terminates external SIP signaling (5060 UDP/TCP, 5061 TLS) and RTP media relay sessions (10000–20000 UDP). 2. **Core Interface (`eth1` / LAN)**: Assigned the **Internal IP**. Establishes private connections with Ring2All PBX clusters, Telephony Server media servers, and internal PostgreSQL instances. When changes are saved in the Server Settings module, the backend executes an atomic reconfiguration cycle: * Re-generates `/etc/nginx/sites-enabled/sbc-admin.conf`. * Validates configuration syntax via `nginx -t`. * Performs a zero-downtime worker reload via `systemctl reload nginx`. --- ## 7. SIP Device Auto-Provisioning Reverse Proxy Security To protect PBX configuration filesβ€”which may contain extension passwords, SIP server addresses, and feature codesβ€”the SBC acts as a hardened provisioning proxy: ```nginx location ~* "^/provisioning/(?.+)$" { if ($http_user_agent !~* "(Yealink|Grandstream|Fanvil|Polycom|Cisco|Snom|Htek|Flyingvoice|Panasonic|Gigaset|curl|Wget)") { return 403 "Forbidden: Non-telephony device"; } proxy_pass https://pbx_provisioning_backend/api/apps/provisioning/devices/config/$provpath; proxy_ssl_verify off; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } ``` * **Header Inspection**: Any request lacking a valid telecom manufacturer User-Agent string receives an immediate `403 Forbidden` response at the web server layer. * **Direct WAN Isolation**: Internal PBX provisioning ports and directories are never exposed directly to the public internet. --- ## 8. Verification & Diagnostics To verify network bindings, NGINX reverse proxy status, and provisioning connectivity from the CLI: ```bash # 1. Test NGINX configuration syntax and reload status nginx -t systemctl status nginx # 2. Verify active listening ports on Public and Internal IPs ss -tulpn | grep -E ':(80|443|5060|5061)' # 3. Simulate authorized SIP phone provisioning request curl -k -I -A "Yealink SIP-T46U 66.86.0.15" https://192.168.10.32/provisioning/001565123456.cfg # 4. Simulate blocked browser/scraper provisioning attempt curl -k -I -A "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" https://192.168.10.32/provisioning/001565123456.cfg # Expected response: HTTP/1.1 403 Forbidden ``` --- ## 9. Model Context Protocol (MCP) AI Integration The **Server Settings** module exposes standardized tools within the Model Context Protocol (MCP) ecosystem, enabling autonomous AI agents and NOC copilots to inspect host network bindings and securely manage edge routing configurations. ### 9.1 MCP Tool Summary | Tool Name | Action | Risk Level | Purpose | | :--- | :--- | :--- | :--- | | `get_sbc_server_settings` | Read | `read` | Retrieve active host network parameters, public/internal IP assignments, FQDNs, and PBX proxy configuration. | | `update_sbc_server_settings` | Write | `operational` | Update host identity, admin domain, IP addresses, and PBX reverse proxy settings with atomic validation. | ### 9.2 Tool Schemas & Input Parameters #### Schema: `get_sbc_server_settings` ```json { "type": "object", "properties": {}, "additionalProperties": false } ``` #### Schema: `update_sbc_server_settings` ```json { "type": "object", "properties": { "hostname": { "type": "string", "description": "System host name identifier" }, "publicIp": { "type": "string", "description": "Public WAN IP address used for external SIP signaling and RTP media" }, "internalIp": { "type": "string", "description": "Internal LAN/DMZ IP address used for PBX cluster interconnectivity" }, "adminDomain": { "type": "string", "description": "Primary canonical FQDN for the SBC administrative web console" }, "adminAliases": { "type": "string", "description": "Alternative domain aliases separated by commas or spaces" }, "sslCertificateId": { "type": "number", "description": "ID of the managed X.509 SSL certificate bound to NGINX" }, "pbxServerUrl": { "type": "string", "description": "HTTPS URL of the Ring2All PBX core server for device auto-provisioning" }, "userAgentFilter": { "type": "boolean", "description": "Enforce telecom hardware manufacturer User-Agent whitelist on provisioning routes" } }, "additionalProperties": false } ``` ### 9.3 Sample Tool Execution Payloads #### Example 1: Inspecting Host Network & Provisioning Settings **Request Payload:** ```json { "tool": "get_sbc_server_settings", "parameters": {} } ``` **Response Payload:** ```json { "success": true, "data": { "hostname": "sbc01.ring2all.net", "publicIp": "198.51.100.25", "internalIp": "192.168.10.32", "adminDomain": "sbc.ring2all.net", "adminAliases": "sbc-primary.ring2all.net, sbc-alt.ring2all.net", "sslCertificateId": 3, "pbxServerUrl": "https://192.168.10.31", "userAgentFilter": true } } ``` #### Example 2: Updating Public IP and Provisioning Bridge URL **Request Payload:** ```json { "tool": "update_sbc_server_settings", "parameters": { "publicIp": "198.51.100.50", "pbxServerUrl": "https://pbx.ring2all.net" } } ``` **Response Payload:** ```json { "success": true, "data": { "message": "SBC server settings updated successfully", "settings": { "hostname": "sbc01.ring2all.net", "publicIp": "198.51.100.50", "internalIp": "192.168.10.32", "adminDomain": "sbc.ring2all.net", "adminAliases": "sbc-primary.ring2all.net, sbc-alt.ring2all.net", "sslCertificateId": 3, "pbxServerUrl": "https://pbx.ring2all.net", "userAgentFilter": true } } } ``` ### 9.4 Bilingual Natural Language Copilot Prompts #### English Prompts * *"Inspect the SBC host server settings and show me the active Public and Internal IPs."* β†’ Agent invokes `get_sbc_server_settings()`. * *"Update the core PBX provisioning server URL to https://pbx.ring2all.net and ensure User-Agent filtering is active."* β†’ Agent invokes `update_sbc_server_settings({"pbxServerUrl": "https://pbx.ring2all.net", "userAgentFilter": true})`. #### Spanish Prompts (EspaΓ±ol) * *"Inspecciona la configuraciΓ³n del servidor SBC y muΓ©strame las IPs pΓΊblica y privada configuradas."* β†’ Agente invoca `get_sbc_server_settings()`. * *"Actualiza la URL del servidor PBX a https://pbx.ring2all.net y verifica que el filtro de User-Agent estΓ© activo."* β†’ Agente invoca `update_sbc_server_settings({"pbxServerUrl": "https://pbx.ring2all.net", "userAgentFilter": true})`. ### 9.5 Enterprise Security & Execution Safeguards 1. **Strict Administrative Authorization**: Updating server network parameters or domain bindings requires `superadmin` or explicit `server_settings` write permission. 2. **IP Address & FQDN Validation**: The backend sanitizes and validates IPv4/IPv6 syntax and RFC 1035 hostnames prior to database write, preventing parameter injection into `/etc/nginx/` configuration files. 3. **Atomic NGINX Syntax Verification**: Updates trigger an automated `nginx -t` validation cycle. If any parameter generates an invalid configuration block, the transaction is rolled back and previous configurations are preserved. --- ## 10. Glossary * **Dual-Homed**: A server architecture equipped with two separate network interfaces connecting to independent networks (e.g., WAN and LAN). * **FQDN**: Fully Qualified Domain Name specifying an exact location in the DNS hierarchy (e.g., `sbc-core01.ring2all.net`). * **Reverse Proxy**: An intermediate proxy server that retrieves resources on behalf of a client from one or more internal upstream servers. * **User-Agent Filtering**: Access control mechanism that evaluates HTTP client headers to block automated scrapers while admitting legitimate telephony hardware. * **Model Context Protocol (MCP)**: An open architectural standard allowing AI copilots to programmatically inspect server parameters and coordinate network reconfigurations.