Skip to content

Host Network, FQDN & System Integration Settings

9 min readUpdated: Sep 26, 2026
View as Markdown
  1. Overview & Architecture
  2. Business & Operational Significance
  3. 🎯 User Roles & Key Capabilities
  4. Visual Interface & Layout
  5. Field Reference & Parameter Specification
  6. Dual-Homed Network & NGINX Web Reverse Proxy Architecture
  7. SIP Device Auto-Provisioning Reverse Proxy Security
  8. Verification & Diagnostics
  9. Model Context Protocol (MCP) AI Integration
  10. Glossary

In Ring2All SBC, the Server Settings module governs system-level network identity, edge routing topologies, administrative web proxy bindings, and secure interconnectivity with core Ring2All PBX systems. It establishes the foundational operational boundary between external public networks (WAN) and trusted administrative networks (LAN/DMZ).

PUBLIC INTERNET (WAN)
│
┌───────────────────────┴───────────────────────┐
│ │
▼ (SIP Signaling / RTP Media) ▼ (HTTPS Admin & Provisioning)
┌─────────────────┐ ┌─────────────────┐
│ Kamailio 6.x │ │ NGINX Reverse │
│ (Public IP) │ │ Proxy (443) │
└────────┬────────┘ └────────┬────────┘
│ │
│ ┌───────────────┴───────────────┐
│ ▼ ▼
│ ┌──────────────────┐ ┌──────────────────┐
│ │ SBC Admin Portal │ │ SIP Provisioning │
│ │ (Fastify REST / │ │ Security Filter │
│ │ React SPA) │ │ (User-Agent Reg) │
│ └──────────────────┘ └────────┬─────────┘
│ │
└───────────────────────────────┬──────────────────────────────┘
▼
SECURE INTERNAL LAN / DMZ
│
┌──────────────────┐
│ Ring2All PBX │
│ (Core Cluster) │
└──────────────────┘

The configuration is maintained in sbc_admin.server_settings and directly synchronizes with host services, NGINX upstream definitions, and Kamailio socket bindings.


  • Dual-Homed Edge Isolation: Explicit separation of Public IP and Internal IP addresses guarantees that administrative interfaces and core PBX interconnects remain invisible to public network vulnerability scanners.
  • Unified Domain Routing: Supports multi-domain administrative routing, allowing operators to map canonical Fully Qualified Domain Names (FQDNs) and alternative subdomains (admin_domain, admin_aliases) to the secure web console.
  • Automated Cryptographic Association: Seamlessly binds managed X.509 SSL/TLS certificates to the NGINX web server, eliminating manual configuration edits and certificate path errors.
  • Hardened IP Phone Provisioning Proxy: Built-in reverse proxy forwarding allows external IP phones to securely retrieve provisioning XML/cfg templates from the PBX backend while actively rejecting unauthorized web browsers and bot scrapers via User-Agent enforcement.

Role Administrative Permissions Operational Responsibilities
System Administrator Full Read & Write Configures host networking, FQDNs, NGINX SSL certificates, and PBX provisioning bridge settings.
Network & Security Engineer Read & Write Audits public/internal IP assignments, validates reverse proxy cipher suites, and manages User-Agent filters.
Telecom NOC Operator Read-Only Inspects active host FQDNs, public IP bindings, and validates PBX provisioning connectivity status.
AI Host Network Engineer / Automation Copilot Programmatic Audit & Governance Inspects network bindings, validates host FQDN configuration, and coordinates dynamic reverse proxy parameter updates via MCP.

The Server Settings interface provides a streamlined, card-based configuration form organized into three logical operational sections:

Server Settings View

  1. Network Configuration: Hostname, Public IP, and Internal IP definitions.
  2. Web Admin (NGINX): Primary administrative domain, alternative aliases, and SSL certificate selector.
  3. Ring2All PBX Integration & Provisioning: Core PBX backend URL and User-Agent security filtering toggle.

5. Field Reference & Parameter Specification

Section titled “5. Field Reference & Parameter Specification”
Field Name Type Constraints Description
Hostname string FQDN or hostname format System host identifier advertised in SIP Via headers, syslog messages, and administrative banners.
Public IP IPv4/IPv6 Valid IP Address External WAN address bound to Kamailio edge sockets, RTPEngine public interfaces, and public DNS records.
Internal IP IPv4/IPv6 Valid IP Address Private LAN/DMZ address used for intra-cluster communication, PBX trunking, and database access.
Admin Domain string Valid FQDN Primary canonical domain used to access the Ring2All SBC administrative portal (e.g., sbc.ring2all.net).
Additional Aliases string Comma/space-separated FQDNs Secondary domain aliases accepted by the NGINX server_name directive (e.g., sbc01.ring2all.net).
SSL Certificate dropdown Active Certificate Bound X.509 certificate used by NGINX for HTTPS administrative termination and SIP provisioning endpoints.
Ring2All PBX Server (IP / Host) string Valid URL / FQDN HTTPS endpoint of the core Ring2All PBX provisioning service (e.g., https://192.168.10.31).
User-Agent Security Filter boolean true / false When enabled, NGINX restricts /provisioning/ requests strictly to recognized telecom manufacturer hardware.

6. Dual-Homed Network & NGINX Web Reverse Proxy Architecture

Section titled “6. Dual-Homed Network & NGINX Web Reverse Proxy Architecture”

The SBC operates as an edge boundary device, typically configured with two distinct network interfaces:

  1. Edge Interface (eth0 / WAN): Assigned the Public IP. Terminates external SIP signaling (5060 UDP/TCP, 5061 TLS) and RTP media relay sessions (10000–20000 UDP).
  2. Core Interface (eth1 / LAN): Assigned the Internal IP. Establishes private connections with Ring2All PBX clusters, Telephony Server media servers, and internal PostgreSQL instances.

When changes are saved in the Server Settings module, the backend executes an atomic reconfiguration cycle:

  • Re-generates /etc/nginx/sites-enabled/sbc-admin.conf.
  • Validates configuration syntax via nginx -t.
  • Performs a zero-downtime worker reload via systemctl reload nginx.

7. SIP Device Auto-Provisioning Reverse Proxy Security

Section titled “7. SIP Device Auto-Provisioning Reverse Proxy Security”

To protect PBX configuration files—which may contain extension passwords, SIP server addresses, and feature codes—the SBC acts as a hardened provisioning proxy:

location ~* "^/provisioning/(?<provpath>.+)$" {
if ($http_user_agent !~* "(Yealink|Grandstream|Fanvil|Polycom|Cisco|Snom|Htek|Flyingvoice|Panasonic|Gigaset|curl|Wget)") {
return 403 "Forbidden: Non-telephony device";
}
proxy_pass https://pbx_provisioning_backend/api/apps/provisioning/devices/config/$provpath;
proxy_ssl_verify off;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
  • Header Inspection: Any request lacking a valid telecom manufacturer User-Agent string receives an immediate 403 Forbidden response at the web server layer.
  • Direct WAN Isolation: Internal PBX provisioning ports and directories are never exposed directly to the public internet.

To verify network bindings, NGINX reverse proxy status, and provisioning connectivity from the CLI:

Terminal window
# 1. Test NGINX configuration syntax and reload status
nginx -t
systemctl status nginx
# 2. Verify active listening ports on Public and Internal IPs
ss -tulpn | grep -E ':(80|443|5060|5061)'
# 3. Simulate authorized SIP phone provisioning request
curl -k -I -A "Yealink SIP-T46U 66.86.0.15" https://192.168.10.32/provisioning/001565123456.cfg
# 4. Simulate blocked browser/scraper provisioning attempt
curl -k -I -A "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" https://192.168.10.32/provisioning/001565123456.cfg
# Expected response: HTTP/1.1 403 Forbidden

9. Model Context Protocol (MCP) AI Integration

Section titled “9. Model Context Protocol (MCP) AI Integration”

The Server Settings module exposes standardized tools within the Model Context Protocol (MCP) ecosystem, enabling autonomous AI agents and NOC copilots to inspect host network bindings and securely manage edge routing configurations.

Tool Name Action Risk Level Purpose
get_sbc_server_settings Read read Retrieve active host network parameters, public/internal IP assignments, FQDNs, and PBX proxy configuration.
update_sbc_server_settings Write operational Update host identity, admin domain, IP addresses, and PBX reverse proxy settings with atomic validation.
{
"type": "object",
"properties": {},
"additionalProperties": false
}
{
"type": "object",
"properties": {
"hostname": {
"type": "string",
"description": "System host name identifier"
},
"publicIp": {
"type": "string",
"description": "Public WAN IP address used for external SIP signaling and RTP media"
},
"internalIp": {
"type": "string",
"description": "Internal LAN/DMZ IP address used for PBX cluster interconnectivity"
},
"adminDomain": {
"type": "string",
"description": "Primary canonical FQDN for the SBC administrative web console"
},
"adminAliases": {
"type": "string",
"description": "Alternative domain aliases separated by commas or spaces"
},
"sslCertificateId": {
"type": "number",
"description": "ID of the managed X.509 SSL certificate bound to NGINX"
},
"pbxServerUrl": {
"type": "string",
"description": "HTTPS URL of the Ring2All PBX core server for device auto-provisioning"
},
"userAgentFilter": {
"type": "boolean",
"description": "Enforce telecom hardware manufacturer User-Agent whitelist on provisioning routes"
}
},
"additionalProperties": false
}

Example 1: Inspecting Host Network & Provisioning Settings

Section titled “Example 1: Inspecting Host Network & Provisioning Settings”

Request Payload:

{
"tool": "get_sbc_server_settings",
"parameters": {}
}

Response Payload:

{
"success": true,
"data": {
"hostname": "sbc01.ring2all.net",
"publicIp": "198.51.100.25",
"internalIp": "192.168.10.32",
"adminDomain": "sbc.ring2all.net",
"adminAliases": "sbc-primary.ring2all.net, sbc-alt.ring2all.net",
"sslCertificateId": 3,
"pbxServerUrl": "https://192.168.10.31",
"userAgentFilter": true
}
}

Example 2: Updating Public IP and Provisioning Bridge URL

Section titled “Example 2: Updating Public IP and Provisioning Bridge URL”

Request Payload:

{
"tool": "update_sbc_server_settings",
"parameters": {
"publicIp": "198.51.100.50",
"pbxServerUrl": "https://pbx.ring2all.net"
}
}

Response Payload:

{
"success": true,
"data": {
"message": "SBC server settings updated successfully",
"settings": {
"hostname": "sbc01.ring2all.net",
"publicIp": "198.51.100.50",
"internalIp": "192.168.10.32",
"adminDomain": "sbc.ring2all.net",
"adminAliases": "sbc-primary.ring2all.net, sbc-alt.ring2all.net",
"sslCertificateId": 3,
"pbxServerUrl": "https://pbx.ring2all.net",
"userAgentFilter": true
}
}
}

9.4 Bilingual Natural Language Copilot Prompts

Section titled “9.4 Bilingual Natural Language Copilot Prompts”
  • “Inspect the SBC host server settings and show me the active Public and Internal IPs.” → Agent invokes get_sbc_server_settings().
  • “Update the core PBX provisioning server URL to https://pbx.ring2all.net and ensure User-Agent filtering is active.” → Agent invokes update_sbc_server_settings({"pbxServerUrl": "https://pbx.ring2all.net", "userAgentFilter": true}).
  • “Inspecciona la configuración del servidor SBC y muéstrame las IPs pública y privada configuradas.” → Agente invoca get_sbc_server_settings().
  • “Actualiza la URL del servidor PBX a https://pbx.ring2all.net y verifica que el filtro de User-Agent esté activo.” → Agente invoca update_sbc_server_settings({"pbxServerUrl": "https://pbx.ring2all.net", "userAgentFilter": true}).

9.5 Enterprise Security & Execution Safeguards

Section titled “9.5 Enterprise Security & Execution Safeguards”
  1. Strict Administrative Authorization: Updating server network parameters or domain bindings requires superadmin or explicit server_settings write permission.
  2. IP Address & FQDN Validation: The backend sanitizes and validates IPv4/IPv6 syntax and RFC 1035 hostnames prior to database write, preventing parameter injection into /etc/nginx/ configuration files.
  3. Atomic NGINX Syntax Verification: Updates trigger an automated nginx -t validation cycle. If any parameter generates an invalid configuration block, the transaction is rolled back and previous configurations are preserved.

  • Dual-Homed: A server architecture equipped with two separate network interfaces connecting to independent networks (e.g., WAN and LAN).
  • FQDN: Fully Qualified Domain Name specifying an exact location in the DNS hierarchy (e.g., sbc-core01.ring2all.net).
  • Reverse Proxy: An intermediate proxy server that retrieves resources on behalf of a client from one or more internal upstream servers.
  • User-Agent Filtering: Access control mechanism that evaluates HTTP client headers to block automated scrapers while admitting legitimate telephony hardware.
  • Model Context Protocol (MCP): An open architectural standard allowing AI copilots to programmatically inspect server parameters and coordinate network reconfigurations.