Atlas Knowledge Base
Dashboard
Firewall

Firewall

The SBN Media firewall - a shared filter the externally-facing services use to allow or reject connections by IP address and country.

configuration
country
firewall
ip-filtering
sbn-media
security

Firewall

The firewall is a built-in filter that the externally-facing SBN Media services apply to the connections they receive. It can allow or reject traffic by IP address and by country, so you can limit who is able to reach SBN Media from outside.

Overview

The firewall is not a separate service. It is built into the services that are exposed to outside networks - the API Proxy, the TURN server, the SIP server and SIP proxy, and the MLR2 frontend - and each of them checks incoming connections against it. They all share one set of rules, so you configure the firewall once and every one of those services applies it.

It is off by default. A connection is decided in this order:

  1. If the firewall is off, the connection is allowed.
  2. If the source address is on the IP allow list, it is always allowed.
  3. If country filtering is set and the source is from a country that is not permitted, it is rejected.
  4. If the source address is on the IP reject list, or has been reported for abuse, it is rejected.
  5. Otherwise the connection is allowed.

To find the country of an address the firewall uses a built-in IP-location database, which refreshes itself daily - no external service is needed for country filtering. An abuse database can optionally be used to reject addresses with a bad reputation.

  1. Applies to: The externally-facing services listed above. Internal-only services are not affected.
  2. Required: No. The firewall is optional and off by default; turn it on when you want to restrict who can reach SBN Media.
  3. Depends on: The built-in IP-location database (included). The optional abuse database needs a key.

Configuration

The firewall is configured under the firewall namespace. View the defaults with ./sbn-media config eject and set the rules in sbn-media.local.yaml. The same rules apply to every service that uses the firewall.


Setting

Default

Description

firewall.enabled

false

Turns the firewall on or off.

firewall.ip.allow

empty

Addresses that are always allowed, whatever the other rules say.

firewall.ip.reject

empty

Addresses that are always rejected.

firewall.country.allow

empty

If set, only these countries are allowed and all others are rejected.

firewall.country.reject

empty

Used only when there is no allow list - these countries are rejected and all others allowed.

firewall.abusedbapikey

empty

Optional key for an abuse database, used to reject addresses with a bad reputation.

Country codes are two letters (for example dk, gb, us). If you set firewall.country.allow, the reject list is ignored - only the allowed countries get through.

Example:

firewall:
enabled: true

# Only allow these countries; everything else is rejected.
country:
allow:
- dk
- gb

ip:
# Always allow these addresses (for example your own offices).
allow:
- "203.0.113.10"
# Always reject these addresses.
reject:
- "198.51.100.7"

The country rules can be reloaded while the services are running. Turning the firewall on or off, and changing the IP allow and reject lists, take effect when the service is restarted.

FAQ

Is the firewall on by default?

No. It is off by default, so nothing is filtered until you set firewall.enabled to true. When you turn it on, every externally-facing service starts applying the rules.

Which services does the firewall protect?

The services that are reachable from outside networks: the API Proxy, the TURN server, the SIP server and SIP proxy, and the MLR2 frontend. They all share the one set of firewall rules.

A legitimate user is being rejected. What should I do?

Add their address to firewall.ip.allow, which always allows it. If you are using firewall.country.allow, remember that any country not on that list is rejected, so add the country they connect from. Turn on the service logs to see the rejections - a blocked connection is logged with its source address.

How does the firewall know the country of an address?

It uses a built-in IP-location database that refreshes itself once a day, so country filtering works without any external service. The abuse database is separate and optional, and is only used if you provide a key.

Related pages

  1. SBN Media Overview (SBN-Media/overview)
  2. Installing and Configuring SBN Media (SBN-Media/installation)
  3. API Proxy (SBN-Media/Platform/api-proxy)
  4. TURN Server (SBN-Media/Telephony/turn-server)




Was this helpful?