SBC

SBC Manager — Firewall Management

The SBC is the first — and only — VoIP system directly exposed to the internet; its security perimeter protects the PBX and internal extensions behind it. The PBX should never be reachable from outside the private network: all external SIP must go through the SBC.

The SBC Manager firewall controls which IP addresses can reach the management interface, SIP ports, and RTP range. Go to Settings → Firewall to view and manage rules.

Management Access

Add the specific IP addresses that should reach the web GUI and SSH to the management allowlist, rather than opening broad network ranges. Management rules are separate from SIP/RTP rules.

SIP Port Protection

SIP signaling ports (5060/5061) are automatically restricted to the IP addresses of enabled trunks: when you apply configuration, the firewall's SIP allowlist is synchronized with the trunk inventory, so only your configured carriers and peers can send SIP to the appliance. Disabling or deleting a trunk removes its addresses at the next apply.

This automatic allowlist is the front line against SIP scanners and registration attacks — traffic from unknown sources is dropped before it ever reaches Asterisk.

HA Deployments

On HA pairs, web, SSH, and SIP firewall rules are mirrored to the peer node automatically so both nodes remain equally reachable.

Verifying

Use Diagnostics → Packet Capture on the SIP interface to confirm expected traffic is arriving, and check the firewall page's rule listing to confirm a carrier's IPs are present after enabling its trunk.