Emergency server help: get in touch

FreePBX Responsive Firewall vs Intrusion Detection (FreePBX 17)

FreePBX Responsive Firewall vs Intrusion Detection explained, why both are missing on open-source-only FreePBX 17, and how to rebuild the protection with fail2ban and your own firewall.

Published 8 min read

Short answer: Both live in the FreePBX Firewall module but do different jobs. Responsive Firewall is an iptables rate limiter for SIP and IAX from unknown sources: a new client gets a few packets to register, and is dropped for 60 seconds if it does not. Intrusion Detection is fail2ban: it reads log files and bans IPs after repeated failures. On FreePBX 17 the Firewall module depends on the commercial System Admin module, so an open-source-only install has neither GUI feature; you get a plain fail2ban config and must add your own firewall.

Applies to FreePBX 17 (open-source only); tested on FreePBX 17.0.33 with Asterisk 22.11 on Debian 12

We checked this on our lab server (Debian 12, FreePBX 17.0.33 installed open-source only, Asterisk 22.11) on 6 October 2026: the module list, the install script and the fail2ban setup. Responsive Firewall behaviour and limits are taken from Sangoma’s documentation (linked below) because the module is not present on that lab.

Responsive Firewall: what it does

Normally the FreePBX Firewall is deny-by-default: SIP from the Internet zone is blocked unless the source is a known trunk or a network you placed in a trusted zone. That breaks remote and mobile phones on changing IPs. Responsive Firewall is the compromise. According to Sangoma’s Responsive Firewall page:

  • An unknown host may send 10 signalling packets. If it has not registered successfully by then, all its signalling is dropped for 60 seconds.
  • A host that registers successfully is treated as a known device and no longer passes through the rate limiter.
  • A second block triggers after 50 or more failed registration or call attempts within 24 hours, or 50 or more packets in under 10 seconds. That block stays until the host has sent no packets at all for 24 hours.
  • It only blocks the port under attack, so a phone pointed at the wrong SIP driver port does not lose access to everything.

It works at the packet level, before Asterisk sees the request. That is its strength: it stops floods cheaply. It is also why it can be confusing: a phone that fails a few registrations (wrong password, wrong port) gets dropped for a minute and looks “offline” while you troubleshoot.

Intrusion Detection: what it does

Intrusion Detection is fail2ban with a FreePBX settings page. Since FreePBX moved it from System Admin into the Firewall module, the page manages the usual fail2ban values:

  • Ban Time: how long an IP stays banned.
  • Max Retry: failures allowed before a ban.
  • Find Time: the window in which failures are counted.
  • Whitelist: addresses never banned, with an option to sync firewall zones into it automatically and to import IPs of registered extensions.

fail2ban reacts to what Asterisk and FreePBX log: failed SIP authentication, requests for unknown endpoints, failed GUI logins. It is slower than Responsive Firewall (it needs log lines first) but understands application-level failures and keeps longer memory.

Side by side

Responsive FirewallIntrusion Detection
Technologyiptables rate limiting in the Firewall modulefail2ban reading log files
Acts onSIP/IAX signalling packets from unknown hostsLog lines: SIP auth failures, GUI login failures, SSH
SpeedImmediate, per packetAfter log lines are written and parsed
Default block60 s after 10 packets without registering; longer block after 50 failures/24 hBan Time setting (our lab jail.local: 1800 s)
Good atFloods and scanners hitting an open SIP portPassword guessing over time; GUI and SSH brute force
Main riskLegitimate phones briefly blocked while misconfiguredBanning your own office NAT IP after a bad password
NeedsFirewall module (needs commercial System Admin)fail2ban; GUI page needs Firewall module

They complement each other. Sangoma’s own security post recommends a deny-by-default firewall and suggests Responsive Firewall only when you really must accept VoIP from unknown sources; Intrusion Detection runs alongside as a second layer.

The FreePBX 17 catch: open-source-only installs

On FreePBX 17, the Firewall module requires the System Admin module, and System Admin is a Sangoma commercial module (commercial modules need the ionCube loader). The official install script makes this explicit. Its --opensourceonly option runs:

# Check if only opensource required then remove the commercial modules
if [ "$opensourceonly" ]; then
  setCurrentStep "Removing commercial modules"
  fwconsole ma list | awk '/Commercial/ {print $2}' | xargs -t -I {} fwconsole ma -f remove {} >> "$log"
  # Remove firewall module also because it depends on commercial sysadmin module
  fwconsole ma -f remove firewall >> "$log" || true
fi

It then purges the sysadmin17 helper package and the ionCube loader. On our open-source-only lab, a search of the module list finds neither module:

fwconsole ma list | grep -iE "firewall|sysadmin"
# (no output on our open-source-only install)

So there is no Firewall menu, no Responsive Firewall and no Intrusion Detection page. What you do get is a fail2ban configuration file installed by the sangoma-pbx17 package:

dpkg -S /etc/fail2ban/jail.local
sangoma-pbx17: /etc/fail2ban/jail.local

Its header still says it is generated by the sysadmin module and should not be edited, and it defines jails including asterisk-iptables (reading /var/log/asterisk/fail2ban, maxretry 5, bantime 1800) and pbx-gui (reading /var/log/asterisk/freepbx_security.log).

On our lab, the asterisk-iptables jail was watching /var/log/asterisk/fail2ban, but Asterisk was not writing that file: logger show channels listed only /var/log/asterisk/full, so the jail counted 0 failures while the full log had 24 “No matching endpoint” lines. Check yours before trusting it.

Open-source-only: get the same protection

Without the commercial modules, build the two layers yourself.

1. Make fail2ban actually see SIP failures

Add a logger channel for the file the jail reads. On FreePBX, use the custom logger file so a reload does not overwrite it. This is the line we added on lab3:

echo "fail2ban => notice,security" >> /etc/asterisk/logger_logfiles_custom.conf
asterisk -rx "logger reload"
asterisk -rx "logger show channels"
/var/log/asterisk/fail2ban          File     default    Enabled    - NOTICE SECURITY
/var/log/asterisk/full              File     default    Enabled    - DEBUG NOTICE WARNING ERROR VERBOSE

After that, the jail started counting failures and banned a scanning IP within minutes:

fail2ban-client status asterisk-iptables
Status for the jail: asterisk-iptables
|- Filter
|  |- Currently failed:	0
|  |- Total failed:	22
|  `- File list:	/var/log/asterisk/fail2ban
`- Actions
   |- Currently banned:	0
   |- Total banned:	2
   `- Banned IP list:

Our fail2ban for Asterisk and FreePBX guide covers filters, whitelisting and testing in depth, and the AI fail2ban regex generator helps with custom log lines.

2. Replace the zone firewall

Responsive Firewall’s real value is that SIP is closed to the world by default. Recreate that with nftables, firewalld or your cloud provider’s security groups: allow SIP (5060/udp and any TLS port) only from your providers’ signalling IPs and your office networks, allow RTP (10000-20000/udp on FreePBX) more widely, and restrict the web GUI to admin networks or a VPN. Our SIP firewall rules generator writes these rules for iptables, nftables, UFW, firewalld, CSF and pfSense, and SIP ports firewall rules explains the port list.

If you have roaming phones on unknown IPs, prefer a VPN or SIP over TLS on a non-standard port over opening 5060 to the internet.

Check that it worked and common problems

  • fail2ban-client status lists the jails; fail2ban-client status asterisk-iptables should show a growing “Total failed” on an internet-facing server.
  • asterisk -rx "pjsip show unidentified_requests" shows sources hitting PJSIP without matching an endpoint; these should get banned.
  • Office phones all go offline at once: your office NAT IP was banned (Intrusion Detection) or rate-limited (Responsive Firewall) after one phone had a bad password. Whitelist office networks or put them in a trusted zone.
  • Remote phone works, then fails for a minute: classic Responsive Firewall behaviour when the phone fails to register within its first packets. Fix the credentials or port; add a stable remote IP to a trusted zone.
  • fail2ban shows 0 failures on a busy server: the jail’s log file is not being written. Check logger show channels.
  • Firewall menu missing on FreePBX 17: the install was open source only, or System Admin is not installed and activated.

Official documentation: Sangoma: Responsive Firewall · Sangoma: Firewall module · FreePBX: Intrusion Detection features · FreePBX 17 install script

Related: fail2ban for Asterisk and FreePBX: Block SIP Password Guessing · SIP Firewall Rules Generator: iptables, nftables, UFW, firewalld, CSF and pfSense · SIP Ports Firewall Rules: 4 Setups for CSF, firewalld and pfSense · AI fail2ban Regex Generator: Filters and Jails from Log Lines · Replace CSF with firewalld and fail2ban: Secure Step-by-Step

See also: Upgrade FreePBX 16 to 17: Backup, Restore and Migration Checklist · Install FreePBX 17 on Debian 12 (Open-Source Only, Tested) · Asterisk and FreePBX Toll Fraud Prevention: 10-Point Checklist · 3CX vs FreePBX: Licensing, Hosting, Features and Lock-in (2026)

Frequently asked questions

What is the difference between Responsive Firewall and Intrusion Detection?

Responsive Firewall rate-limits SIP and IAX packets from unknown hosts in iptables. Intrusion Detection is fail2ban, which bans IPs after repeated failures found in log files.

Should I enable Responsive Firewall?

Only if you must accept SIP from unknown IPs, such as roaming phones. Otherwise keep SIP limited to known networks and providers, and run Intrusion Detection as well.

Why is there no Firewall menu on my FreePBX 17?

The Firewall module depends on the commercial System Admin module. The install script’s –opensourceonly option removes both.

Does fail2ban work on an open-source-only FreePBX 17?

The sangoma-pbx17 package installs a jail.local, but on our lab Asterisk was not writing the log file the SIP jail reads. Add a fail2ban logger channel and confirm failures are counted.

My own phones keep getting blocked. What do I do?

Fix the failing device first, then whitelist your office networks in Intrusion Detection or place them in a trusted firewall zone.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
FreePBX 17 (open-source only); tested on FreePBX 17.0.33 with Asterisk 22.11 on Debian 12
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.