# FreePBX Responsive Firewall vs Intrusion Detection (FreePBX 17)

Source: https://srvscripts.com/guides/freepbx-responsive-firewall-intrusion-detection/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Both live in the FreePBX Firewall module but do different jobs. **Responsive Firewall** is an iptables rate limiter for SIP and IAX from unknown sources: a new client gets a few packets to register, and is dropped for 60 seconds if it does not. **Intrusion Detection** is fail2ban: it reads log files and bans IPs after repeated failures. On FreePBX 17 the Firewall module depends on the commercial System Admin module, so an open-source-only install has neither GUI feature; you get a plain fail2ban config and must add your own firewall.

We checked this on our lab server (Debian 12, FreePBX 17.0.33 installed open-source only, Asterisk 22.11) on 6 October 2026: the module list, the install script and the fail2ban setup. Responsive Firewall behaviour and limits are taken from Sangoma’s documentation (linked below) because the module is not present on that lab.

## Responsive Firewall: what it does

Normally the FreePBX Firewall is deny-by-default: SIP from the **Internet** zone is blocked unless the source is a known trunk or a network you placed in a trusted zone. That breaks remote and mobile phones on changing IPs. Responsive Firewall is the compromise. According to Sangoma’s Responsive Firewall page:

- An unknown host may send **10 signalling packets**. If it has not registered successfully by then, all its signalling is dropped for **60 seconds**.

- A host that registers successfully is treated as a known device and no longer passes through the rate limiter.

- A second block triggers after **50 or more failed registration or call attempts within 24 hours**, or **50 or more packets in under 10 seconds**. That block stays until the host has sent no packets at all for 24 hours.

- It only blocks the port under attack, so a phone pointed at the wrong SIP driver port does not lose access to everything.

It works at the packet level, before Asterisk sees the request. That is its strength: it stops floods cheaply. It is also why it can be confusing: a phone that fails a few registrations (wrong password, wrong port) gets dropped for a minute and looks “offline” while you troubleshoot.

## Intrusion Detection: what it does

Intrusion Detection is fail2ban with a FreePBX settings page. Since FreePBX moved it from System Admin into the Firewall module, the page manages the usual fail2ban values:

- **Ban Time:** how long an IP stays banned.

- **Max Retry:** failures allowed before a ban.

- **Find Time:** the window in which failures are counted.

- **Whitelist:** addresses never banned, with an option to sync firewall zones into it automatically and to import IPs of registered extensions.

fail2ban reacts to what Asterisk and FreePBX log: failed SIP authentication, requests for unknown endpoints, failed GUI logins. It is slower than Responsive Firewall (it needs log lines first) but understands application-level failures and keeps longer memory.

## Side by side

|  | Responsive Firewall | Intrusion Detection |
| --- | --- | --- |
| Technology | iptables rate limiting in the Firewall module | fail2ban reading log files |
| Acts on | SIP/IAX signalling packets from unknown hosts | Log lines: SIP auth failures, GUI login failures, SSH |
| Speed | Immediate, per packet | After log lines are written and parsed |
| Default block | 60 s after 10 packets without registering; longer block after 50 failures/24 h | Ban Time setting (our lab jail.local: 1800 s) |
| Good at | Floods and scanners hitting an open SIP port | Password guessing over time; GUI and SSH brute force |
| Main risk | Legitimate phones briefly blocked while misconfigured | Banning your own office NAT IP after a bad password |
| Needs | Firewall module (needs commercial System Admin) | fail2ban; GUI page needs Firewall module |

They complement each other. Sangoma’s own security post recommends a deny-by-default firewall and suggests Responsive Firewall only when you really must accept VoIP from unknown sources; Intrusion Detection runs alongside as a second layer.

## The FreePBX 17 catch: open-source-only installs

On FreePBX 17, the Firewall module requires the System Admin module, and System Admin is a Sangoma commercial module (commercial modules need the ionCube loader). The official install script makes this explicit. Its `--opensourceonly` option runs:

```
# Check if only opensource required then remove the commercial modules
if [ "$opensourceonly" ]; then
  setCurrentStep "Removing commercial modules"
  fwconsole ma list | awk '/Commercial/ {print $2}' | xargs -t -I {} fwconsole ma -f remove {} >> "$log"
  # Remove firewall module also because it depends on commercial sysadmin module
  fwconsole ma -f remove firewall >> "$log" || true
fi
```

It then purges the `sysadmin17` helper package and the ionCube loader. On our open-source-only lab, a search of the module list finds neither module:

```
fwconsole ma list | grep -iE "firewall|sysadmin"
# (no output on our open-source-only install)
```

So there is no Firewall menu, no Responsive Firewall and no Intrusion Detection page. What you do get is a fail2ban configuration file installed by the `sangoma-pbx17` package:

```
dpkg -S /etc/fail2ban/jail.local
sangoma-pbx17: /etc/fail2ban/jail.local
```

Its header still says it is generated by the sysadmin module and should not be edited, and it defines jails including `asterisk-iptables` (reading `/var/log/asterisk/fail2ban`, maxretry 5, bantime 1800) and `pbx-gui` (reading `/var/log/asterisk/freepbx_security.log`).

On our lab, the `asterisk-iptables` jail was watching `/var/log/asterisk/fail2ban`, but Asterisk was not writing that file: `logger show channels` listed only `/var/log/asterisk/full`, so the jail counted 0 failures while the full log had 24 “No matching endpoint” lines. Check yours before trusting it.

## Open-source-only: get the same protection

Without the commercial modules, build the two layers yourself.

### 1. Make fail2ban actually see SIP failures

Add a logger channel for the file the jail reads. On FreePBX, use the custom logger file so a reload does not overwrite it. This is the line we added on lab3:

```
echo "fail2ban => notice,security" >> /etc/asterisk/logger_logfiles_custom.conf
asterisk -rx "logger reload"
asterisk -rx "logger show channels"
```

```
/var/log/asterisk/fail2ban          File     default    Enabled    - NOTICE SECURITY
/var/log/asterisk/full              File     default    Enabled    - DEBUG NOTICE WARNING ERROR VERBOSE
```

After that, the jail started counting failures and banned a scanning IP within minutes:

```
fail2ban-client status asterisk-iptables
Status for the jail: asterisk-iptables
|- Filter
|  |- Currently failed:	0
|  |- Total failed:	22
|  `- File list:	/var/log/asterisk/fail2ban
`- Actions
   |- Currently banned:	0
   |- Total banned:	2
   `- Banned IP list:
```

Our [fail2ban for Asterisk and FreePBX guide](/guides/fail2ban-asterisk-freepbx/) covers filters, whitelisting and testing in depth, and the [AI fail2ban regex generator](/tools/ai-fail2ban-regex-generator/) helps with custom log lines.

### 2. Replace the zone firewall

Responsive Firewall’s real value is that SIP is closed to the world by default. Recreate that with nftables, firewalld or your cloud provider’s security groups: allow SIP (5060/udp and any TLS port) only from your providers’ signalling IPs and your office networks, allow RTP (10000-20000/udp on FreePBX) more widely, and restrict the web GUI to admin networks or a VPN. Our [SIP firewall rules generator](/tools/voip-firewall-generator/) writes these rules for iptables, nftables, UFW, firewalld, CSF and pfSense, and [SIP ports firewall rules](/guides/sip-ports-firewall/) explains the port list.

If you have roaming phones on unknown IPs, prefer a VPN or SIP over TLS on a non-standard port over opening 5060 to the internet.

## Check that it worked and common problems

- `fail2ban-client status` lists the jails; `fail2ban-client status asterisk-iptables` should show a growing “Total failed” on an internet-facing server.

- `asterisk -rx "pjsip show unidentified_requests"` shows sources hitting PJSIP without matching an endpoint; these should get banned.

- **Office phones all go offline at once:** your office NAT IP was banned (Intrusion Detection) or rate-limited (Responsive Firewall) after one phone had a bad password. Whitelist office networks or put them in a trusted zone.

- **Remote phone works, then fails for a minute:** classic Responsive Firewall behaviour when the phone fails to register within its first packets. Fix the credentials or port; add a stable remote IP to a trusted zone.

- **fail2ban shows 0 failures on a busy server:** the jail’s log file is not being written. Check `logger show channels`.

- **Firewall menu missing on FreePBX 17:** the install was open source only, or System Admin is not installed and activated.

**Official documentation:** [Sangoma: Responsive Firewall](https://sangomakb.atlassian.net/wiki/spaces/PG/pages/26181896/Responsive+Firewall) · [Sangoma: Firewall module](https://sangomakb.atlassian.net/wiki/spaces/PG/pages/26181828/Firewall) · [FreePBX: Intrusion Detection features](https://www.freepbx.org/?p=51311) · [FreePBX 17 install script](https://github.com/FreePBX/sng_freepbx_debian_install)

**Related:** [fail2ban for Asterisk and FreePBX: Block SIP Password Guessing](/guides/fail2ban-asterisk-freepbx/) · [SIP Firewall Rules Generator: iptables, nftables, UFW, firewalld, CSF and pfSense](/tools/voip-firewall-generator/) · [SIP Ports Firewall Rules: 4 Setups for CSF, firewalld and pfSense](/guides/sip-ports-firewall/) · [AI fail2ban Regex Generator: Filters and Jails from Log Lines](/tools/ai-fail2ban-regex-generator/) · [Replace CSF with firewalld and fail2ban: Secure Step-by-Step](/guides/replace-csf-with-firewalld-fail2ban/)

**See also:** [Upgrade FreePBX 16 to 17: Backup, Restore and Migration Checklist](/guides/upgrade-freepbx-16-to-17/) · [Install FreePBX 17 on Debian 12 (Open-Source Only, Tested)](/guides/install-freepbx-17-debian-12/) · [Asterisk and FreePBX Toll Fraud Prevention: 10-Point Checklist](/guides/asterisk-freepbx-toll-fraud-prevention/) · [3CX vs FreePBX: Licensing, Hosting, Features and Lock-in (2026)](/guides/3cx-vs-freepbx/)

## Frequently asked questions

### What is the difference between Responsive Firewall and Intrusion Detection?

Responsive Firewall rate-limits SIP and IAX packets from unknown hosts in iptables. Intrusion Detection is fail2ban, which bans IPs after repeated failures found in log files.

### Should I enable Responsive Firewall?

Only if you must accept SIP from unknown IPs, such as roaming phones. Otherwise keep SIP limited to known networks and providers, and run Intrusion Detection as well.

### Why is there no Firewall menu on my FreePBX 17?

The Firewall module depends on the commercial System Admin module. The install script’s –opensourceonly option removes both.

### Does fail2ban work on an open-source-only FreePBX 17?

The sangoma-pbx17 package installs a jail.local, but on our lab Asterisk was not writing the log file the SIP jail reads. Add a fail2ban logger channel and confirm failures are counted.

### My own phones keep getting blocked. What do I do?

Fix the failing device first, then whitelist your office networks in Intrusion Detection or place them in a trusted firewall zone.
