VICIfast
Feature · VICIfast Firewall

VICIfast Firewall.

Your VICIdial server starts closed. Agents, carriers and admins each get exactly the ports they need, from addresses you allow - set in the dashboard, on the box within seconds. Agents whose IP changes let themselves back in from a portal on your own domain, while a 100,000-entry blocklist and country rules keep everyone else out.
See pricing

7-day free trial · Cancel anytime · Pay with card or USDT

vicifast - firewall
# How the VICIfast Firewall decides - first match wins
 1  VICIfast platform addresses    allow  all ports
 2  Call audio + backup portal     allow  udp 10000-30000, tcp 446
 3  Your allow rules, by profile   allow  agent / carrier / admin ports
 4  Your block rules               drop   all ports
 5  Managed blocklist (104,872)    drop   SIP + webphone ports
 6  Blocked countries              drop   all ports
 7  Scheduled country allow        allow  tcp 443 + 8089
    Everything else                drop

How it decides

Closed by default. Seven rules, in a fixed order.

A new VICIfast server refuses every incoming connection it has not been told to accept. The firewall checks seven tiers from the top, and the first one that matches decides. The same order is explained in plain English inside the dashboard, so nobody has to guess why an address got in or didn't.

TierWhat it coversDecisionPorts
1VICIfast platform addresses, so your rules, backups and updates reach the boxAllowAll
2Call audio, and the backup agent portalAllowUDP 10000-30000, TCP 446
3Your allow rules, by access profileAllowThe profile's ports
4Your block rulesDropAll
5Managed blocklistDropSIP 5060, 5061, 5070 and webphone 8089
6Blocked countriesDropAll
7Scheduled country allowAllowTCP 443 and 8089
-Everything elseDropAll
The VICIfast Firewall instructions dialog explaining, in plain English, which rule wins
The Instructions dialog in the dashboard walks through the same order.

Allow beats block

Your allow rules sit above every blocklist and every blocked country. An address you let in is never caught by a list you didn't write.

Calls keep their sound

Call audio sits above every block rule, so tightening the firewall never cuts the audio of a call in progress.

Deny can't be switched off

There is no setting that opens the server to everyone. Everything the dashboard adds is an address you named or a country you chose, on a schedule you set.

Who gets in, and to what

Every address gets a profile, not the keys to everything.

When you allow an address you say what it is for, and the profile decides the ports. A carrier reaches SIP and nothing else. SSH stays shut to everyone except the people you trust with it.

AgentYour floor.

VICIdial web pages - TCP 443 · SIP - UDP 5060 and 5070 · Webphone - TCP 8089

CarrierYour SIP provider's signalling addresses.

SIP - UDP 5060, and nothing else

AdminYou, your supervisors and your IT.

Everything an agent gets · SSH - TCP 22 · The server's private admin port

The Add rule dialog: an IP address, the Admin access profile, a 48-hour expiry, a reason and an optional weekday schedule in a chosen time zone
Adding a rule: one address, a profile, how long it lasts, why - and, if you want, only during set hours.
The Firewall Rules tab listing allow rules with Agent, Carrier and Admin profiles, an expiring rule, agent self-serve rules, an automatic carrier rule, a block rule and a scheduled country allow for the Philippines
The Firewall Rules tab: every address, its profile, its reason and when it ends.

Allow and block rules

One address per rule, with a reason and an end date.

  • One IP address per rule, never a range, so a single rule cannot quietly open a whole network.
  • Permanent, or ending after 24 hours, 48 hours, 72 hours or 7 days. Expired rules are removed within a minute.
  • A reason on every rule - "Office, Manila", "Supervisor at home" - so the list still makes sense a year later. Reasons and end dates can be edited afterwards.
  • "Whitelist me" gives the address you are browsing from Admin access in one click.
  • Block rules drop an address on every VICIdial, SIP and SSH port.
  • Select up to 200 rules and delete them at once.
  • Rules the platform adds for your carriers are marked and protected, so nobody deletes your SIP provider by accident.

Agent self-serve portal

When an agent's IP changes, they let themselves back in.

Home broadband, mobile hotspots and coworking Wi-Fi all hand out new addresses. Instead of messaging you, the agent opens your portal link and signs in with the same VICIdial username and password they already use. Their new address is allowed within seconds, and the portal sends them straight on to the agent screen.

The agent firewall portal in a desktop browser: a VICIdial username and password form beside a panel showing the detected location, device and the three sign-in steps
The portal on a desktop.
The agent firewall portal on a phone, with the sign-in form first
On a phone, the form comes first.
  • Their normal VICIdial login - nothing new to remember. An unknown username gets the same answer as a wrong password, so the portal never confirms which usernames exist.
  • You choose how long access lasts: 24 hours, 48 hours, 72 hours or 7 days. Signing in again starts the clock over.
  • Managers (VICIdial user level 7 and up) get Admin access and land on the admin panel.
  • Made for phones: the code field opens a number pad, and the dashboard gives you the link as a QR code to share.
  • Agents on the VICIfast mobile app never see the portal. Signing in to the app allows the phone, and the rule follows it when its address changes.
  • A backup portal on the server itself, on port 446, keeps agents working if the main portal cannot be reached.

Portal security

Public enough for your agents, not a door for anyone else.

CAPTCHA, then lockout

After 5 failed sign-ins the portal asks for a CAPTCHA. An address with 100 failures in an hour is locked out.

Optional TOTP

Require a six-digit code from an authenticator app on top of the password. Agents enrol themselves once; after that only an admin can reset it. Off until you turn it on.

You hear about it

When one agent gets their password wrong 3 times in an hour, you get an email - at most once a day per agent, and you can switch it off.

Every attempt, with a location

Each sign-in attempt is logged with its address, city, country, network, browser and outcome, and kept for 7 days.

Revoke in one click

The Agent Rules tab shows each agent's active whitelists and when they end, with a Revoke button next to each. Removal takes effect at once.

Enrol and lock agents

From the dashboard you can enrol an agent in TOTP, remove their enrolment, or lock them out of the portal.

The firewall Activities tab: portal sign-in attempts with the address, city, country, network and outcome of each
The Activities tab: who tried, from where, and what happened.
The firewall Agent Rules tab: one row per agent with TOTP status, active whitelists and last attempt; one agent expanded to show their whitelisted address with a Revoke button and their recent sign-in attempts
The Agent Rules tab: each agent's TOTP, their active whitelists with a Revoke button, and recent sign-ins.

Your domain, your brand

The portal on your own domain, with your name on it.

On plans that include your own domain, the portal moves to firewall.your-domain.com. You add one CNAME and one TXT record; the certificate is handled for you, and every server under that domain uses the branded link. Resellers use a verified firewall domain of their own.

Whitelabel means no VICIfast at all

With whitelabelling on, the portal shows your logo and nothing of ours - no VICIfast name, logo, support email or "Powered by" line, not even in the browser tab. Your agents only ever see you.

Managed blocklist

104,872 known-bad addresses, kept current for you.

Every night at 02:00 UTC the platform rebuilds one blocklist from four public sources and sends it to every server that has it switched on.

  • Only a complete rebuild ships. If a source fails to download, servers keep the last good list instead of a partial one.
  • It covers the SIP and webphone ports only, never the web pages on 443 - and an address you allowed is never blocked by it.
  • On by default, with one switch per server.
SourceWhat it listsEntries
VoIPBLAddresses caught scanning and abusing SIP serversabout 100,000
FireHOL Level 1A conservative list of addresses that are unsafe to accept traffic fromabout 4,700
Spamhaus DROP and EDROPNetworks hijacked or run by spammers and criminalsabout 1,700

Counts as of September 2026.

Firewall settings: agent self-serve on or off, email when an agent can't sign in, optional TOTP, managed blocklist, carrier auto-whitelist and access length of 24, 48, 72 or 168 hours
Settings: self-serve, failed sign-in email, TOTP, the managed blocklist, carrier auto-whitelist and access length.

Countries

Block countries you never work from. Open one on a schedule when you need to.

Country block

Tick up to 250 countries and every address from them is dropped before it reaches the agent screen, SIP or SSH. The ranges come from ipdeny.com, refresh on the 1st of every month, and are fetched the moment you add a country. Addresses you allowed still get in, and call audio is never blocked.

The firewall Country Blocking tab: China, Russia, North Korea and Iran blocked, above a searchable list of every country
The Country Blocking tab: pick countries from the list; the ones you block show at the top.

Scheduled country allow

For agents whose address changes too often even for the portal - mobile data, shared networks - open the agent screen (443) and webphone (8089) to a whole country, only during the hours you choose.

  • Up to 5 countries per rule.
  • Days and hours in your time zone, overnight windows and daylight saving included.
  • SIP, SSH and the admin port stay closed, and your block rules and blocked countries still win.
  • You tick a warning before it saves, because it opens the login pages to everyone in those countries.
The scheduled country allow dialog: India and Sri Lanka chosen, open 18:00 to 04:00 on weekdays in Kolkata time, with the risk acknowledgement ticked
Countries, days, hours, time zone - and the warning you tick.

Carriers

Your SIP providers are let in automatically.

Every 5 minutes the platform reads the carriers configured on your dialer, resolves their hostnames and allows those addresses with the Carrier profile. When a provider's hostname starts pointing somewhere new, the old address is removed.

  • Trunks from the VICIfast marketplace go further: the provider’s published addresses are allowed when you add the trunk and refreshed on their own, nightly or twice a day depending on the provider.
  • Carrier access is SIP on UDP 5060 only.
  • Automatic carrier rules can be switched off per server, and they are protected from accidental deletion.

Under the hood

Saved in the dashboard, on the box in seconds - and kept there.

Pushed when you save

A change goes to the server the moment you save it and usually lands within seconds. A button forces a fresh push whenever you want one.

Re-checked every minute

Every server is checked once a minute and anything it missed is sent again. A server with nothing to change is left alone.

Drift gets noticed

Each server reports the rules it is actually running. If that stops matching what was sent, the VICIfast team is alerted.

Reboots are covered

At boot the server restores its rules from its own saved state, and the platform pushes them again as a backstop.

Problems are visible

If a server stops accepting changes, the dashboard shows a warning and the nightly maintenance report flags it.

Careful updates

When the firewall software itself is updated, each server is backed up first, then checked - version, list sizes, rule order, a fresh SSH login and the web page - and put back automatically if any check fails.

Access and audit

Your team runs it, and every change has a name on it.

The owner manages the firewall, and so can any member you give the firewall permission along with a role that can make changes. Everything is set per server, and every rule and setting change lands in the audit log with who made it and when. Remove a member and the rules they added go with them.

Coming from ViciBox?

What changes if you're used to the ViciBox Dynamic Portal.

ViciBox's Dynamic Portal is a solid, free answer to the same problem, and plenty of VICIdial floors run it today. Agents sign in on the server's port 446 with their VICIdial login, a cron job rebuilds the allowed list every minute, and VoIPBL blocks known SIP abusers out of the box. Here is how the two compare, using ViciBox's own documentation.

 VICIfast FirewallViciBox Dynamic Portal
Where agents sign infirewall.vicifast.com/your-server - or firewall.your-domain.com on plans with your own domain - with their VICIdial loginhttps://your-server:446/valid8.php, with their VICIdial login
Where you manage itA web dashboard, per server, for you and the members you chooseOver SSH: the vicibox-firewall menu, /etc/firewalld/whitelist.conf and cron jobs, plus the ViciWhite and ViciBlack lists in VICIdial admin
How fast a change appliesPushed when you save, usually within seconds; every server re-checked each minuteAllowed list rebuilt by cron every minute; ViciWhite changes within 2 minutes
BlocklistsVoIPBL, FireHOL Level 1 and Spamhaus DROP/EDROP - 104,872 entries, rebuilt daily - plus your own block rulesVoIPBL (55,000+ addresses per its docs), refreshed every 6 hours, plus the ViciBlack list
Access levelsAgent, Carrier and Admin profiles, each with its own portsAllowed addresses join firewalld's External zone, which carries the VICIdial agent services
Your own certificate or portHandled by the platform; the portal moves to your domain with one CNAME and one TXT recordEdit dynportal-ssl.conf and listen.conf over SSH
Firewall engineufw with ipsetfirewalld with ipset

Also in the VICIfast Firewall

  • A reason and an end date on every rule, from 24 hours to permanent.
  • Country blocking and scheduled country allow, set from the dashboard.
  • Optional TOTP on the portal, with self-enrolment.
  • A log of every sign-in attempt with its city, country and network, and an email when one agent keeps failing.
  • Your carriers allowed automatically, and kept current when their addresses change.
  • Every change in the audit log with a name on it, and removed members’ rules taken back.
  • Agents on the VICIfast mobile app followed automatically when their address changes.
Read the full comparison

ViciBox details from docs.vicibox.com (ViciBox 11.0 and 12.0 firewall documentation), checked September 2026.

40smedian deploy time
99.94%fleet uptime · last 30d
6regions live
Auditedevery state change

The real rule order on every VICIfast server. Your allow rules sit above every block, so an address you let in is never caught by a blocklist or a blocked country. Call audio sits above every block too, so a call never loses its sound.

FAQ

Questions worth answering

No. Every server starts with incoming traffic denied. Only call audio (UDP 10000-30000) and the backup agent portal (TCP 446) answer everyone. The agent screen, the admin panel, SIP and SSH answer only addresses you allow, plus VICIfast platform addresses so your rules, backups and updates can reach the box.

They open your portal link, sign in with their normal VICIdial login, and their new address is allowed within seconds for the access length you chose - 24 hours, 48 hours, 72 hours or 7 days. Agents on the VICIfast mobile app never see the portal: signing in to the app allows them, and the rule follows the phone when its address changes. For teams whose addresses change all day, a scheduled country allow opens the agent screen to a whole country during working hours.

Not an agent you have allowed. Allow rules are checked before every block, so an allowed address is never caught by the managed blocklist, your own block rules or a blocked country. The managed blocklist also only covers the SIP and webphone ports, never the web pages on port 443.

After 5 failed attempts the portal adds a CAPTCHA, and an address with 100 failures in an hour is locked out. You can require a TOTP code from an authenticator app on top of the VICIdial password, and you get an email when one agent gets their password wrong 3 times in an hour. Every attempt is logged with the city, country and network it came from.

Yes, on plans that include your own domain: the portal moves to firewall.your-domain.com with one CNAME and one TXT record. With whitelabelling, the portal shows no VICIfast logo, name or support address.

It is pushed the moment you save, and usually lands within seconds. Every server is also re-checked once a minute, so a server that missed a change is brought back in line. After a reboot the box restores its rules from local state, and the platform pushes them again as a backstop.

The account owner, and members you give the firewall permission with a role that can make changes (Admin or Operator). A Viewer can look but not change. Every rule and setting change is written to the audit log with who made it.

Yes, up to 250 countries, on every VICIdial, SIP and SSH port - call audio is never blocked. The country address ranges come from ipdeny.com, refresh monthly, and are fetched the moment you add a country. Addresses you allowed still get in, because allow rules come first.

Lock the dialer down without learning iptables.

Start the trial. Your server starts closed. Allow your team, let agents re-admit themselves from a portal on your domain, and block the rest - all from the dashboard.

All features