Skip to main content
Glama

cisco-mcp

A read-only MCP server for Cisco IOS / IOS-XE and Nexus (NX-OS) switches. It lets an LLM run show commands over SSH — and nothing else.

The two-account model

To run show running-config on IOS you need privilege 15, but you don't want a priv-15 account doing everything. So the server uses two accounts:

Account

Used for

Read-only (CISCO_RO_*)

Every tool call

Privilege-15 (CISCO_PRIV15_*)

Only show running-config on IOS/IOS-XE

The priv-15 account is scoped as tightly as possible: it fires only when the command is show running-config (or its abbreviations show run / sh run / show running) on an IOS/IOS-XE device. Everything else — including show startup-config, show tech-support, and show archive — stays on the read-only account.

Platform-aware: privilege levels are an IOS/IOS-XE concept. Nexus uses RBAC — its read-only network-operator role can already read the running config — so on NX-OS devices the server always uses the read-only account and never escalates.

Related MCP server: Network MCP Server

Safety

Every command passes through a fail-closed allowlist (allowlist.py) before it runs:

  • must be a show command (abbreviations like sh run included);

  • config mode, write/erase/reload/copy/clear/debug, command chaining (;, newlines), and pipe-to-write (| redirect, | tee, | append) are rejected.

The LLM never decides what's safe — the server enforces it mechanically, which also contains prompt-injection arriving through arguments or command output.

Setup

# 1. install (uv recommended)
uv sync           # or: pip install -e .

# 2. credentials
cp .env.example .env            # fill in the two accounts

# 3. inventory
cp devices.example.yaml devices.yaml   # list your switches + platform

# 4. run tests
uv run pytest

Register with an MCP client

stdio transport, e.g. in a client config:

{
  "mcpServers": {
    "cisco": {
      "command": "uv",
      "args": ["run", "cisco-mcp"],
      "cwd": "/path/to/cisco-mcp"
    }
  }
}

Tools

25 tools total. Every one runs through the same allowlist + account-selection gate; only get_running_config (or run_show_command with show running-config) on an IOS/IOS-XE device escalates to the priv-15 account.

Meta

  • list_devices — inventory with platform + notes

  • run_show_command(device, command) — any allowlisted show, with the same gate

System / identity

  • get_versionshow version

  • get_running_configshow running-config (priv-15 on IOS/IOS-XE, read-only on NX-OS)

  • get_inventory_hwshow inventory (chassis / modules / serial numbers)

  • get_clockshow clock

  • get_logsshow logging

Health / capacity

  • get_cpushow processes cpu history (IOS/IOS-XE) / show system resources (NX-OS)

  • get_memoryshow memory statistics (IOS/IOS-XE) / show system resources (NX-OS)

  • get_environmentshow environment

  • get_poe_statusshow power inline

L2 / switching

  • get_interfacesshow interfaces

  • get_interface_statusshow ip interface brief

  • get_vlansshow vlan brief

  • get_trunksshow interfaces trunk

  • get_spanning_treeshow spanning-tree

  • get_etherchannelsshow etherchannel summary (IOS/IOS-XE) / show port-channel summary (NX-OS)

  • get_mac_address_tableshow mac address-table

L3 / routing

  • get_arp_tableshow ip arp

  • get_routing_tableshow ip route

  • get_ospf_neighborsshow ip ospf neighbor

  • get_bgp_summaryshow ip bgp summary

  • get_eigrp_neighborsshow ip eigrp neighbors

Neighbor discovery

  • get_cdp_neighborsshow cdp neighbors detail

  • get_lldp_neighborsshow lldp neighbors detail

Layout

src/cisco_mcp/
  server.py       MCP tools (FastMCP, stdio)
  allowlist.py    safety gate + priv-15 policy   <- security core
  connection.py   account selection + Netmiko SSH
  credentials.py  two account profiles from env
  inventory.py    devices.yaml loader
  platforms.py    IOS vs NX-OS behavior
tests/            allowlist + account-selection tests (no network)
Install Server
F
license - not found
A
quality
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

View all related MCP servers

Related MCP Connectors

  • Operate your Linux servers from your LLM. Every action runs through an auditable allowlist.

  • Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.

  • Deterministic trust gate for AI output: leaked-secret, prompt-injection & PII in one call.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Chiefff-Kiefff/cisco-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server