firewalla-mcp-server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| FIREWALLA_BOX_ID | Yes | Your Firewalla Box GID (Group ID) found in device settings | |
| FIREWALLA_MSP_ID | Yes | Your Firewalla MSP ID, which is the full domain (e.g., company123.firewalla.net) | |
| FIREWALLA_MSP_TOKEN | Yes | Your Firewalla MSP access token generated in API settings |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
| prompts | {} |
| resources | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_active_alarmsA | Retrieve active security alarms from the Firewalla MSP API (GET /v2/alarms): status:1 is added unless the query names a status (status:2 for archived alarms). Without a ts: qualifier the API covers the last 30 days. Returns up to limit alarms and a cursor for the next page, or groups with groupBy. Scoped to FIREWALLA_BOX_ID when set, otherwise every box. |
| get_specific_alarmA | Get detailed information for one Firewalla alarm (GET /v2/alarms/{gid}/{aid}). Alarm IDs are per box: pass gid on a multi-box account, or each box is checked, one request per box, until one has the alarm. |
| get_flow_dataA | Query network traffic flows from the Firewalla MSP API (GET /v2/flows). Without a ts: qualifier the API covers the last 24 hours. Returns up to limit flows and a cursor for the next page, or groups with groupBy. Scoped to FIREWALLA_BOX_ID when set, otherwise every box. |
| get_device_statusA | Check online/offline status of devices on the Firewalla network. Reads the device list from GET /v2/devices (box, else FIREWALLA_BOX_ID, else every box; group limits it to a box group) and returns up to limit devices, sorted by name. |
| get_network_rulesA | Retrieve firewall rules and conditions (GET /v2/rules). The API returns every matching rule; the tool returns the first limit. Scoped to FIREWALLA_BOX_ID when set, otherwise every box. |
| pause_ruleA | Pause an active firewall rule on the box until resume_rule reactivates it (POST /v2/rules/{id}/pause, no body). The MSP API takes no duration, so the pause does not expire on its own. Checks the rule's status first and changes nothing if it is already paused. |
| resume_ruleA | Resume a paused firewall rule on the box, restoring it to active (POST /v2/rules/{id}/resume, no body). Checks the rule's status first and changes nothing if it is already active. |
| get_target_listsA | Retrieve target lists (GET /v2/target-lists). Without owner the API returns the MSP's global lists and the Firewalla-managed lists; owner selects global lists, a box's lists, or several. entry_count is the number of entries in each list; the API does not return the entries of Firewalla-managed lists, so their targets is null. Returns up to limit lists. |
| get_specific_target_listA | Retrieve one target list by ID, including its targets (GET /v2/target-lists/{id}). |
| create_target_listA | Create a new target list (POST /v2/target-lists); each call creates another list. owner global makes it shareable across all boxes, a box GID ties it to that box. |
| update_target_listA | Update an existing target list (PATCH /v2/target-lists/{id}). Only the fields given are sent; targets, when given, is the complete new list and is not merged with the current targets. |
| delete_target_listA | Permanently delete a target list (DELETE /v2/target-lists/{id}); cannot be undone. The tool does not check whether a rule still targets the list. |
| search_flowsA | Search network flows with advanced query filters. Use this for: historical analysis, specific time ranges, complex filtering, or when you need more than 50 flows. Supports pagination, time-based queries (e.g., "ts:>1h" for the last hour, or Unix seconds such as "ts:1735689600-1735693200"), and all flow fields including geographic filtering. For quick "what's happening now" snapshots, use get_recent_flow_activity instead. Reads GET /v2/flows, 500 per request, following the cursor up to limit. Scoped to FIREWALLA_BOX_ID when set, otherwise every box. |
| search_alarmsB | Search alarms using full-text or field filters. Alarm types: 1=Security Activity, 2=Abnormal Upload, 3=Large Bandwidth Usage, 4=Monthly Data Plan, 5=New Device, 6=Device Back Online, 7=Device Offline, 8=Video Activity, 9=Gaming Activity, 10=Porn Activity, 11=VPN Activity, 12=VPN Connection Restored, 13=VPN Connection Error, 14=Open Port, 15=Internet Connectivity Update, 16=Large Upload. Reads GET /v2/alarms, 500 per request, following the cursor up to limit. Scoped to FIREWALLA_BOX_ID when set, otherwise every box. |
| search_rulesA | Search firewall rules by target, action or status; the MSP API applies the query (GET /v2/rules). Supports all rule fields. Scoped to FIREWALLA_BOX_ID when set, otherwise every box. |
| get_boxesA | List the Firewalla boxes this MSP token can see (GET /v2/boxes, optionally one box group), with online status, model and version. Not limited by FIREWALLA_BOX_ID. |
| get_simple_statisticsA | Get account-wide counts from GET /v2/stats/simple: online boxes, offline boxes, alarms and rules, optionally for one box group. Not limited by FIREWALLA_BOX_ID. |
| get_statistics_by_regionA | Top regions by blocked flows, from GET /v2/stats/topRegionsByBlockedFlows, optionally for one box group; the API returned no more than 5 regions. Not limited by FIREWALLA_BOX_ID. |
| get_statistics_by_boxA | Top boxes by blocked flows (the default) or by Security Activity alarms, from GET /v2/stats/{type}, with each box's details from GET /v2/boxes; each box's value is the statistic, over about the last 30 days when measured. Not limited by FIREWALLA_BOX_ID. |
| get_recent_flow_activityA | Get a snapshot of the 50 most recent network flows (one GET /v2/flows request) with protocol, region and blocked/allowed counts; the minutes they span depend on how busy the network is. Use this for: "what's happening right now?", current security threats, immediate network issues. DO NOT use for: historical analysis, more than 50 flows, or daily/weekly patterns; use search_flows with time queries like "ts:>24h" for those. Scoped to FIREWALLA_BOX_ID when set, otherwise every box. |
| get_flow_insightsA | Get category-based flow analysis for a period: top content categories and their domains, top devices by bandwidth, and optionally blocked traffic. Ideal for answering questions like "what porn sites were accessed" or "what social media was used". Computed client-side from the period's largest flows (GET /v2/flows by total bytes: up to 500 for categories, 200 for devices) and, with include_blocked, the 50 most frequent blocked flows, so on a busy network it covers the largest flows, not all of them. Scoped to FIREWALLA_BOX_ID when set, otherwise every box. |
| get_alarm_trendsA | Alarms generated per day, from GET /v2/trends/alarms: one point per day for the last 30 days, the last point being today so far. period (default 30d) returns the days that overlap it. The trends API takes no box, so it covers every box (or the group) even with FIREWALLA_BOX_ID set. |
| get_rule_trendsA | Rules created per day for the last 30 days, from GET /v2/trends/rules; period and group work as in get_alarm_trends. When that endpoint answers 400 (it did when measured), each UTC day counts the rules in GET /v2/rules created on it, scoped to FIREWALLA_BOX_ID when set (rules deleted since are not counted), and the response says so. |
| get_bandwidth_usageA | Top devices by upload plus download over the period, summed client-side from up to 10 times limit (1,000 at most) of the period's most recent flows (GET /v2/flows, 500 per request), so on a busy network the totals cover a sample. Scoped to box, else FIREWALLA_BOX_ID, else every box. |
| get_offline_devicesA | List offline devices from the full device list (GET /v2/devices), most recently seen first by default, up to limit; total_offline_devices counts all of them. Scoped to box, else FIREWALLA_BOX_ID, else every box. |
| search_devicesA | Search devices by name, IP, MAC or status (convenience wrapper with client-side filtering): reads the device list from GET /v2/devices (box, else FIREWALLA_BOX_ID, else every box) and filters it locally. |
| search_target_listsA | Search target lists (convenience wrapper with client-side filtering): reads GET /v2/target-lists, sending owner if given (without it, the global and Firewalla-managed lists), and applies the query locally. |
| get_network_rules_summaryA | Get overview counts of network rules by action, direction, status and target type (convenience wrapper): reads the rules from GET /v2/rules and counts them locally. Scoped to FIREWALLA_BOX_ID when set, otherwise every box. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| security_report | Comprehensive security report for a time period |
| threat_analysis | Deep analysis of recent threats and blocked attempts |
| bandwidth_analysis | Top bandwidth consumers and usage patterns |
| device_investigation | Investigate a specific device: flows, alarms, behavior |
| network_health_check | Overall network health: summary, devices, metrics, topology, rules |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| Firewall Summary | Box online status and device, alarm and rule counts per box, plus blocked flows in a recent sample |
| Device Inventory | Complete device inventory with status and metadata |
| Security Metrics | Aggregated security statistics and trends |
| Network Topology | Network structure and device relationships |
| Recent Threats | Latest security events and blocked attempts |
TDQS
Scored across 28 tools
Several tools overlap in purpose: get_offline_devices and get_device_status both read device lists and report online/offline status; get_flow_data, search_flows, and get_recent_flow_activity all query flows with different scopes; get_network_rules and search_rules both retrieve rules. Descriptions help distinguish them, but the boundaries are not always obvious.
Most tools follow a consistent get_/search_/create_/update_/delete_/pause_/resume_ verb pattern with clear noun objects. Minor deviations like get_network_rules_summary and get_specific_target_list vs get_specific_alarm are acceptable, but the mix of get_ and search_ for similar resources (flows, alarms, rules) creates slight inconsistency.
28 tools is on the heavy side for a single server, though the domain (Firewalla MSP API) is broad with devices, alarms, flows, rules, target lists, and statistics. The count is borderline: many tools are convenience wrappers or variations on the same resource, which could be consolidated.
The tool set covers the main Firewalla MSP resources well: devices, alarms, flows, rules, target lists, and statistics. Minor gaps exist (e.g., no create/update/delete for rules or alarms, no device management actions), but the core read and search operations are comprehensive.