Skip to main content
Glama
antonio-mello-ai

io.github.antonio-mello-ai/mcp-pfsense

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
PFSENSE_HOSTYespfSense hostname or IP
PFSENSE_PORTNoAPI port443
PFSENSE_SCHEMENohttp or httpshttps
PFSENSE_PASSWORDYesAPI user password
PFSENSE_USERNAMENoAPI usernameadmin
PFSENSE_VERIFY_SSLNoVerify SSL certificatefalse

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
get_system_statusA

Get pfSense system status including version, CPU, memory, uptime, and temperature.

get_interfacesA

List all network interfaces with status and configuration.

list_firewall_rulesC

List firewall rules, optionally filtered by interface.

add_firewall_ruleA

Add a firewall rule. Type is 'pass', 'block', or 'reject'.

The rule is staged (not active) until apply_changes('firewall') is called or apply=true is passed here.

delete_firewall_ruleA

Delete a firewall rule by its ID (the id from list_firewall_rules). Requires confirm=true.

Staged until apply_changes('firewall') is called or apply=true is passed.

list_firewall_aliasesA

List firewall aliases (IP groups, port groups, URL lists).

list_dhcp_leasesA

List active DHCP leases showing IP, MAC, hostname, and lease times.

list_dhcp_static_mappingsA

List DHCP static mappings (IP reservations), optionally filtered by interface.

Each mapping carries parent_id (its DHCP server / interface) — pass that as interface to delete_dhcp_static_mapping.

add_dhcp_static_mappingA

Create a DHCP static mapping (IP reservation) for a MAC address.

Staged until apply_changes('dhcp') is called or apply=true is passed.

delete_dhcp_static_mappingA

Delete a DHCP static mapping. Requires confirm=true.

interface is the mapping's DHCP server — the parent_id value returned by list_dhcp_static_mappings; mapping_id is its id there. Staged until apply_changes('dhcp') is called or apply=true is passed.

list_dns_host_overridesA

List DNS Resolver host overrides (local DNS entries).

add_dns_host_overrideA

Create a DNS host override entry in Unbound DNS Resolver.

Staged until apply_changes('dns') is called or apply=true is passed.

delete_dns_host_overrideA

Delete a DNS host override by ID. Requires confirm=true.

Staged until apply_changes('dns') is called or apply=true is passed.

get_pending_changesA

Check whether a subsystem ('firewall', 'dhcp' or 'dns') has staged, unapplied changes.

apply_changesA

Apply ALL staged changes of a subsystem ('firewall', 'dhcp' or 'dns'). Requires confirm=true.

This reloads the subsystem, activating every pending change — including any a human staged in the pfSense WebGUI and has not reviewed yet.

get_gateway_statusA

Get gateway status including latency, packet loss, and online state.

get_arp_tableA

Get ARP table showing connected devices (IP, MAC, interface).

list_servicesA

List all services and their running status.

restart_serviceB

Restart a service by name. Requires confirm=true.

get_firewall_logsA

Read-only view of recent firewall log entries.

Each entry contains its ID and raw log text from pfrest. limit caps the number of entries (default 50). This tool only reads logs; it never writes to the firewall.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.5/5.0

Scored across 20 tools

Disambiguation4/5

Most tools target a distinct resource and action, such as firewall rules, DHCP mappings, DNS overrides, logs, and ARP. A few read-only tools like get_arp_table and list_dhcp_leases could be confused when looking for connected devices, but their descriptions clarify the difference.

Naming Consistency3/5

The set largely uses snake_case verb_noun naming, but read operations are split inconsistently between get_ and list_ (e.g., get_interfaces vs list_firewall_rules). Add/delete pairs are consistent, while apply_changes and get_pending_changes follow a different style.

Tool Count4/5

20 tools is on the heavier side, but it is justified by pfSense's broad scope covering firewall, DHCP, DNS, system status, services, and networking. The count is slightly over the ideal range but not bloated for the domain.

Completeness3/5

Firewall rules, DHCP static mappings, and DNS overrides each support add/list/delete, and the staged-apply workflow is covered. However, there are no update/edit tools for any managed resource, which is a notable gap for a management server.

Maintenance

ActivityMaintained
ResponsivenessSlow