io.github.antonio-mello-ai/mcp-pfsense
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| PFSENSE_HOST | Yes | pfSense hostname or IP | |
| PFSENSE_PORT | No | API port | 443 |
| PFSENSE_SCHEME | No | http or https | https |
| PFSENSE_PASSWORD | Yes | API user password | |
| PFSENSE_USERNAME | No | API username | admin |
| PFSENSE_VERIFY_SSL | No | Verify SSL certificate | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_system_statusA | Get pfSense system status including version, CPU, memory, uptime, and temperature. |
| get_interfacesA | List all network interfaces with status and configuration. |
| list_firewall_rulesC | List firewall rules, optionally filtered by interface. |
| add_firewall_ruleA | Add a firewall rule. Type is 'pass', 'block', or 'reject'. The rule is staged (not active) until apply_changes('firewall') is called or apply=true is passed here. |
| delete_firewall_ruleA | Delete a firewall rule by its ID (the Staged until apply_changes('firewall') is called or apply=true is passed. |
| list_firewall_aliasesA | List firewall aliases (IP groups, port groups, URL lists). |
| list_dhcp_leasesA | List active DHCP leases showing IP, MAC, hostname, and lease times. |
| list_dhcp_static_mappingsA | List DHCP static mappings (IP reservations), optionally filtered by interface. Each mapping carries |
| add_dhcp_static_mappingA | Create a DHCP static mapping (IP reservation) for a MAC address. Staged until apply_changes('dhcp') is called or apply=true is passed. |
| delete_dhcp_static_mappingA | Delete a DHCP static mapping. Requires confirm=true.
|
| list_dns_host_overridesA | List DNS Resolver host overrides (local DNS entries). |
| add_dns_host_overrideA | Create a DNS host override entry in Unbound DNS Resolver. Staged until apply_changes('dns') is called or apply=true is passed. |
| delete_dns_host_overrideA | Delete a DNS host override by ID. Requires confirm=true. Staged until apply_changes('dns') is called or apply=true is passed. |
| get_pending_changesA | Check whether a subsystem ('firewall', 'dhcp' or 'dns') has staged, unapplied changes. |
| apply_changesA | Apply ALL staged changes of a subsystem ('firewall', 'dhcp' or 'dns'). Requires confirm=true. This reloads the subsystem, activating every pending change — including any a human staged in the pfSense WebGUI and has not reviewed yet. |
| get_gateway_statusA | Get gateway status including latency, packet loss, and online state. |
| get_arp_tableA | Get ARP table showing connected devices (IP, MAC, interface). |
| list_servicesA | List all services and their running status. |
| restart_serviceB | Restart a service by name. Requires confirm=true. |
| get_firewall_logsA | Read-only view of recent firewall log entries. Each entry contains its ID and raw log text from pfrest. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 20 tools
Most tools target a distinct resource and action, such as firewall rules, DHCP mappings, DNS overrides, logs, and ARP. A few read-only tools like get_arp_table and list_dhcp_leases could be confused when looking for connected devices, but their descriptions clarify the difference.
The set largely uses snake_case verb_noun naming, but read operations are split inconsistently between get_ and list_ (e.g., get_interfaces vs list_firewall_rules). Add/delete pairs are consistent, while apply_changes and get_pending_changes follow a different style.
20 tools is on the heavier side, but it is justified by pfSense's broad scope covering firewall, DHCP, DNS, system status, services, and networking. The count is slightly over the ideal range but not bloated for the domain.
Firewall rules, DHCP static mappings, and DNS overrides each support add/list/delete, and the staged-apply workflow is covered. However, there are no update/edit tools for any managed resource, which is a notable gap for a management server.