Panorama MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| PANORAMA_URL | Yes | The base URL of the Panorama management interface. Example: https://panorama.example.net | |
| PANORAMA_API_KEY | Yes | API key for a dedicated read-only Panorama administrator or service account. Must be kept secret. | |
| PANORAMA_RULEBASE | Yes | The rulebase to evaluate, e.g., 'pre-rulebase'. | |
| PANORAMA_VERIFY_TLS | Yes | Whether to enable TLS certificate verification. Set to 'false' only in controlled lab environments; do not disable in production. | true |
| PANORAMA_DEVICE_GROUP | Yes | The Panorama device group to use, e.g., 'shared'. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_device_groupsA | List Panorama device groups visible to the configured read-only API key. |
| get_security_rulesB | Fetch normalized security rules from one Panorama device group and rulebase. |
| search_policy_coverageA | Find exact duplicates, coverage, conflicts, and partial overlaps without changing Panorama. |
| preclear_rule_requestB | Run deterministic read-only preclear checks before a rule change is considered. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool has a clearly distinct purpose: fetching rules, listing groups, searching for policy overlap, and running preclear checks. There is no ambiguity in what each tool does.
All tool names follow a consistent verb_noun pattern (get_, list_, search_, preclear_), using snake_case throughout. The naming is predictable and clear.
With only 4 tools, the server is tightly scoped to read-only policy analysis and preclear workflows. Each tool earns its place, and the count falls well within the ideal 3-15 range.
The set covers the core read-only workflow: list accessible groups, fetch rules, analyze coverage/conflicts, and run preclear checks. Minor gaps exist (e.g., no direct rule-detail retrieval for a single rule), but the essential operations are present and coherent.