Skip to main content
Glama
fquiroga

Panorama MCP Server

by fquiroga

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
PANORAMA_URLYesThe base URL of the Panorama management interface. Example: https://panorama.example.net
PANORAMA_API_KEYYesAPI key for a dedicated read-only Panorama administrator or service account. Must be kept secret.
PANORAMA_RULEBASEYesThe rulebase to evaluate, e.g., 'pre-rulebase'.
PANORAMA_VERIFY_TLSYesWhether to enable TLS certificate verification. Set to 'false' only in controlled lab environments; do not disable in production.true
PANORAMA_DEVICE_GROUPYesThe Panorama device group to use, e.g., 'shared'.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
list_device_groupsA

List Panorama device groups visible to the configured read-only API key.

get_security_rulesB

Fetch normalized security rules from one Panorama device group and rulebase.

search_policy_coverageA

Find exact duplicates, coverage, conflicts, and partial overlaps without changing Panorama.

preclear_rule_requestB

Run deterministic read-only preclear checks before a rule change is considered.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.7/5.0

Scored across 4 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: fetching rules, listing groups, searching for policy overlap, and running preclear checks. There is no ambiguity in what each tool does.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern (get_, list_, search_, preclear_), using snake_case throughout. The naming is predictable and clear.

Tool Count5/5

With only 4 tools, the server is tightly scoped to read-only policy analysis and preclear workflows. Each tool earns its place, and the count falls well within the ideal 3-15 range.

Completeness4/5

The set covers the core read-only workflow: list accessible groups, fetch rules, analyze coverage/conflicts, and run preclear checks. Minor gaps exist (e.g., no direct rule-detail retrieval for a single rule), but the essential operations are present and coherent.

Maintenance

ActivitySlowing
ResponsivenessNo issues