sos-microtik-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| validate_networkA | Check IP addresses / subnets the user provided BEFORE using them, and explain
the result to the user. Accepts '/prefix' or dotted masks:
'192.168.20.1/24', '192.168.20.1 255.255.255.0', '192.168.20.1/255.255.255.0'.
Several values can be separated by commas.
purpose='interface': an address for the router itself (gateway, tunnel IP).
purpose='network' : a subnet or route (LAN range, WireGuard allowed-address).
If |
| discover_routersC | Find MikroTik devices on the local network via MNDP (like Winbox Neighbors). |
| connectB | Open an SSH session to a router under |
| reconnectB | Reconnect a session (optionally to a new IP) reusing the stored credentials. |
| list_sessionsB | List open router sessions. |
| disconnectC | Close a session and forget its credentials. |
| router_overviewB | Version, board, interfaces by type, Wi-Fi driver, bridges and interface lists. Call this before planning any change. |
| run_commandA | Run a READ-ONLY RouterOS command (print, export, monitor, ping count=4...). For changes use the dedicated tools or apply_changes. |
| collect_infoB | Save full export + hardware/status/Wi-Fi/VPN/firewall info to ~/mikrotik-sites///. Read-only. |
| configure_wifiB | Set SSID and Wi-Fi password on the router's Wi-Fi interfaces. interfaces: which Wi-Fi interfaces (default: all, e.g. both 2.4 and 5 GHz). password: leave empty to have the user type it in a local popup (preferred), or set generate_password=True to create a strong one (shown in a local popup and saved under ~/mikrotik-sites//, never returned to chat). security: 'wpa2', 'wpa2-wpa3' (mixed, default) or 'wpa3'. Legacy 'wireless' driver only supports WPA2; mixed falls back to WPA2 there. country: regulatory country, e.g. 'Costa Rica'. Recommended on first setup. Works with legacy wireless, new wifi (7.13+) and wifiwave2 drivers. |
| setup_bridge_with_wifi_subnetA | Put all LAN ports and Wi-Fi in a bridge, with Wi-Fi in its own subnet. wifi_gateway (REQUIRED, ask the user, never invent): router IP + mask for the
Wi-Fi subnet, as '192.168.20.1/24' or '192.168.20.1 255.255.255.0'.
lan_address: only if the user wants to set/change the LAN gateway (same formats).
If omitted, the current LAN address is kept (shown in the dry run; confirm it).
dhcp_range: optional pool 'first-last' (e.g. '192.168.20.100-192.168.20.200').
Default: the usable range after the first 9 addresses. Confirm with the user.
mode='vlan' (default): ONE bridge with VLAN filtering. LAN ports untagged on
VLAN 1, Wi-Fi ports on wifi_vlan_id, router IP on a VLAN interface.
Caution: on many non-CRS3xx models this disables hardware offload (CPU switching).
mode='separate_bridge': LAN ports in |
| audit_securityA | Read-only security audit: version, users, exposed services, firewall, DNS resolver, proxies, MAC access, SNMP, Wi-Fi encryption, IPv6 firewall, and compromise indicators (schedulers/scripts, socks/proxy, static DNS). Optionally saves the report to ~/mikrotik-sites//. |
| harden_servicesC | Common hardening. disable_services default: telnet, ftp, www, api, api-ssl (SSH and Winbox stay on; SSH can never be disabled here). restrict_mgmt_to: subnets allowed to use SSH/Winbox (ask the user), comma-separated, '/prefix' or dotted mask. Refused if this computer's IP is not inside them. |
| firewall_baselineB | Apply a MikroTik-defconf-style IPv4 firewall: input: accept established/related/untracked, drop invalid, accept ICMP, accept WireGuard ports, drop everything not from LAN. forward: fasttrack, accept established/related, drop invalid, drop new WAN connections that aren't port-forwards. nat: masquerade out WAN (if none exists). If the router already has other filter rules, the tool stops and lists them; set replace_existing=True to replace them (rules tagged mcp-wifi/mcp-wg are kept). |
| wireguard_statusA | Show WireGuard interfaces (address with mask in both formats), peers (handshake, traffic, endpoints) and whether the firewall allows each port. Secrets are masked. |
| wireguard_create_interfaceA | Create (or update) a WireGuard interface. All values come from the user. address (REQUIRED, ask the user, never invent): the router's tunnel IP with mask, as '10.10.10.1/24' or '10.10.10.1 255.255.255.0'. Validated and checked for overlap with the router's existing subnets. private_key_source (REQUIRED, ask the user): 'router' = RouterOS creates the interface's own key (never leaves the router). 'user' = the user enters an existing private key (e.g. rebuilding a tunnel). Leave private_key empty: it is entered in a local popup on apply. wg_name, listen_port (REQUIRED, ask the user; RouterOS commonly uses 13231). |
| wireguard_add_peerA | Add a WireGuard peer. This server never generates keys; all values come from the user. allowed_address (REQUIRED, ask the user): addresses this peer uses/routes, comma-separated, '/prefix' or dotted mask. E.g. '10.10.10.2/32' (phone/laptop) or '10.10.10.2/32, 192.168.50.0 255.255.255.0' (remote site + its LAN). Validated: format, overlap with other peers, inside the tunnel subnet, not the router's own IP. public_key: the REMOTE peer's public key (shown in its WireGuard app / remote router). Leave empty to have the user type it in a local popup on apply. Checked: format, not this router's own key, not already used on this interface. use_preshared_key: on apply the preshared key is entered in a local popup (or via preshared_key). Never ask the user to paste it in chat. endpoint: 'host:port' of the remote side for site-to-site. Omit for roaming clients. write_client_config: also save a .conf for the remote device. Requires (ask the user): client_allowed_ips: '0.0.0.0/0' for full tunnel, or specific subnets (split tunnel); server_endpoint: public IP/hostname (and :port) the client connects to. On apply the user may enter the client's private key in a popup to get a complete config + QR; it is checked against public_key. If left empty, a template is saved. client_dns: optional DNS server IP(s) for the client config. |
| wireguard_update_peerA | Modify a WireGuard peer, found by its public key or comment. allowed_address: new value (validated, '/prefix' or dotted mask, comma-separated). endpoint: 'host:port', or '' to clear (roaming client). replace_public_key / replace_preshared_key: new key entered in a local popup on apply (public key may also be given as new_public_key). Keys are never generated. |
| wireguard_remove_peerC | Remove a WireGuard peer, identified by its public key or comment. |
| apply_changesA | Apply arbitrary RouterOS commands (one per list item) when no dedicated tool fits. Same safety net: backup + rollback timer + stop on first error. |
| confirm_changesA | Disarm the rollback after verifying the change works; saves the new config locally. |
| rollback_nowC | Immediately restore the pre-change backup. The router REBOOTS. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 22 tools
Most tools have clearly distinct purposes (e.g., configure_wifi vs firewall_baseline vs wireguard_create_interface). However, there is some overlap between run_command, apply_changes, and collect_info, and between connect, reconnect, and disconnect, which could cause minor confusion. The descriptions help clarify boundaries.
All tool names follow a consistent snake_case verb_noun pattern. Examples include discover_routers, configure_wifi, validate_network, apply_changes, and wireguard_add_peer. There are no naming inconsistencies.
22 tools is slightly on the higher side but appropriate for the breadth of functionality (session management, Wi-Fi, firewall, WireGuard, auditing, etc.). Each tool appears to serve a distinct purpose, though some could potentially be merged (e.g., connect/reconnect).
The tool set covers a wide range of MikroTik management tasks: discovery, connection, configuration, security, and WireGuard. Some areas might be missing, such as user management, logging, or advanced routing, but core workflows are well-supported.