Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
validate_networkA

Check IP addresses / subnets the user provided BEFORE using them, and explain the result to the user. Accepts '/prefix' or dotted masks: '192.168.20.1/24', '192.168.20.1 255.255.255.0', '192.168.20.1/255.255.255.0'. Several values can be separated by commas. purpose='interface': an address for the router itself (gateway, tunnel IP). purpose='network' : a subnet or route (LAN range, WireGuard allowed-address). If name is a connected router session, also checks overlap with its subnets. Reports mask in both formats, network, broadcast, usable range and host count.

discover_routersC

Find MikroTik devices on the local network via MNDP (like Winbox Neighbors).

connectB

Open an SSH session to a router under name. Leave password empty so the user is prompted in a local popup (keeps it out of the conversation).

reconnectB

Reconnect a session (optionally to a new IP) reusing the stored credentials.

list_sessionsB

List open router sessions.

disconnectC

Close a session and forget its credentials.

router_overviewB

Version, board, interfaces by type, Wi-Fi driver, bridges and interface lists. Call this before planning any change.

run_commandA

Run a READ-ONLY RouterOS command (print, export, monitor, ping count=4...). For changes use the dedicated tools or apply_changes.

collect_infoB

Save full export + hardware/status/Wi-Fi/VPN/firewall info to ~/mikrotik-sites///. Read-only.

configure_wifiB

Set SSID and Wi-Fi password on the router's Wi-Fi interfaces.

interfaces: which Wi-Fi interfaces (default: all, e.g. both 2.4 and 5 GHz). password: leave empty to have the user type it in a local popup (preferred), or set generate_password=True to create a strong one (shown in a local popup and saved under ~/mikrotik-sites//, never returned to chat). security: 'wpa2', 'wpa2-wpa3' (mixed, default) or 'wpa3'. Legacy 'wireless' driver only supports WPA2; mixed falls back to WPA2 there. country: regulatory country, e.g. 'Costa Rica'. Recommended on first setup. Works with legacy wireless, new wifi (7.13+) and wifiwave2 drivers.

setup_bridge_with_wifi_subnetA

Put all LAN ports and Wi-Fi in a bridge, with Wi-Fi in its own subnet.

wifi_gateway (REQUIRED, ask the user, never invent): router IP + mask for the Wi-Fi subnet, as '192.168.20.1/24' or '192.168.20.1 255.255.255.0'. lan_address: only if the user wants to set/change the LAN gateway (same formats). If omitted, the current LAN address is kept (shown in the dry run; confirm it). dhcp_range: optional pool 'first-last' (e.g. '192.168.20.100-192.168.20.200'). Default: the usable range after the first 9 addresses. Confirm with the user. mode='vlan' (default): ONE bridge with VLAN filtering. LAN ports untagged on VLAN 1, Wi-Fi ports on wifi_vlan_id, router IP on a VLAN interface. Caution: on many non-CRS3xx models this disables hardware offload (CPU switching). mode='separate_bridge': LAN ports in bridge, Wi-Fi in wifi_bridge. wan_interface: excluded from bridging (default: members of the WAN interface list). lan_ports / wifi_ports: default all Ethernet (minus WAN) / all Wi-Fi interfaces. isolate_wifi_from_lan: block traffic between Wi-Fi and LAN; Wi-Fi gets internet, DNS and DHCP only (no router management from Wi-Fi).

audit_securityA

Read-only security audit: version, users, exposed services, firewall, DNS resolver, proxies, MAC access, SNMP, Wi-Fi encryption, IPv6 firewall, and compromise indicators (schedulers/scripts, socks/proxy, static DNS). Optionally saves the report to ~/mikrotik-sites//.

harden_servicesC

Common hardening. disable_services default: telnet, ftp, www, api, api-ssl (SSH and Winbox stay on; SSH can never be disabled here). restrict_mgmt_to: subnets allowed to use SSH/Winbox (ask the user), comma-separated, '/prefix' or dotted mask. Refused if this computer's IP is not inside them.

firewall_baselineB

Apply a MikroTik-defconf-style IPv4 firewall: input: accept established/related/untracked, drop invalid, accept ICMP, accept WireGuard ports, drop everything not from LAN. forward: fasttrack, accept established/related, drop invalid, drop new WAN connections that aren't port-forwards. nat: masquerade out WAN (if none exists). If the router already has other filter rules, the tool stops and lists them; set replace_existing=True to replace them (rules tagged mcp-wifi/mcp-wg are kept).

wireguard_statusA

Show WireGuard interfaces (address with mask in both formats), peers (handshake, traffic, endpoints) and whether the firewall allows each port. Secrets are masked.

wireguard_create_interfaceA

Create (or update) a WireGuard interface. All values come from the user.

address (REQUIRED, ask the user, never invent): the router's tunnel IP with mask, as '10.10.10.1/24' or '10.10.10.1 255.255.255.0'. Validated and checked for overlap with the router's existing subnets. private_key_source (REQUIRED, ask the user): 'router' = RouterOS creates the interface's own key (never leaves the router). 'user' = the user enters an existing private key (e.g. rebuilding a tunnel). Leave private_key empty: it is entered in a local popup on apply. wg_name, listen_port (REQUIRED, ask the user; RouterOS commonly uses 13231).

wireguard_add_peerA

Add a WireGuard peer. This server never generates keys; all values come from the user.

allowed_address (REQUIRED, ask the user): addresses this peer uses/routes, comma-separated, '/prefix' or dotted mask. E.g. '10.10.10.2/32' (phone/laptop) or '10.10.10.2/32, 192.168.50.0 255.255.255.0' (remote site + its LAN). Validated: format, overlap with other peers, inside the tunnel subnet, not the router's own IP. public_key: the REMOTE peer's public key (shown in its WireGuard app / remote router). Leave empty to have the user type it in a local popup on apply. Checked: format, not this router's own key, not already used on this interface. use_preshared_key: on apply the preshared key is entered in a local popup (or via preshared_key). Never ask the user to paste it in chat. endpoint: 'host:port' of the remote side for site-to-site. Omit for roaming clients. write_client_config: also save a .conf for the remote device. Requires (ask the user): client_allowed_ips: '0.0.0.0/0' for full tunnel, or specific subnets (split tunnel); server_endpoint: public IP/hostname (and :port) the client connects to. On apply the user may enter the client's private key in a popup to get a complete config + QR; it is checked against public_key. If left empty, a template is saved. client_dns: optional DNS server IP(s) for the client config.

wireguard_update_peerA

Modify a WireGuard peer, found by its public key or comment. allowed_address: new value (validated, '/prefix' or dotted mask, comma-separated). endpoint: 'host:port', or '' to clear (roaming client). replace_public_key / replace_preshared_key: new key entered in a local popup on apply (public key may also be given as new_public_key). Keys are never generated.

wireguard_remove_peerC

Remove a WireGuard peer, identified by its public key or comment.

apply_changesA

Apply arbitrary RouterOS commands (one per list item) when no dedicated tool fits. Same safety net: backup + rollback timer + stop on first error.

confirm_changesA

Disarm the rollback after verifying the change works; saves the new config locally.

rollback_nowC

Immediately restore the pre-change backup. The router REBOOTS.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.5/5.0

Scored across 22 tools

Disambiguation4/5

Most tools have clearly distinct purposes (e.g., configure_wifi vs firewall_baseline vs wireguard_create_interface). However, there is some overlap between run_command, apply_changes, and collect_info, and between connect, reconnect, and disconnect, which could cause minor confusion. The descriptions help clarify boundaries.

Naming Consistency5/5

All tool names follow a consistent snake_case verb_noun pattern. Examples include discover_routers, configure_wifi, validate_network, apply_changes, and wireguard_add_peer. There are no naming inconsistencies.

Tool Count4/5

22 tools is slightly on the higher side but appropriate for the breadth of functionality (session management, Wi-Fi, firewall, WireGuard, auditing, etc.). Each tool appears to serve a distinct purpose, though some could potentially be merged (e.g., connect/reconnect).

Completeness4/5

The tool set covers a wide range of MikroTik management tasks: discovery, connection, configuration, security, and WireGuard. Some areas might be missing, such as user management, logging, or advanced routing, but core workflows are well-supported.

Maintenance

ActivityMaintained
ResponsivenessNo issues