Best OPNSense MCP Servers
OPNsense is an open source, easy-to-use and easy-to-build HardenedBSD based firewall and routing platform.
Why this server?
Provides bounded access to OPNsense using a URL and API key/secret for exact-object reads, with writes enabled only when explicitly turned on.
AlicenseAqualityAmaintenanceProvides a secure, job-oriented MCP connector for NetBox device lookup, enabling retrieval of device identity, status, site, role, and primary IP by name or ID without write access or bulk enumeration.5Apache 2.0Why this server?
Enables comprehensive management of OPNsense firewall infrastructure via its REST API, including tools for firewall rules, DNS overrides, DHCP mappings, system diagnostics, configuration backups, and service control.
AlicenseAqualityDmaintenanceSlim OPNsense MCP Server — 62 tools for managing firewall infrastructure via the OPNsense REST API. Covers DNS/Unbound, Firewall rules, Diagnostics, Interfaces, DHCP (ISC + Kea), System/Backups, ACME/Let's Encrypt, and Firmware. No SSH, no shell, API-only with 3 runtime dependencies. AGPL-3.0 + Commercial dual-licensed.10054 npm2AGPL 3.0Why this server?
Provides tools for managing OPNsense firewall operations, including ARP, DHCP, logs, rules, interfaces, system status, and packet capture.
AlicenseBqualityAmaintenanceOPNsense firewall operations via API & mcp. Query ARP, DHCP, firewall rules, logs, interfaces, system status, and packet capture via STDIO or SSE.1410MITWhy this server?
Provides tools for managing OPNsense firewalls, including system status, firewall rules, network diagnostics, DNS, DHCP, VPN, HAProxy, services, and security settings.
AlicenseAqualityBmaintenanceA secure MCP server for managing OPNsense firewalls through AI assistants. Provides 81 tools across system, firewall, network, DNS, DHCP, VPN, HAProxy, services, diagnostics, and security domains.81232 PyPI21MITWhy this server?
Provides tools to manage firewall rules, view network interfaces, manage DHCP leases, and monitor system status on an OPNsense firewall.
AlicenseAqualityCmaintenanceEnables interaction with OPNsense firewalls through MCP tools for managing firewall rules, interfaces, DHCP leases, and system monitoring.26MITWhy this server?
Inspects OPNsense config.xml changes and firewall rule modifications, providing risk assessment, shadowing notes, and embedded certificate checks.
AlicenseAqualityBmaintenanceProvides read-only network engineering analysis by parsing configs and logs to explain config changes, check CIS/PCI compliance, diagnose 802.1X issues, find embedded certificates, infer topology, and assess proposed changes before pushing them.12MITWhy this server?
Provides comprehensive firewall operations for OPNsense appliances: reading firmware, health, interfaces, gateways, rules, NAT, aliases, VPN (WireGuard/OpenVPN/IPsec), DHCP, and firewall logs, plus governed writes such as toggling rules, editing aliases, restarting services, applying staged changes, and rebooting.
AlicenseAqualityAmaintenanceGoverned OPNsense + pfSense firewall operations — gateway-health, rule-shadow, and blocked-traffic RCA, with guarded rule/alias writes, unbypassable audit logging (MCP + CLI), budget/runaway guards, dry-run, and undo/rollback.35MITWhy this server?
Enables monitoring of OPNsense firewall status and restarting services through the OPNsense API.
FlicenseAqualityDmaintenanceEnables Claude to monitor and manage homelab infrastructure including Docker containers, OPNsense firewall, and TrueNAS storage with configurable capability levels from read-only monitoring to full management control.137 npm7-Why this server?
Provides tools for managing OPNsense firewalls, including device management, configuration sync, health checks, firmware upgrades, backups, and remote console access.
AlicenseNot gradedqualityAmaintenanceManage a fleet of OPNsense firewalls from an AI agent, inside guardrails it can't drive around. MCP server for central management of OPNsense firewall fleets. 129 tools across devices, config sync, tasks, schedules, templates, backups and remote consoles - destructive actions confirmation-gated, MCP-issued tokens lifetime-bounded, backup and storage secrets excluded from the toolset entirely.Apache 2.0