paloalto-mcp
Provides read-only monitoring and troubleshooting of Palo Alto Networks Panorama and PAN-OS firewalls via the PAN-OS XML API. It exposes tools for device inventory, health and resource checks, HA/license/certificate status, interfaces and counters, routing, sessions, VPN and GlobalProtect status, log searches, policy/NAT matching, security/NAT rule listing, and redacted configuration inspection.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@paloalto-mcpcheck the health of the main firewall: HA, CPU, memory, and disk"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
paloalto-mcp
A read-only Model Context Protocol (MCP) server that lets an AI agent inspect
Palo Alto Networks Panorama and PAN-OS firewalls for monitoring and troubleshooting, built for
OpenClaw Enterprise (OCE) on Ubuntu Server. It follows the same design as
the sibling extreme-mcp project.
It can look. It cannot change anything.
Talks to the PAN-OS XML API over HTTPS, either to a Panorama (which can proxy to the firewalls it manages) or to a firewall directly.
Runs as its own systemd service on the OCE host, bound to 127.0.0.1 only.
Credentials never leave the service. The agent receives results, not passwords.
Tools (24)
Group | Tool | What it returns |
Inventory |
| Approved devices (Panorama / firewalls), filter by name, site or kind |
| The firewalls a Panorama reports as managed, connection state, and which ones are not in the inventory | |
Health |
| Hostname, model, serial, PAN-OS and content versions, uptime |
| Management CPU, memory and load | |
| Filesystem usage; flags nearly full partitions | |
| HA enabled, local/peer state, config sync; flags problems | |
| Licences with days left; flags expired or expiring | |
| Device certificates, soonest expiry first; flags expired or expiring | |
| Recent jobs (commits, downloads), flags failures | |
Network |
| Interfaces with state, zone, IP, speed; flags down interfaces that are in a zone |
| Per-interface counters; | |
| Global drop counters (non-zero only), the quickest "why is traffic being dropped" view | |
| Routing table, default routes, filter by virtual router or destination | |
| The route the firewall would use for a destination (FIB lookup) | |
| Session table utilisation and rates | |
| Matching sessions (a filter is required) | |
| IKE gateways and IPsec tunnels; flags non-up | |
| Connected GlobalProtect users | |
Logs |
| Traffic, threat, system, config, URL, ... logs by a named window (15m to 7d) or the last N minutes (1 to 1440, measured on the firewall's own clock), with validated filters (source, destination, application, rule, action, severity) |
Policy |
| The firewall's own security-policy-match test: which rule would a flow hit |
| The firewall's own NAT-policy-match test | |
| Security or NAT rules (Panorama: per device group, pre or post) with filters | |
| A fixed section of the configuration (addresses, services, zones, system settings, ...) | |
| The running configuration, paged or searched |
Related MCP server: netmiko-mcp
Security model
The point is that a prompt-injected or confused agent cannot do harm through this server.
No write path exists. Operational commands come from a fixed table that contains only
showandtestcommands (plusrequest license info, which is read-only). Import-time assertions fail if anything else is added. There is no generic command runner, no commit, noset/edit/delete, no config load.Callers never supply XML or XPath. Each tool maps to a fixed command or XPath; variable parts (IP, port, zone, rule, application, interface, vsys, device group) are validated with strict patterns and then placed into the XML as escaped text.
Inventory allowlist. Every call names a device in the inventory. IPs and arbitrary hostnames are rejected before any request.
Use a read-only account. Create a dedicated admin role (XML API: operational requests, configuration read, logs and export allowed; commit, import and everything else off) and an account with it. The server logs in with that username and password (keygen) and keeps the session key in memory only; a pre-generated API key also works. Even if the software were bypassed, the device enforces read-only.
TLS: by default each device's own certificate is pinned (
certs/<name>.pem, approved by you after checking the fingerprint), since management interfaces usually use self-signed certificates.tls: causes normal CA verification instead.Loopback only, secrets as systemd credentials, per-call JSON audit log, hardened systemd unit.
Treat device text as data. Log entries and object names come from the network and can contain attacker-influenced text.
Configuration redaction
Firewall configurations contain password hashes, pre-shared keys, SNMP communities and RADIUS/TACACS secrets. Unlike the
switch project, get_config and get_config_section therefore redact by default: values of elements whose names mean
secret (password, phash, secret, community, psk, key, token, ...) and PEM blocks are replaced with REDACTED. It is best-effort
(a secret under an unexpected element name could be missed), so the output is still sensitive. Set CONFIG_REDACT=false
in /etc/paloalto-mcp/paloalto-mcp.env to return configuration unfiltered for administrators.
Inventory
/etc/paloalto-mcp/inventory.yaml (server only; see inventory.example.yaml). Entries need mcp_enabled: true.
kind: panoramawithaddress.kind: firewallwithvia: <panorama name>andserial(queried through the Panorama withtarget=<serial>; uses the Panorama's key and certificate), or withaddress(queried directly).Optional:
site,model,credential(use keypanos_key_<credential>),tls(pinnedorca),vsys.
Credentials are panos_user_<name> + panos_pass_<name> (or panos_key_<name>), where <name> is panorama, firewall or the entry's credential. Keep the real inventory out of git.
Adding the firewalls a Panorama manages
import-panorama.py is an administrator tool (not an MCP tool, so an agent cannot change the device list). It reads the firewalls
a Panorama manages and adds them to the inventory as direct connections, pinning each device certificate. It runs as root
on the server, because it uses the stored Panorama login and writes to /etc/paloalto-mcp.
sudo /opt/paloalto-mcp/venv/bin/python /opt/paloalto-mcp/import-panorama.py <panorama name>Review (writes nothing): for every firewall it prints name, management IP, model, certificate subject, SHA256 fingerprint, expiry and issuer, and whether pinning will work. Devices with an expired or CA-only certificate, or that cannot be reached, are listed with the reason and are not added. It ends with a review code.
Write:
... --write --confirm <review code>scans again and applies only if every certificate still matches what was reviewed. It appends the entries (existing ones and comments are untouched), writescerts/<name>.pem, keeps a timestamped backup of the inventory, checks the result loads, and rolls everything back on failure. Then restart the service.
Refreshing pins. Factory certificates expire, and a pin matches one exact certificate, so run
import-panorama.py --refresh now and then (no Panorama needed). It re-checks every pinned firewall, lists those whose
certificate changed (old and new fingerprint, expiry, common name) and any that expire within 90 days, and ends with a review
code. --refresh --write --confirm <code> re-pins only what you reviewed and keeps the old file as <name>.pem.bak-<time>.
Restart the service afterwards.
Firewalls already in the inventory (same serial or address) are skipped. Options: --all (include disconnected firewalls),
--only TEXT. Direct connections use the shared read-only login panos_user_firewall / panos_pass_firewall.
Deploy
bash install.sh # user, dirs, venv, code, unit
vi /etc/paloalto-mcp/inventory.yaml
bash set-secret.sh panos_user_firewall # prompts without echo; then panos_pass_firewall (or *_panorama)
/opt/paloalto-mcp/venv/bin/python /opt/paloalto-mcp/scan-cert.py panorama.example.net | sudo tee /etc/paloalto-mcp/certs/pan-primary.pem
sudo systemctl enable --now paloalto-mcp && sudo ss -lntp | grep ':8766' # must show 127.0.0.1Compare the fingerprint scan-cert.py prints with the one on the device before saving the certificate.
Register in OCE:
openclaw mcp add paloalto-network-readonly --transport streamable-http --url http://127.0.0.1:8766/mcp
openclaw mcp tools paloalto-network-readonlyWith a small local model, give the firewall tools to a separate agent (or use --include) rather than one agent with every network tool.
Configuration
Variable | Default | |
| 127.0.0.1 / 8766 | loopback only |
| /etc/paloalto-mcp/inventory.yaml | |
| JSON line per call | |
| /etc/paloalto-mcp/certs | pinned certificates |
| system | for |
| 30 / 6 | |
| true | see above |
Development
python -m venv .venv && .venv/bin/pip install -r requirements-dev.txt
.venv/bin/python -m pytestTested on real devices: a full Panorama (with its managed firewalls and device groups), and PA-440, PA-850 and PA-3220 firewalls,
all running a supported PAN-OS release. Response layouts for some commands vary by PAN-OS version and model, so parsers are
tolerant, and each tool reports parse_warnings with the raw result when it cannot recognise a response. Verify against your own
devices after deploying.
Licence
See LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Read-only local AI advice, shared reports and website audits. No PC scan or local actions.
Read-only MCP access to a documented IT fleet: state, changes, posture. 15 tools.
Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.
Read-only finance and operations controls for AI agents with evidence and safe next actions.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables secure, read-only monitoring of Cisco Meraki networks, allowing AI agents to query real-time information on organizations, networks, devices, clients, and traffic without risk of configuration changes.MIT
- AlicenseAqualityBmaintenanceProvides read-only SSH access to network devices (routers, switches, firewalls) with command allow/deny policies, nt-templates output parsing, and an audit trail, enabling an AI agent to query device state securely.10MIT
- AlicenseNot gradedqualityBmaintenanceProvides read-only, multi-vendor network device interaction, configuration auditing against vendor-guide rules, and safe diffing of proposed changes for AI agents to inspect and analyze network infrastructure without any commit or write capability.Apache 2.0
- AlicenseAqualityBmaintenanceEnables language models to read FortiGate/FortiOS firewalls and answer operational questions about firewall policies, network configuration, and live client state. Provides question-shaped diagnostic tools for reference checks, configuration searches, device lookups, routing, DHCP, ARP, wireless clients, and multi-appliance targeting without allowing configuration changes.17Apache 2.0