Sophos Firewall MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| USE_ROUTER | No | Set 'true' to enable FastEmbed semantic tool routing (default: false) | |
| SOPHOS_HOST | No | Sophos Firewall IP address or FQDN (default: 172.16.16.16) | |
| SOPHOS_PORT | No | Web Console API port (default: 4444) | |
| SOPHOS_TIMEOUT | No | API request timeout in seconds (default: 30.0) | |
| SOPHOS_PASSWORD | Yes | API Administrator Password (required) | |
| SOPHOS_USERNAME | No | API Administrator Username (default: admin) | |
| SOPHOS_VERIFY_SSL | No | Verify SSL/TLS certificates (set 'false' for self-signed certs, default: false) | |
| SOPHOS_API_VERSION | No | Sophos XML API Version (default: 2200.1) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| sophos_raw_api_requestA | Execute a low-level, generic Sophos Firewall XML API operation. Use when executing custom or low-level SFOS XML API calls for tags or configuration settings not supported by dedicated high-level tools. Args: operation: API operation type ('Get', 'Set', or 'Remove'). tag: Target Sophos XML entity tag. params: Optional payload dictionary or search filter criteria. client: Optional SophosFirewallClient instance. Returns: Parsed API response dictionary or object list. |
| sophos_get_system_infoA | Retrieve system information including appliance model, firmware version, serial number, and uptime. Use when inspecting hardware/firmware details and overall system status. Args: client: Optional SophosFirewallClient instance. Returns: System information parameters from Sophos Firewall. |
| sophos_get_service_statusA | Retrieve current operational status of system services (DNS, DHCP, IPS, Web Protection, AntiVirus). Use when monitoring background service health or diagnosing firewall subsystem failures. Args: client: Optional SophosFirewallClient instance. Returns: Status details of core firewall services. |
| sophos_get_interface_listA | List network interfaces with configuration, IP addresses, network zones, and link state. Use when inspecting physical or virtual interface configurations, subnets, and link states. Args: client: Optional SophosFirewallClient instance. Returns: List or dict of network interface configurations. |
| sophos_list_firewall_rulesA | List firewall security rules configured on the appliance. Use when browsing security policies or searching for rules matching a specific name. Args: name: Optional firewall rule name filter. client: Optional SophosFirewallClient instance. Returns: List or dict of firewall rule configurations. |
| sophos_get_firewall_ruleA | Retrieve details for a specific firewall rule by name. Use when inspecting full policy configuration for a single firewall rule. Args: name: Name of the firewall rule. client: Optional SophosFirewallClient instance. Returns: Firewall rule configuration. |
| sophos_create_firewall_ruleA | Create a new IPv4 firewall security rule. Use when defining new network access control policies between zones and host objects. Args: name: Unique name for the firewall rule. action: Rule policy action ('Accept', 'Drop', or 'Reject'). Default is 'Accept'. source_zones: List of source network zone names (e.g. ['LAN']). destination_zones: List of destination network zone names (e.g. ['WAN']). source_networks: List of source host/network object names (e.g. ['Any']). destination_networks: List of destination host/network object names (e.g. ['Any']). services: List of service object names (e.g. ['HTTP', 'HTTPS']). status: Rule status ('Enable' or 'Disable'). Default is 'Enable'. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_update_firewall_ruleA | Update configuration fields on an existing firewall rule. Use when modifying parameters such as logging, action, zones, host objects, or status on an existing security policy. Args: name: Name of the firewall rule to update. action: Optional new rule policy action ('Accept', 'Drop', or 'Reject'). source_zones: Optional list of source network zone names. destination_zones: Optional list of destination network zone names. source_networks: Optional list of source host/network object names. destination_networks: Optional list of destination host/network object names. services: Optional list of service object names. log_traffic: Optional logging setting ('Enable' or 'Disable'). status: Optional rule status ('Enable' or 'Disable'). client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_update_firewall_rule_statusA | Enable or disable an existing firewall rule. Use when toggling a security policy active state without deleting the rule. Args: name: Name of the firewall rule. status: Desired state ('Enable' or 'Disable'). client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_delete_firewall_ruleA | Delete a firewall rule by name. Use when permanently removing an obsolete security policy. Args: name: Name of the firewall rule to delete. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_list_ip_hostsA | List IP host objects defined on Sophos Firewall. Use when browsing IP address, network subnet, or IP range objects. Args: name: Optional IP host name filter. client: Optional SophosFirewallClient instance. Returns: List or dict of IP host objects. |
| sophos_get_ip_hostA | Retrieve configuration details for a specific IP host object. Use when inspecting target IP address or subnet definition for an object. Args: name: Name of the IP host object. client: Optional SophosFirewallClient instance. Returns: IP host configuration. |
| sophos_create_ip_hostA | Create a new IP host object (IP Address, Network, IP Range, or IP List). Use when registering host IP or network subnet definitions for firewall policies. Args: name: Unique name for the host object. host_type: Type of host object ('IP', 'Network', 'IPRange', or 'IPList'). Default is 'IP'. ip_address: IP address or starting IP address/subnet. subnet_mask: Subnet mask if host_type is 'Network' (e.g. '255.255.255.0' or '24'). ip_family: IP protocol family ('IPv4' or 'IPv6'). Default is 'IPv4'. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_delete_ip_hostA | Delete an IP host object by name. Use when deleting unused IP host objects from the firewall database. Args: name: Name of the IP host to remove. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_list_ip_host_groupsA | List IP host groups configured on Sophos Firewall. Use when viewing grouped IP host definitions used in rule sets. Args: name: Optional group name filter. client: Optional SophosFirewallClient instance. Returns: List or dict of IP host groups. |
| sophos_create_ip_host_groupA | Create an IP host group containing multiple IP host objects. Use when bundling multiple IP host objects together for unified security policies. Args: name: Unique name for the host group. host_list: List of IP host object names to include in the group. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_delete_ip_host_groupA | Delete an IP host group by name. Use when deleting an obsolete host group object from Sophos Firewall. Args: name: Name of the host group to remove. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_list_fqdn_hostsA | List FQDN (Fully Qualified Domain Name) host objects. Use when inspecting domain-based network host objects. Args: name: Optional FQDN host name filter. client: Optional SophosFirewallClient instance. Returns: List or dict of FQDN host objects. |
| sophos_create_fqdn_hostA | Create a new FQDN host object. Use when defining domain name target objects for firewall or NAT rules. Args: name: Unique name for the FQDN host object. fqdn: Fully qualified domain name (e.g. 'api.example.com'). client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_delete_fqdn_hostA | Delete an FQDN host object by name. Use when deleting domain-based host objects from Sophos Firewall. Args: name: Name of the FQDN host object to remove. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_list_servicesA | List service objects (TCP, UDP, ICMP, IP protocol definitions). Use when inspecting custom or predefined port and protocol definitions. Args: name: Optional service name filter. client: Optional SophosFirewallClient instance. Returns: List or dict of service definitions. |
| sophos_get_serviceA | Retrieve details of a specific service definition. Use when verifying target port ranges or protocol parameters for a service. Args: name: Name of the service object. client: Optional SophosFirewallClient instance. Returns: Service definition configuration. |
| sophos_create_serviceA | Create a custom TCP/UDP service definition. Use when adding new port or protocol definitions for firewall rules. Args: name: Unique name for the service definition. protocol: Protocol type ('TCP', 'UDP', 'TCP/UDP', or 'ICMP'). Default is 'TCP'. source_port: Source port range (e.g. '1:65535'). Default is '1:65535'. destination_port: Destination port or port range (e.g. '8080' or '8000:8080'). client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_delete_serviceA | Delete a custom service definition object by name. Use when deleting obsolete service port definitions from Sophos Firewall. Args: name: Name of the service object to delete. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_list_service_groupsA | List service group objects configured on Sophos Firewall. Use when browsing bundled groups of services used in rule policies. Args: name: Optional service group name filter. client: Optional SophosFirewallClient instance. Returns: List or dict of service groups. |
| sophos_create_service_groupA | Create a new service group object. Use when bundling multiple service port definitions into a single named group for security rules. Args: name: Unique name for the service group. service_list: List of service object names to include in the group. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_delete_service_groupA | Delete a service group object by name. Use when removing an obsolete service group definition from Sophos Firewall. Args: name: Name of the service group to remove. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_list_nat_rulesA | List NAT and DNAT port-forwarding rules on Sophos Firewall. Use when reviewing Network Address Translation rules and port forwarding. Args: name: Optional NAT rule name filter. client: Optional SophosFirewallClient instance. Returns: List or dict of NAT rules. |
| sophos_get_nat_ruleA | Retrieve detailed configuration of a specific NAT rule. Use when auditing original/translated source, destination, and service parameters. Args: name: Name of the NAT rule. client: Optional SophosFirewallClient instance. Returns: NAT rule configuration details. |
| sophos_create_nat_ruleA | Create a Network Address Translation (NAT or DNAT) rule. Use when defining port forwarding, SNAT masquerading, or DNAT inbound translation rules. Args: name: Unique name for the NAT rule. status: Rule status ('Enable' or 'Disable'). Default is 'Enable'. original_source: Original source host/network object names. original_destination: Original destination host/network object names. original_service: Original service object names. translated_source: Translated source object ('MASQUERADE', 'Original', etc.). translated_destination: Translated destination host/network object. translated_service: Translated service object name. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_update_nat_ruleA | Update fields on an existing NAT rule. Use when updating status or target translation parameters on an existing NAT or port-forwarding rule. Args: name: Name of the NAT rule to update. status: Optional new status ('Enable' or 'Disable'). translated_source: Optional new translated source object. translated_destination: Optional new translated destination object. translated_service: Optional new translated service object. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_delete_nat_ruleA | Delete a NAT rule by name. Use when permanently removing a NAT or port-forwarding policy. Args: name: Name of the NAT rule to remove. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_list_usersA | List local user accounts configured on Sophos Firewall. Use when browsing local user accounts and group memberships. Args: username: Optional username filter. client: Optional SophosFirewallClient instance. Returns: List or dict of user accounts. |
| sophos_get_userA | Retrieve details for a specific local user account. Use when inspecting permissions, email, or profile settings for a user. Args: username: Username of the user account. client: Optional SophosFirewallClient instance. Returns: User account details. |
| sophos_create_userA | Create a new local user account on Sophos Firewall. Use when registering new local user accounts for VPN or portal access. Args: username: Login username for the account. name: Full display name of the user. password: User login password. group: User group name (e.g. 'Open Group' or 'Administrator'). Default is 'Open Group'. email: Optional user email address. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_delete_userA | Delete a local user account by username. Use when removing obsolete or revoked user accounts from Sophos Firewall. Args: username: Username of the account to delete. client: Optional SophosFirewallClient instance. Returns: API response status dictionary. |
| sophos_list_live_usersA | List active logged-in user sessions on Sophos Firewall. Use when monitoring live user logins, active session counts, or connected users. Args: client: Optional SophosFirewallClient instance. Returns: List or dict of live user sessions. |
| sophos_list_ipsec_vpnsA | List IPsec site-to-site VPN connection configurations and status. Use when inspecting site-to-site IPsec tunnel states and gateway parameters. Args: client: Optional SophosFirewallClient instance. Returns: List or dict of IPsec VPN connections. |
| sophos_list_sslvpn_policiesA | List SSL VPN remote access policies configured on Sophos Firewall. Use when viewing user access policies, SSL VPN IP pools, and permitted networks. Args: client: Optional SophosFirewallClient instance. Returns: List or dict of SSL VPN remote access policies. |
| route_toolsA | Find relevant Sophos Firewall tools matching a natural language prompt. Args: query: Natural language task description or question. top_k: Number of relevant tools to return. Default is 5. Returns: List of matching tool schema definitions or status string. |
| call_routed_toolB | Dynamically execute a routed tool by name with arguments. Args: tool_name: Name of the registered tool to call. arguments: Optional dictionary of arguments to pass to the tool function. Returns: Result of the executed tool function. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| audit_firewall_rules | Prompt template for conducting a security audit of firewall rules. Args: focus_zone: Network zone to audit (e.g. 'WAN', 'LAN', 'DMZ'). Default is 'WAN'. |
| troubleshoot_connectivity | Prompt template for troubleshooting network connectivity issues between hosts. Args: source_ip: IP address or host name attempting connection. destination_ip: Target destination IP address or service. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| get_system_info_resource | Resource providing system details, appliance model, serial number, and firmware version. |
| get_interfaces_resource | Resource providing network interface configuration, zones, and link state. |
| get_service_status_resource | Resource providing operational status of core firewall background services. |
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jelmervdm/sophos-firewall-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server