fortigate-mcp-server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| K8S_CONTEXT | No | Kubernetes context to use with K8S_KUBECONFIG. | |
| PROXMOX_HOST | No | Proxmox VE host; enables the Proxmox tools with PROXMOX_USER, PROXMOX_TOKEN_NAME and PROXMOX_TOKEN_VALUE. | |
| PROXMOX_PORT | No | Proxmox VE port. | |
| PROXMOX_USER | No | Proxmox VE user. | |
| FORTIGATE_HOST | Yes | Hostname or IP of the FortiGate. | |
| FORTIGATE_PORT | No | HTTPS admin port. | 443 |
| FORTIGATE_VDOM | No | VDOM for every call (tools also take vdom). | root |
| K8S_KUBECONFIG | No | Kubernetes kubeconfig path; enables the Kubernetes tools. | |
| FORTIGATE_TIMEOUT | No | Request timeout in seconds. | 30 |
| FORTICLOUD_ACCOUNT | No | FortiCloud account, only for activate_vm_eval_license (main FortiCloud account, 2FA off). | |
| FORTIGATE_PASSWORD | No | Session login password, used when no token is set (needed on an unlicensed VM). | |
| FORTIGATE_USERNAME | No | Session login username, used when no token is set (needed on an unlicensed VM). | |
| PROXMOX_TOKEN_NAME | No | Proxmox VE token name. | |
| PROXMOX_VERIFY_SSL | No | Verify the Proxmox TLS certificate. | |
| FORTICLOUD_PASSWORD | No | FortiCloud password, only for activate_vm_eval_license. | |
| FORTIGATE_API_TOKEN | No | REST API admin token (recommended). | |
| FORTIGATE_READ_ONLY | No | Refuse every POST/PUT/DELETE before it reaches the FortiGate. | false |
| PROXMOX_TOKEN_VALUE | No | Proxmox VE token value. | |
| FORTIGATE_VERIFY_SSL | No | Verify the TLS certificate. | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_system_statusC | FortiGate model, serial, firmware version/build, hostname and uptime. |
| get_license_statusA | License and FortiGuard contract status. By default returns only the VM license, FortiCare and FortiGuard sections; set all=true for every entitlement. An unlicensed FortiGate-VM reports vm.status=vm_invalid and refuses most other API calls with 401. |
| get_license_limitsB | How much of the license's object limits is used. The free FortiGate-VM evaluation license allows 1 vCPU, 2 GB RAM and at most 3 interfaces, 3 firewall policies and 3 static routes; this lists what counts against each so you can plan before hitting one. |
| get_resource_usageC | Current CPU, memory, disk and session usage. |
| list_interfacesB | List interface configuration (IP, mode, role, alias, allowaccess). |
| get_interfaceC | Get one interface's full configuration. |
| get_interface_statusB | Live interface state: link, speed, IP and traffic counters. |
| update_interfaceA | Update an interface. Changing the interface this server connects through (its IP, mode or allowaccess) can cut off API access, so double-check those changes. |
| list_admin_sessionsC | Administrators currently logged in (GUI, SSH, API) and where from. |
| backup_configA | Back up the full running configuration (FortiOS CLI text) to a local file and return its path and size. Allowed in read-only mode. Configs are hundreds of KB, so the text itself is not returned. |
| forticonverter_setup_promptA | Show or hide the 'Migrate Config with FortiConverter' step of the GUI's FortiGate Setup popup. Without hide, only reports the current state. FortiGate-VM evaluation licenses are not eligible for FortiConverter, so that step never completes and the popup reappears at every login until it is hidden. There is no CLI equivalent. |
| activate_vm_eval_licenseA | Activate the free permanent evaluation license on an unlicensed FortiGate-VM by logging in to FortiCloud from the FortiGate (the same call the GUI makes). The FortiCloud account comes from the FORTICLOUD_ACCOUNT and FORTICLOUD_PASSWORD environment variables, never from tool arguments. The FortiGate reboots to apply it. Unlicensed VMs refuse most API calls, so use session auth (FORTIGATE_USERNAME/PASSWORD) on a fresh VM. FortiCare error 10 means wrong credentials, an IAM sub-user, or 2FA on the account. |
| list_firewall_policiesC | List IPv4 firewall policies in evaluation order. |
| get_firewall_policyC | Get one firewall policy. |
| create_firewall_policyA | Create a firewall policy. New policies are added at the end of the list; use move_firewall_policy to reorder. FortiGate-VM evaluation licenses allow only 3 policies. |
| update_firewall_policyA | Update a firewall policy. Only the fields given change; list fields are replaced, not appended. |
| delete_firewall_policyC | Delete a firewall policy. |
| move_firewall_policyB | Move a policy before or after another one (policies match top-down). |
| get_policy_statsC | Hit counts, bytes, packets and last-used time per policy. |
| list_sessionsC | Current firewall sessions, optionally filtered. |
| list_addressesC | List firewall address objects. |
| get_addressC | Get one firewall address object. |
| create_addressC | Create a firewall address: a subnet/host, an IP range, or an FQDN. |
| update_addressC | Update a firewall address object. |
| delete_addressA | Delete a firewall address (fails while a policy or group still uses it). |
| list_address_groupsB | List firewall address groups and their members. |
| create_address_groupC | Create an address group. |
| update_address_groupB | Update an address group. members replaces the whole member list. |
| delete_address_groupA | Delete an address group (fails while a policy still uses it). |
| list_servicesC | List custom firewall services (port definitions). |
| create_serviceC | Create a custom TCP/UDP service. |
| list_service_groupsC | List service groups and their members. |
| create_service_groupA | Create a service group, e.g. K3S-MGMT = [SSH, K8S-API, PING]. Grouping services lets one policy cover what would otherwise need several, which helps under the evaluation license's 3-policy limit. |
| update_service_groupB | Update a service group. members replaces the whole member list. |
| delete_service_groupA | Delete a service group (fails while a policy still uses it). |
| delete_serviceA | Delete a custom service (fails while a policy still uses it). |
| list_port_forwardsB | List virtual IPs (port forwards / static NAT) and the policies that use each one. |
| create_port_forwardA | Create a port forward (VIP): traffic arriving on extintf at extip:extport goes to mappedip:mappedport. A VIP only passes traffic once a policy from extintf uses it as a destination. With attach_to_policy, the VIP is added to that existing policy's destinations instead of needing a new policy (the evaluation license allows only 3). FortiOS does not allow VIPs and ordinary addresses in the same policy's destinations, so the target must already use only VIPs, or pass replace_destinations=true to turn it into a VIP-only policy (its old destinations stop being reachable through it). In that policy, services match the mapped (internal) port. |
| delete_port_forwardA | Delete a VIP. FortiOS refuses while a policy uses it; detach=true first removes it from every policy's destinations. A policy whose only destination is this VIP blocks the delete: change or delete that policy first. |
| search_applicationsA | Search application-control signatures by name (contains, case-insensitive) and/or category, e.g. query=YouTube or category=P2P. Returns id, name, category and risk. |
| list_app_categoriesB | Application-control categories (id and name), e.g. P2P, Proxy, Game, Video/Audio. |
| list_app_control_profilesB | App-control profiles with their rules, showing application and category names instead of ids. |
| add_app_control_ruleA | Add a rule to an app-control profile matching applications and/or categories by name (or id). Rules are checked top-down and the built-in profiles start with a catch-all pass rule, so new rules are inserted at the top by default (position=bottom to append). Only affects policies whose application_list is this profile. |
| delete_app_control_ruleB | Remove a rule from an app-control profile by its id (see list_app_control_profiles). |
| list_ssl_ssh_profilesA | List SSL/SSH inspection profiles with the CA each one re-signs with. The built-in no-inspection, certificate-inspection and deep-inspection profiles are read-only; edit custom-deep-inspection or a copy instead. |
| update_ssl_ssh_profileB | Update an SSL/SSH inspection profile, e.g. the CA used to re-sign certificates during deep inspection. Clients must trust that CA, and FortiGate-VM evaluation licenses re-sign RSA sites with 512-bit keys regardless of the CA, which modern clients reject. |
| list_certificatesA | List local and CA certificates with key type and size, validity and usage flags. Certificates with RSA keys under 2048 bits are flagged weak: FortiGate-VM evaluation licenses generate 512-bit factory certificates. Bundled public CAs are omitted unless include_bundle is true. |
| download_certificateA | Download a certificate's PEM (public part only), e.g. the deep-inspection CA Fortinet_CA_SSL so clients can be told to trust it. Returns the PEM and its SHA-256 fingerprint. |
| get_top_trafficA | Live FortiView summary of the sessions passing through right now, grouped by source, destination, application, country, interface, policy or protocol. Destinations include the resolved hostname; application IDs are translated to names. Empty when nothing is flowing (it reflects current sessions, not history). |
| get_arp_tableB | IPv4 ARP table: which MAC answers for which IP on each interface. |
| get_logsA | Read FortiGate logs, newest first. Useful types: traffic/forward (sessions through policies, with app identification), app-ctrl (per-connection application and, with certificate inspection, the HTTPS hostname), event/system (admin and config events), ips, webfilter. FortiGate-VMs without a log disk only keep logs in memory, which is lost on reboot. |
| get_routing_tableB | Active IPv4 routing table (connected, static, DHCP-learned and dynamic routes). |
| list_static_routesC | List configured static routes. |
| create_static_routeB | Add a static route. FortiGate-VM evaluation licenses allow only 3 routes. |
| delete_static_routeA | Delete a static route by its sequence number (seq-num from list_static_routes). |
| get_dns_settingsC | System DNS settings: upstream resolvers the FortiGate itself uses and forwards to. |
| list_dns_serversC | Interfaces where the FortiGate answers DNS queries, and in which mode. |
| set_dns_serverA | Serve DNS on an interface. Modes: recursive (local zones first, then forward to the system resolvers), non-recursive (local zones only), forward-only. |
| delete_dns_serverC | Stop serving DNS on an interface. |
| list_dns_zonesB | List local DNS zones (dns-database) with their records. |
| create_dns_zoneB | Create a local DNS zone. view=shadow serves internal clients. FortiOS does not accept wildcard (*) hostnames, so add one record per name. |
| delete_dns_zoneB | Delete a local DNS zone and all its records. |
| add_dns_recordB | Add a record to a local DNS zone. Wildcard (*) hostnames are rejected by FortiOS. |
| delete_dns_recordB | Delete a record from a local DNS zone by its id (see list_dns_zones). |
| list_dhcp_serversB | List DHCP servers with their ranges, options and reservations. |
| list_dhcp_leasesC | Current DHCP leases handed out by the FortiGate. |
| update_dhcp_serverB | Update a DHCP server. Note: vci_match=true makes the server answer only clients whose vendor class matches vci-string (FortiOS defaults to FortiSwitch/FortiExtender), which silently ignores ordinary clients. |
| add_dhcp_reservationA | Reserve an IP for a MAC address on a DHCP server (the IP may sit outside the pool). |
| delete_dhcp_reservationC | Remove a DHCP reservation by its id (see list_dhcp_servers). |
| fortigate_apiA | Call any FortiOS REST endpoint directly. path must start with /api/v2/ (cmdb/... for configuration, monitor/... for live state). FORTIGATE_READ_ONLY still applies. Prefer the dedicated tools when one exists. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 70 tools
While many tools have distinct resource+action purposes, there is significant overlap in generic tools such as fortigate_api (which can do anything) and get_system_status/get_resource_usage/get_license_status all providing system-level info. Some naming like get_interface_status vs get_interface vs list_interfaces could confuse, though descriptions help.
Most tools follow a consistent verb_noun pattern (e.g., list_, get_, create_, update_, delete_), with a few exceptions like backup_config, activate_vm_eval_license, and fortigate_api which are action-oriented but still descriptive. Overall predictable.
70 tools is heavy for a single MCP server, likely overwhelming for an agent and increasing selection complexity. It covers many FortiGate domains but may be better split into sub-servers by function.
The tool set provides comprehensive coverage across interfaces, policies, addresses, services, certificates, DNS, DHCP, routing, logs, and more. CRUD operations are present for most resources, with no obvious dead ends for the stated purpose.