Skip to main content
Glama
ry-ops

fortigate-mcp-server

by ry-ops

delete_port_forward

Delete a port forward (VIP) on FortiGate; if a policy uses it, set detach=true to remove it from policies first, or the delete is blocked.

Instructions

Delete a VIP. FortiOS refuses while a policy uses it; detach=true first removes it from every policy's destinations. A policy whose only destination is this VIP blocks the delete: change or delete that policy first.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesVIP name
vdomNoVDOM (default: FORTIGATE_VDOM, usually root)
detachNoRemove the VIP from policies first (default false)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.4.1

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral burden and does it well: it discloses the failure condition (policy still references the VIP), the effect of detach=true (removes the VIP from every policy's destinations), and the hard blocker case (sole destination policy). It stops short of auth/permission or response details, but the destructive semantics are clearly conveyed.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the core action ('Delete a VIP') then layers the conditional behavior in three tight sentences. No filler, though the conditional clauses could be slightly denser.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive tool with no annotations and no output schema, the description covers the important edge cases (in-use refusal, sole-destination blocker) and the detach workflow. Missing only ancillary details such as permission requirements, which for this domain are minor.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents name, vdom, and detach; baseline is 3. The description adds some behavioral meaning to detach ('removes it from every policy's destinations') but leaves name/vdom to the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Delete a VIP') that clearly identifies the operation. It maps to the port-forward VIP concept matching the tool name and its list_port_forwards/create_port_forward siblings, though it doesn't explicitly name those siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives concrete usage context: it tells the agent the delete will be refused while a policy uses the VIP, offers detach=true as the workaround, and warns that a policy whose only destination is this VIP blocks the delete. This is actionable pre-invocation guidance, though it is framed as prerequisites rather than as tool selection.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.