Check Point Management MCP Server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Check Point Management MCP ServerAdd access rule blocking 10.0.1.0/24 to 192.168.1.100 on port 443, then publish and install."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Check Point Management MCP Server
An MCP (Model Context Protocol) server for Check Point Management write-path workflows: draft an access rule, publish the session, install policy — the full compensating-control lifecycle, exposed as typed MCP tools with the same three-stage state machine as the real Management API.
Built with FastMCP v3. Originally built for a live orchestration demo at Tenable EXPOSURE 2026 (Boston), where an AI agent deployed a compensating firewall control for an unpatchable industrial asset under human supervision.
Why this exists
Check Point ships an official MCP server bundle. Its @chkp/quantum-management-mcp is the right read-side wrapper but is read-only by design — list rules, show objects, query topology, no writes. Compensating-control workflows (block traffic to an asset you can't patch yet) need add-access-rule, publish, and install-policy: an operator-supervised write path the official MCP intentionally doesn't expose.
This server fills that write-side gap with the three-stage lifecycle (draft → published → installed) matching the real Management API state machine — so an AI agent's audit trail reads exactly like a human operator's.
Related MCP server: ComplianceCow MCP Server
What it does (and doesn't)
Does: expose the write-path contract — tool signatures, rule lifecycle, response shapes — mirroring Check Point's Management API (add-access-rule, publish, install-policy, show-access-rulebase).
Doesn't (yet): contact a real Smart-1 or Security Management Server. The backend is in-memory, which makes it safe for demos, agent development, and workflow testing out of the box. For production, the in-memory backend swaps for the official cp_mgmt_api_python_sdk talking to Smart-1 Cloud or on-prem — tool signatures and response shapes do not change.
Tools
Tool | Lifecycle stage | Description |
| read | List current rules in an access layer |
| draft | Add a rule in the current session (status: |
| draft → published | Commit drafted rules to the management server |
| published → installed | Push published rules to gateways — the rule actually enforces |
The deliberate two-gate publish/install split mirrors real Check Point operator workflow, giving a supervising human two natural checkpoints before anything enforces.
Quick Start
Prerequisites
Python 3.11+
uv (recommended) or pip
No credentials needed — the backend is in-memory
Install & Run
git clone <repo-url> && cd checkpoint-mcp-server
uv sync
uv run checkpoint-mcp # stdio mode for Claude Desktop / Claude Code
uv run pytest -v # testsClaude Desktop Integration
{
"mcpServers": {
"checkpoint": {
"command": "uv",
"args": ["run", "--directory", "/path/to/checkpoint-mcp-server", "checkpoint-mcp"]
}
}
}Outputs
All tools return Markdown: rule tables with UID, source/destination/service/action, lifecycle status badges, and publish/install task summaries — shaped for LLM consumption and human-readable audit trails.
Stack
Python 3.11+, FastMCP v3, pydantic-settings, hatchling
Entry point:
checkpoint_mcp.server:main(CLI:checkpoint-mcp)In-memory state machine in
state.py; vendor-shaped mock seed data inmock/data.py
Limitations
In-memory backend: no real Check Point management server is contacted; state resets on restart. Production use requires swapping in the official SDK (interfaces are designed for it).
Access-control scope only: NAT rules, threat prevention, VPN, and object management are not covered.
Single session model: no concurrent session/locking semantics like a real multi-admin Management Server.
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/tarhou/checkpoint-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server