OPNSense MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| OPNSENSE_HOST | Yes | The URL of your OPNsense firewall (e.g., https://your-opnsense-host:port) | |
| OPNSENSE_API_KEY | Yes | Your OPNsense API key | |
| OPNSENSE_SSH_HOST | No | Your OPNsense SSH host (optional, for advanced features) | |
| OPNSENSE_API_SECRET | Yes | Your OPNsense API secret | |
| OPNSENSE_VERIFY_SSL | No | Whether to verify SSL certificates | false |
| OPNSENSE_SSH_KEY_PATH | No | Path to SSH private key file (alternative to password) | |
| OPNSENSE_SSH_PASSWORD | No | Your OPNsense SSH password (optional, for advanced features) | |
| OPNSENSE_SSH_USERNAME | No | Your OPNsense SSH username (optional, for advanced features) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| configureC | Configure OPNsense connection |
| list_vlansB | List all VLANs |
| get_vlanC | Get VLAN details |
| create_vlanC | Create a new VLAN |
| delete_vlanC | Delete a VLAN |
| update_vlanC | Update VLAN description |
| list_firewall_rulesC | List all firewall rules |
| get_firewall_ruleC | Get firewall rule details |
| create_firewall_ruleC | Create a new firewall rule |
| create_firewall_presetC | Create a firewall rule from a preset |
| update_firewall_ruleC | Update a firewall rule |
| delete_firewall_ruleC | Delete a firewall rule |
| toggle_firewall_ruleC | Toggle firewall rule enabled/disabled |
| find_firewall_rulesC | Find firewall rules by description |
| create_backupC | Create a configuration backup |
| list_backupsB | List available backups |
| restore_backupC | Restore a configuration backup |
| test_connectionB | Test API connection and authentication |
| get_interfacesB | List available network interfaces |
| list_dhcp_leasesC | List all DHCP leases |
| find_device_by_nameC | Find devices by hostname pattern |
| find_device_by_macC | Find device by MAC address |
| get_guest_devicesB | Get all devices on guest network (VLAN 4) |
| get_devices_by_interfaceB | Group devices by network interface |
| list_arp_entriesB | List all ARP table entries |
| find_arp_by_ipC | Find ARP entries by IP address or subnet |
| find_arp_by_macC | Find ARP entries by MAC address |
| find_arp_by_interfaceC | Find ARP entries on specific interface |
| find_arp_by_hostnameC | Find ARP entries by hostname pattern |
| get_arp_statsC | Get ARP table statistics |
| find_devices_on_vlanC | Find devices on specific VLAN |
| list_dns_blocklistB | List all DNS blocklist entries |
| block_domainC | Add a domain to the DNS blocklist |
| unblock_domainB | Remove a domain from the DNS blocklist |
| block_multiple_domainsC | Block multiple domains at once |
| apply_blocklist_categoryC | Apply a predefined category of domain blocks |
| search_dns_blocklistC | Search DNS blocklist entries |
| toggle_blocklist_entryB | Enable/disable a DNS blocklist entry |
| haproxy_service_controlC | Control HAProxy service (start, stop, restart, reload) |
| haproxy_backend_createC | Create a new HAProxy backend |
| haproxy_backend_listB | List all HAProxy backends |
| haproxy_backend_deleteC | Delete an HAProxy backend |
| haproxy_frontend_createC | Create a new HAProxy frontend |
| haproxy_frontend_listB | List all HAProxy frontends |
| haproxy_frontend_deleteC | Delete an HAProxy frontend |
| haproxy_certificate_listB | List available certificates for HAProxy |
| haproxy_certificate_createC | Create a certificate for HAProxy |
| haproxy_acl_createC | Create an ACL for HAProxy frontend |
| haproxy_action_createC | Create an action for HAProxy frontend |
| haproxy_statsC | Get HAProxy statistics |
| haproxy_backend_healthC | Get health status of a specific backend |
| macro_start_recordingC | Start recording API calls to create a macro |
| macro_stop_recordingB | Stop recording and save the macro |
| macro_listB | List all saved macros |
| macro_playC | Play a saved macro |
| macro_deleteC | Delete a saved macro |
| macro_analyzeC | Analyze a macro to detect patterns and parameters |
| macro_generate_toolC | Generate an MCP tool definition from a macro |
| macro_exportC | Export all macros to a file |
| macro_importC | Import macros from a file |
| iac_plan_deploymentC | Plan infrastructure deployment changes |
| iac_apply_deploymentC | Apply a deployment plan |
| iac_destroy_deploymentC | Destroy deployed resources |
| iac_list_resource_typesB | List available resource types |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| VLANs | List of all configured VLANs |
| Firewall Rules | List of all firewall rules |
| Network Interfaces | Available network interfaces |
| Connection Status | OPNsense connection status |
| DHCP Leases | Current DHCP leases |
| DNS Blocklist | DNS blocklist entries |
| HAProxy Backends | HAProxy backend configurations |
| HAProxy Frontends | HAProxy frontend configurations |
| HAProxy Statistics | HAProxy statistics and health status |
| Recorded Macros | List of recorded API macros |
| ARP Table | ARP table entries showing IP to MAC mappings |
| IaC Resource Types | Available infrastructure resource types |
| Deployments | Current infrastructure deployments |
| Resource State | Current state of managed resources |
TDQS
Scored across 64 tools
The tool set has clear groupings by domain (e.g., ARP, firewall, HAProxy, macros), which helps disambiguation within groups, but there is significant overlap across some tools. For example, multiple ARP-related tools (find_arp_by_hostname, find_arp_by_interface, find_arp_by_ip, find_arp_by_mac) have very similar purposes and could be confused, and the macro tools (macro_play, macro_start_recording, macro_stop_recording) have overlapping functionalities. However, descriptions provide enough detail to differentiate them in most cases.
Naming is mostly consistent with a verb_noun pattern (e.g., create_firewall_rule, delete_vlan, list_arp_entries), and snake_case is used throughout. There are minor deviations, such as 'configure' and 'test_connection' which omit the noun, and 'iac_apply_deployment' uses a prefix, but overall the pattern is predictable and readable across the set.
With 64 tools, the count is excessive for a single server, making it feel heavy and potentially overwhelming. While OPNsense is a broad platform, the tools cover multiple distinct domains (e.g., firewall, VLAN, HAProxy, macros, ARP), suggesting they might be better split into separate, more focused servers. This large number increases complexity and reduces coherence.
The tool surface is quite comprehensive for the OPNsense domain, covering core areas like firewall rules (create, get, list, update, delete, toggle), VLAN management, DNS blocklisting, HAProxy configuration, and macro operations. Minor gaps exist, such as no direct tools for DHCP configuration beyond listing leases, but overall, it provides good CRUD/lifecycle coverage and few dead ends for agents.