View available block and allow target lists, including Firewalla-managed categories and user-defined custom lists, to audit network security configurations.
Retrieve current security alerts and active alarms from Firewalla firewall to monitor network threats, filter by alarm type, and manage security incidents.
A read-only MCP server that enables Claude to audit Firewalla network security configurations and monitor network activity. It provides tools to inspect devices, rules, alarms, and traffic flows without making any changes to the Firewalla system.
Query network traffic flows from Firewalla firewall to monitor security, analyze network activity, and track bandwidth usage with filtering, grouping, and sorting options.
Audit and review configured Firewalla network security rules to identify overly permissive settings, stale configurations, and scope mismatches for security optimization.
Search active security alarms on your Firewalla network to monitor threats, audit events by device or type, and identify patterns like rogue devices or repeated attacks.
Retrieve a snapshot of recent network flows for immediate security threat detection and current network issue analysis. Provides up to 50 most recent flows from the last 10-20 minutes.
Search and analyze network traffic flows to monitor activity, identify security issues, and audit blocked or allowed connections using Firewalla's query grammar.
Retrieve metadata for a Firewalla target list to identify its block mode, source, type, size, and last update timestamp for security auditing purposes.
Analyze network traffic by searching historical flows with advanced filters for protocols, locations, categories, and time ranges to identify patterns or investigate security events.
Report code near-misses to improve the Code Firewall MCP's threat detection by submitting legitimate variants or new dangerous patterns for classifier training.