Atlas / MCP servers / vespo92 / OPNSense

OPNSenseBLOCK

mcp/vespo92/opnsense-1

MCP Server for OPNSense to act as IaC proxy

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
200 109r · 73w · 23d
Transport
sse · stdio · streamable-http
License
MIT
Stars
88
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/opnsense-mcp-server) [](https://opensource.org/licenses/MIT)

A Model Context Protocol (MCP) server for comprehensive OPNsense firewall management. This server enables AI assistants like Claude to directly manage firewall configurations, diagnose network issues, and automate complex networking tasks.

Features

🔥 Firewall Management

  • Complete CRUD operations for firewall rules
  • Proper handling of API-created "automation rules"
  • Inter-VLAN routing configuration
  • Batch rule creation and management
  • Enhanced persistence with multiple fallback methods

🌐 NAT Configuration (SSH-based)

  • Outbound NAT rule management
  • NAT mode control (automatic/hybrid/manual/disabled)
  • No-NAT exception rules for inter-VLAN traffic
  • Automated DMZ NAT issue resolution
  • Direct XML configuration manipulation

🔍 Network Diagnostics

  • Comprehensive routing analysis
  • ARP table inspection with vendor identification
  • Interface configuration management
  • Network connectivity troubleshooting
  • Auto-fix capabilities for common issues

🖥️ SSH/CLI Execution

  • Direct command execution on OPNsense
  • Configuration file manipulation
  • System-level operations not available via API
  • Service management and restarts

📊 Additional Capabilities

  • VLAN management
  • DHCP lease viewing and management
  • DNS blocklist configuration
  • HAProxy load balancer support
  • Configuration backup and restore
  • Infrastructure as Code support

Installation

Prerequisites

  • Node.js 18+ to run the server (Bun 1.1.39+ to develop on it)
  • OPNsense firewall (v24.7+ recommended)
  • API credentials for OPNsense
  • SSH access (optional, for advanced features)

Quick Start with npm

  1. Install the package:
npm install -g opnsense-mcp-server
  1. Create a .env file with your credentials:
# R
Read from source at commit 0a1353a0df07OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add opnsense-mcp-server --env OPNSENSE_API_KEY=${OPNSENSE_API_KEY} --env OPNSENSE_API_SECRET=${OPNSENSE_API_SECRET} --env OPNSENSE_CLIENT_CERT_PASSPHRASE=${OPNSENSE_CLIENT_CERT_PASSPHRASE} --env OPNSENSE_CLIENT_KEY_PATH=${OPNSENSE_CLIENT_KEY_PATH} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "opnsense-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OPNSENSE_API_KEY": "${OPNSENSE_API_KEY}",
        "OPNSENSE_API_SECRET": "${OPNSENSE_API_SECRET}",
        "OPNSENSE_CLIENT_CERT_PASSPHRASE": "${OPNSENSE_CLIENT_CERT_PASSPHRASE}",
        "OPNSENSE_CLIENT_KEY_PATH": "${OPNSENSE_CLIENT_KEY_PATH}"
      }
    }
  }
}
03

Exposed tools (200)

109 read · 73 write · 23 destructive. Blast radius: 23 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
CertificatesreadAll installed certificates
DeploymentsreadCurrent infrastructure deployments
RootFsreadRoot filesystem
TestAccountreadTest
VLANsreadList of all configured VLANs
acme_add_actionwriteCreate a new ACME automation action (restart HAProxy, restart web UI, SFTP upload, SSH command, etc.)
acme_delete_actiondestructiveDelete an ACME automation action
acme_get_settingsreadGet full ACME/Let\
acme_renew_certificatewriteTrigger manual renewal of a specific certificate
acme_revoke_certificatedestructiveRevoke a certificate
acme_sign_certificatereadIssue/sign a certificate (initial creation or re-issue)
acme_update_certificatewriteUpdate certificate settings (renewal interval, restart actions, enable/disable, description)
add_dnsbl_subscriptionwriteAdd a DNSBL subscription list (e.g. OISD, Hagezi, Abuse.ch ThreatFox)
applyResourcedestructiveApply a single resource (create, update, or delete)
apply_blocklist_categorywriteApply a predefined category of domain blocks
block_domainwriteAdd a domain to the DNS blocklist
block_multiple_domainsreadBlock multiple domains at once
cert_check_expiryreadCheck certificate expiration status
cert_deletedestructiveDelete a certificate
cert_generate_csrreadGenerate a Certificate Signing Request
cert_getreadGet certificate details
cert_importwriteImport a certificate
cert_letsencrypt_renewreadRenew a Let\
cert_letsencrypt_requestreadRequest a Let\
cert_listreadList all certificates
cli_apply_changeswriteApply all configuration changes via CLI
cli_check_nfsreadCheck NFS connectivity from DMZ
cli_executewriteExecute a CLI command on OPNsense for advanced configuration
cli_fix_dmz_routingreadComprehensive DMZ routing fix via CLI
cli_fix_interface_blockingreadFix interface blocking settings via CLI (for DMZ routing issues)
cli_reload_firewallreadReload firewall rules via CLI
cli_show_routingreadShow routing table via CLI
configurereadConfigure OPNsense connection
create_backupwriteCreate a configuration backup
create_firewall_presetwriteCreate a firewall rule from a preset
create_firewall_rulewriteCreate a new firewall rule
create_vlanwriteCreate a new VLAN
delete_firewall_ruledestructiveDelete a firewall rule
delete_vlandestructiveDelete a VLAN
find_arp_by_hostnamereadFind ARP entries by hostname pattern
find_arp_by_interfacereadFind ARP entries on specific interface
find_arp_by_ipreadFind ARP entries by IP address or subnet
find_arp_by_macreadFind ARP entries by MAC address
find_device_by_macreadFind device by MAC address
find_device_by_namereadFind devices by hostname pattern
find_devices_on_vlanreadFind devices on specific VLAN
find_firewall_rulesreadFind firewall rules by description
firewall_apply_changeswriteApply pending firewall changes
firewall_auditreadAudit firewall rules for security issues
firewall_create_rulewriteCreate a new firewall rule
firewall_delete_ruledestructiveDelete a firewall rule
firewall_get_rulereadGet a specific firewall rule by UUID
firewall_list_rulesreadList all firewall rules
firewall_toggle_rulereadToggle a firewall rule enabled/disabled
firewall_update_rulewriteUpdate an existing firewall rule
get_arp_statsreadGet ARP table statistics
get_devices_by_interfacereadGroup devices by network interface
get_firewall_rulereadGet firewall rule details
get_guest_devicesreadGet all devices on guest network (VLAN 4)
get_interfacesreadList available network interfaces
get_vlanreadGet VLAN details
group_devicesreadGroup devices together (e.g., all devices belonging to one person)
haproxy_acl_createwriteCreate an ACL for HAProxy frontend. Supports all OPNsense HAProxy ACL expression types including SNI matching for TCP/SSL passthrough.
haproxy_acl_deletedestructiveDelete an HAProxy ACL
haproxy_acl_updatewriteUpdate an existing HAProxy ACL
haproxy_action_createwriteCreate an action for HAProxy frontend. Supports all OPNsense HAProxy action types including tcp-request for SNI routing.
haproxy_action_deletedestructiveDelete an HAProxy action
haproxy_action_updatewriteUpdate an existing HAProxy action
haproxy_backend_createwriteCreate a new HAProxy backend
haproxy_backend_deletedestructiveDelete an HAProxy backend
haproxy_backend_getreadGet detailed information about a specific HAProxy backend by UUID
haproxy_backend_healthreadGet health status of a specific backend
haproxy_backend_listreadList all HAProxy backends
haproxy_backend_updatewriteUpdate an existing HAProxy backend configuration
haproxy_certificate_createwriteCreate a certificate for HAProxy
haproxy_certificate_listreadList available certificates for HAProxy
haproxy_frontend_createwriteCreate a new HAProxy frontend
haproxy_frontend_deletedestructiveDelete an HAProxy frontend
haproxy_frontend_getreadGet detailed information about a specific HAProxy frontend by UUID
haproxy_frontend_listreadList all HAProxy frontends
haproxy_frontend_updatewriteUpdate an existing HAProxy frontend configuration
haproxy_server_addwriteAdd a server to an HAProxy backend
haproxy_server_deletedestructiveDelete an HAProxy server
haproxy_server_updatewriteUpdate an existing HAProxy server
haproxy_service_controlwriteControl HAProxy service (start, stop, restart, reload)
haproxy_statsreadGet HAProxy statistics
iac_apply_deploymentwriteApply a deployment plan
iac_destroy_deploymentdestructiveDestroy deployed resources
iac_list_resource_typesreadList available resource types
iac_plan_deploymentreadPlan infrastructure deployment changes
ids_analyze_alertsreadAnalyze recent IDS alerts for patterns
ids_block_ipreadBlock an IP address detected by IDS
ids_disable_rule_setwriteDisable a rule set
ids_enable_rule_setwriteEnable a rule set
ids_get_alertreadGet detailed alert information
ids_get_statisticsreadGet IDS/IPS statistics
ids_get_statusreadGet IDS/IPS service status
ids_list_alertsreadList recent IDS alerts
ids_list_rule_setsreadList available rule sets
ids_restartwriteRestart IDS/IPS service
ids_startwriteStart IDS/IPS service
ids_stopwriteStop IDS/IPS service
ids_update_ruleswriteUpdate IDS/IPS rule sets
interface_configure_dmzreadConfigure DMZ interface for inter-VLAN routing
interface_enable_intervlan_allwriteEnable inter-VLAN routing on all interfaces
interface_enable_intervlan_routingwriteEnable inter-VLAN routing on a specific interface
interface_get_configreadGet detailed configuration for a specific interface
interface_list_overviewreadList all network interfaces with their overview
interface_update_configwriteUpdate interface configuration
list_arp_entriesreadList all ARP table entries
list_available_dnsblreadList all available DNSBL subscription lists (e.g. OISD, Hagezi, Abuse.ch)
list_backupsreadList available backups
list_dhcp_leasesreadList all DHCP leases
list_dns_blocklistreadList all DNS blocklist entries
list_firewall_rulesreadList all firewall rules
list_vlansreadList all VLANs
macro_analyzereadAnalyze a macro to detect patterns and parameters
macro_deletedestructiveDelete a saved macro
macro_exportreadExport all macros to a file
macro_generate_toolreadGenerate an MCP tool definition from a macro
macro_importwriteImport macros from a file
macro_listreadList all saved macros
macro_playreadPlay a saved macro
macro_start_recordingwriteStart recording API calls to create a macro
macro_stop_recordingwriteStop recording and save the macro
monit_add_alertwriteAdd a new Monit alert recipient (email address for notifications)
monit_add_servicewriteAdd a new Monit monitored service (process, host, custom script, filesystem, network, etc.)
monit_add_testwriteAdd a new Monit test condition (CPU, memory, disk, custom, etc.)
monit_delete_alertdestructiveDelete a Monit alert recipient
monit_delete_servicedestructiveDelete a Monit monitored service
monit_delete_testdestructiveDelete a Monit test
monit_get_settingsreadGet full Monit configuration (general settings, services, tests, alerts)
monit_statusreadGet Monit live status — shows if Monit is running and the state of all monitored services
monit_update_alertwriteUpdate an existing Monit alert recipient
monit_update_servicewriteUpdate an existing Monit service
monit_update_testwriteUpdate an existing Monit test
monitoring_get_cpu_usagereadGet CPU usage statistics
monitoring_get_disk_usagereadGet disk usage statistics
monitoring_get_memory_usagereadGet memory usage statistics
monitoring_get_metricsreadGet current system metrics
monitoring_get_network_statsreadGet network interface statistics
nat_analyze_configreadAnalyze NAT configuration for issues
nat_apply_changeswriteApply NAT configuration changes
nat_cleanup_dmz_fixdestructiveRemove all MCP-created NAT fix rules
nat_create_outbound_rulewriteCreate an outbound NAT rule
nat_create_port_forwardwriteCreate a port forward rule
nat_delete_outbound_ruledestructiveDelete an outbound NAT rule by description (SSH mode) or UUID (API mode)
nat_delete_port_forwarddestructiveDelete a port forward rule
nat_fix_dmzreadFix DMZ NAT issue - adds no-NAT rules for inter-VLAN traffic
nat_get_modereadGet current NAT mode (automatic, hybrid, manual, disabled)
nat_list_outboundreadList all outbound NAT rules
nat_list_port_forwardsreadList all port forward rules
nat_quick_fix_dmzreadQuick fix for DMZ NAT issue with minimal configuration
nat_set_modewriteSet NAT mode (automatic, hybrid, manual, disabled)
network_queryreadQuery network devices using natural language
openvpn_create_serverwriteCreate a new OpenVPN server instance
openvpn_disconnect_clientreadDisconnect a specific VPN client
openvpn_get_connectionsreadGet active OpenVPN connections
openvpn_list_clientsreadList all OpenVPN client configurations
openvpn_list_serversreadList all OpenVPN server instances
remove_dnsbl_subscriptiondestructiveRemove a DNSBL subscription list. Deletes the entry if no lists remain.
restore_backupreadRestore a configuration backup
routing_create_intervlan_ruleswriteCreate firewall rules for inter-VLAN routing
routing_diagnosticswriteRun comprehensive inter-VLAN routing diagnostics
routing_fix_allreadAutomatically fix all detected inter-VLAN routing issues
routing_fix_dmzreadQuick fix for DMZ to LAN routing (includes NFS rules)
search_dns_blocklistreadSearch DNS blocklist entries
ssh_backup_configreadBackup OPNsense configuration via SSH
ssh_batch_executewriteExecute multiple commands in sequence via SSH
ssh_check_nfs_connectivityreadCheck NFS connectivity from OPNsense
ssh_enable_intervlan_routingwriteEnable inter-VLAN routing via SSH
ssh_executewriteExecute arbitrary command via SSH on OPNsense (full CLI access)
ssh_fix_dmz_routingwriteApply comprehensive DMZ routing fix via SSH
ssh_fix_interface_blockingreadFix interface blocking settings via SSH (resolves DMZ routing issues)
ssh_quick_dmz_fixwriteApply quick DMZ fix (streamlined version)
ssh_reload_firewallreadReload firewall rules via SSH
ssh_restore_configreadRestore OPNsense configuration via SSH
ssh_show_pf_rulesreadShow packet filter rules via SSH
ssh_show_routingreadShow routing table via SSH
ssh_system_statusreadGet comprehensive system status via SSH
ssh_test_vlan_connectivityreadTest connectivity between VLANs
sync_network_datawriteSync network data from OPNsense
system_enable_intervlan_routingwriteEnable inter-VLAN routing at the system level
system_get_settingsreadGet system-level firewall and routing settings
system_update_firewall_settingswriteUpdate system firewall settings
test_connectionreadTest API connection and authentication
test_toolreadA test tool
toggle_blocklist_entrywriteEnable/disable a DNS blocklist entry
toggle_firewall_rulereadToggle firewall rule enabled/disabled
toggle_firewall_rule_logwriteToggle logging on/off for a firewall rule, or set it explicitly with the
traffic_apply_changeswriteApply traffic shaper changes
traffic_create_pipewriteCreate a traffic shaper pipe
traffic_create_queuewriteCreate a traffic shaper queue
traffic_create_rulewriteCreate a traffic shaper rule
traffic_delete_pipedestructiveDelete a traffic shaper pipe
traffic_get_statisticsreadGet traffic shaper statistics
traffic_list_pipesreadList traffic shaper pipes (bandwidth limiters)
traffic_list_queuesreadList traffic shaper queues
traffic_list_rulesreadList traffic shaper rules
traffic_update_pipewriteUpdate a traffic shaper pipe
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (11 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (24)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
scripts/fixes/ssh-dmz-fix.ts:19
console.log('OPNSENSE_SSH_KEY_PATH=~/.ssh/id_rsa');
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/resources/ssh/executor.ts:156
privateKeyPath: process.env.OPNSENSE_SSH_KEY_PATH || join(homedir(), '.ssh', 'id_rsa'),
Why it matters. touches a credential store
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.iac-example:5
OPNSENSE_HOST=https://192.168.1.1
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
acme_delete_action, acme_revoke_certificate, applyResource, cert_delete, delete_firewall_rule, delete_vlan, firewall_delete_rule, haproxy_acl_delete, haproxy_action_delete, haproxy_backend_delete, hap
Why it matters. 23 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.iac-example
.env.iac-example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/db/network-query/processor.ts:157
.createHash('md5')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/debug/debug-persistence.ts:8
import { OPNSenseAPIClient } from '../../src/api/client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/debug/debug-persistence.ts:9
import { FirewallRuleResource, FirewallRule } from '../../src/resources/firewall/rule.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/debug/diagnose-routing.ts:1
import { OPNSenseAPIClient } from '../../src/api/client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/debug/discover-api.ts:2
import { OPNSenseAPIClient } from '../../src/api/client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/debug/discover-interfaces.ts:1
import { OPNSenseAPIClient } from '../../src/api/client.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONFIGURATION.md:27
"OPNSENSE_HOST": "https://192.168.1.1",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONFIGURATION.md:47
"OPNSENSE_HOST": "https://192.168.1.1",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONFIGURATION.md:88
| `OPNSENSE_HOST` | Full URL to OPNsense | `https://192.168.1.1` |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONFIGURATION.md:130
"OPNSENSE_HOST": "https://192.168.1.1",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
dashboard/package.json
react, react-dom, react-router-dom, @tanstack/react-query, recharts, lucide-react, clsx, date-fns
Why it matters. 21 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/cors, @types/express, @types/uuid, @types/xml2js, axios, cors, dotenv
Why it matters. 30 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/troubleshooting/common-issues.md:63
- Add "GUI - All pages" for full access
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
test-suite/README.md:81
4. Verify API user has full permissions
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.archive/implementation-plan/ACTION-PLAN-24H.md:125
- Generates access credentials
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CONFIGURATION.md:221
6. **Use read-only API keys** when possible
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/features/safety-modes.md:11
Both variables are read once from `process.env` and applied *after* any
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/operations/DEPLOYMENT-GUIDE.md:25
- **API Access**: Enabled with valid credentials
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:121
curl -fsSL https://bun.sh/install | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 0a1353a0df07full audit observations/trust-audit/mcp-server/vespo92__opnsense-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070a1353a0df07BLOCKD69first audit
06

Questions

What is the OPNSense MCP server?

MCP Server for OPNSense to act as IaC proxy

What tools does OPNSense expose?

200 in total: 109 read-only, 73 that write, and 23 that can delete or overwrite (acme_delete_action, acme_revoke_certificate, applyResource, cert_delete, delete_firewall_rule). Every one is listed on this page with its risk.

Is OPNSense safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 23 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OPNSense need?

It reads OPNSENSE_API_KEY, OPNSENSE_API_SECRET, OPNSENSE_CLIENT_CERT_PASSPHRASE, OPNSENSE_CLIENT_KEY_PATH, OPNSENSE_SSH_KEY_PATH, OPNSENSE_SSH_PASSPHRASE, OPNSENSE_SSH_PASSWORD, POSTGRES_PASSWORD, REDIS_KEY_PREFIX, REDIS_PASSWORD, SSH_PASSWORD and STATE_ENCRYPTION_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OPNSense run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as opnsense-mcp-server at 0.11.0.

How current is this page?

The grade is for one exact copy of the source (0a1353a0df07), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement