OPNSenseBLOCK
MCP Server for OPNSense to act as IaC proxy
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/opnsense-mcp-server) [](https://opensource.org/licenses/MIT)
A Model Context Protocol (MCP) server for comprehensive OPNsense firewall management. This server enables AI assistants like Claude to directly manage firewall configurations, diagnose network issues, and automate complex networking tasks.
Features
🔥 Firewall Management
- Complete CRUD operations for firewall rules
- Proper handling of API-created "automation rules"
- Inter-VLAN routing configuration
- Batch rule creation and management
- Enhanced persistence with multiple fallback methods
🌐 NAT Configuration (SSH-based)
- Outbound NAT rule management
- NAT mode control (automatic/hybrid/manual/disabled)
- No-NAT exception rules for inter-VLAN traffic
- Automated DMZ NAT issue resolution
- Direct XML configuration manipulation
🔍 Network Diagnostics
- Comprehensive routing analysis
- ARP table inspection with vendor identification
- Interface configuration management
- Network connectivity troubleshooting
- Auto-fix capabilities for common issues
🖥️ SSH/CLI Execution
- Direct command execution on OPNsense
- Configuration file manipulation
- System-level operations not available via API
- Service management and restarts
📊 Additional Capabilities
- VLAN management
- DHCP lease viewing and management
- DNS blocklist configuration
- HAProxy load balancer support
- Configuration backup and restore
- Infrastructure as Code support
Installation
Prerequisites
- Node.js 18+ to run the server (Bun 1.1.39+ to develop on it)
- OPNsense firewall (v24.7+ recommended)
- API credentials for OPNsense
- SSH access (optional, for advanced features)
Quick Start with npm
- Install the package:
npm install -g opnsense-mcp-server
- Create a
.envfile with your credentials:
# R
0a1353a0df07OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add opnsense-mcp-server --env OPNSENSE_API_KEY=${OPNSENSE_API_KEY} --env OPNSENSE_API_SECRET=${OPNSENSE_API_SECRET} --env OPNSENSE_CLIENT_CERT_PASSPHRASE=${OPNSENSE_CLIENT_CERT_PASSPHRASE} --env OPNSENSE_CLIENT_KEY_PATH=${OPNSENSE_CLIENT_KEY_PATH} -- npx -y [email protected]{
"mcpServers": {
"opnsense-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"OPNSENSE_API_KEY": "${OPNSENSE_API_KEY}",
"OPNSENSE_API_SECRET": "${OPNSENSE_API_SECRET}",
"OPNSENSE_CLIENT_CERT_PASSPHRASE": "${OPNSENSE_CLIENT_CERT_PASSPHRASE}",
"OPNSENSE_CLIENT_KEY_PATH": "${OPNSENSE_CLIENT_KEY_PATH}"
}
}
}
}Exposed tools (200)
109 read · 73 write · 23 destructive. Blast radius: 23 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Certificates | read | All installed certificates |
Deployments | read | Current infrastructure deployments |
RootFs | read | Root filesystem |
TestAccount | read | Test |
VLANs | read | List of all configured VLANs |
acme_add_action | write | Create a new ACME automation action (restart HAProxy, restart web UI, SFTP upload, SSH command, etc.) |
acme_delete_action | destructive | Delete an ACME automation action |
acme_get_settings | read | Get full ACME/Let\ |
acme_renew_certificate | write | Trigger manual renewal of a specific certificate |
acme_revoke_certificate | destructive | Revoke a certificate |
acme_sign_certificate | read | Issue/sign a certificate (initial creation or re-issue) |
acme_update_certificate | write | Update certificate settings (renewal interval, restart actions, enable/disable, description) |
add_dnsbl_subscription | write | Add a DNSBL subscription list (e.g. OISD, Hagezi, Abuse.ch ThreatFox) |
applyResource | destructive | Apply a single resource (create, update, or delete) |
apply_blocklist_category | write | Apply a predefined category of domain blocks |
block_domain | write | Add a domain to the DNS blocklist |
block_multiple_domains | read | Block multiple domains at once |
cert_check_expiry | read | Check certificate expiration status |
cert_delete | destructive | Delete a certificate |
cert_generate_csr | read | Generate a Certificate Signing Request |
cert_get | read | Get certificate details |
cert_import | write | Import a certificate |
cert_letsencrypt_renew | read | Renew a Let\ |
cert_letsencrypt_request | read | Request a Let\ |
cert_list | read | List all certificates |
cli_apply_changes | write | Apply all configuration changes via CLI |
cli_check_nfs | read | Check NFS connectivity from DMZ |
cli_execute | write | Execute a CLI command on OPNsense for advanced configuration |
cli_fix_dmz_routing | read | Comprehensive DMZ routing fix via CLI |
cli_fix_interface_blocking | read | Fix interface blocking settings via CLI (for DMZ routing issues) |
cli_reload_firewall | read | Reload firewall rules via CLI |
cli_show_routing | read | Show routing table via CLI |
configure | read | Configure OPNsense connection |
create_backup | write | Create a configuration backup |
create_firewall_preset | write | Create a firewall rule from a preset |
create_firewall_rule | write | Create a new firewall rule |
create_vlan | write | Create a new VLAN |
delete_firewall_rule | destructive | Delete a firewall rule |
delete_vlan | destructive | Delete a VLAN |
find_arp_by_hostname | read | Find ARP entries by hostname pattern |
find_arp_by_interface | read | Find ARP entries on specific interface |
find_arp_by_ip | read | Find ARP entries by IP address or subnet |
find_arp_by_mac | read | Find ARP entries by MAC address |
find_device_by_mac | read | Find device by MAC address |
find_device_by_name | read | Find devices by hostname pattern |
find_devices_on_vlan | read | Find devices on specific VLAN |
find_firewall_rules | read | Find firewall rules by description |
firewall_apply_changes | write | Apply pending firewall changes |
firewall_audit | read | Audit firewall rules for security issues |
firewall_create_rule | write | Create a new firewall rule |
firewall_delete_rule | destructive | Delete a firewall rule |
firewall_get_rule | read | Get a specific firewall rule by UUID |
firewall_list_rules | read | List all firewall rules |
firewall_toggle_rule | read | Toggle a firewall rule enabled/disabled |
firewall_update_rule | write | Update an existing firewall rule |
get_arp_stats | read | Get ARP table statistics |
get_devices_by_interface | read | Group devices by network interface |
get_firewall_rule | read | Get firewall rule details |
get_guest_devices | read | Get all devices on guest network (VLAN 4) |
get_interfaces | read | List available network interfaces |
get_vlan | read | Get VLAN details |
group_devices | read | Group devices together (e.g., all devices belonging to one person) |
haproxy_acl_create | write | Create an ACL for HAProxy frontend. Supports all OPNsense HAProxy ACL expression types including SNI matching for TCP/SSL passthrough. |
haproxy_acl_delete | destructive | Delete an HAProxy ACL |
haproxy_acl_update | write | Update an existing HAProxy ACL |
haproxy_action_create | write | Create an action for HAProxy frontend. Supports all OPNsense HAProxy action types including tcp-request for SNI routing. |
haproxy_action_delete | destructive | Delete an HAProxy action |
haproxy_action_update | write | Update an existing HAProxy action |
haproxy_backend_create | write | Create a new HAProxy backend |
haproxy_backend_delete | destructive | Delete an HAProxy backend |
haproxy_backend_get | read | Get detailed information about a specific HAProxy backend by UUID |
haproxy_backend_health | read | Get health status of a specific backend |
haproxy_backend_list | read | List all HAProxy backends |
haproxy_backend_update | write | Update an existing HAProxy backend configuration |
haproxy_certificate_create | write | Create a certificate for HAProxy |
haproxy_certificate_list | read | List available certificates for HAProxy |
haproxy_frontend_create | write | Create a new HAProxy frontend |
haproxy_frontend_delete | destructive | Delete an HAProxy frontend |
haproxy_frontend_get | read | Get detailed information about a specific HAProxy frontend by UUID |
haproxy_frontend_list | read | List all HAProxy frontends |
haproxy_frontend_update | write | Update an existing HAProxy frontend configuration |
haproxy_server_add | write | Add a server to an HAProxy backend |
haproxy_server_delete | destructive | Delete an HAProxy server |
haproxy_server_update | write | Update an existing HAProxy server |
haproxy_service_control | write | Control HAProxy service (start, stop, restart, reload) |
haproxy_stats | read | Get HAProxy statistics |
iac_apply_deployment | write | Apply a deployment plan |
iac_destroy_deployment | destructive | Destroy deployed resources |
iac_list_resource_types | read | List available resource types |
iac_plan_deployment | read | Plan infrastructure deployment changes |
ids_analyze_alerts | read | Analyze recent IDS alerts for patterns |
ids_block_ip | read | Block an IP address detected by IDS |
ids_disable_rule_set | write | Disable a rule set |
ids_enable_rule_set | write | Enable a rule set |
ids_get_alert | read | Get detailed alert information |
ids_get_statistics | read | Get IDS/IPS statistics |
ids_get_status | read | Get IDS/IPS service status |
ids_list_alerts | read | List recent IDS alerts |
ids_list_rule_sets | read | List available rule sets |
ids_restart | write | Restart IDS/IPS service |
ids_start | write | Start IDS/IPS service |
ids_stop | write | Stop IDS/IPS service |
ids_update_rules | write | Update IDS/IPS rule sets |
interface_configure_dmz | read | Configure DMZ interface for inter-VLAN routing |
interface_enable_intervlan_all | write | Enable inter-VLAN routing on all interfaces |
interface_enable_intervlan_routing | write | Enable inter-VLAN routing on a specific interface |
interface_get_config | read | Get detailed configuration for a specific interface |
interface_list_overview | read | List all network interfaces with their overview |
interface_update_config | write | Update interface configuration |
list_arp_entries | read | List all ARP table entries |
list_available_dnsbl | read | List all available DNSBL subscription lists (e.g. OISD, Hagezi, Abuse.ch) |
list_backups | read | List available backups |
list_dhcp_leases | read | List all DHCP leases |
list_dns_blocklist | read | List all DNS blocklist entries |
list_firewall_rules | read | List all firewall rules |
list_vlans | read | List all VLANs |
macro_analyze | read | Analyze a macro to detect patterns and parameters |
macro_delete | destructive | Delete a saved macro |
macro_export | read | Export all macros to a file |
macro_generate_tool | read | Generate an MCP tool definition from a macro |
macro_import | write | Import macros from a file |
macro_list | read | List all saved macros |
macro_play | read | Play a saved macro |
macro_start_recording | write | Start recording API calls to create a macro |
macro_stop_recording | write | Stop recording and save the macro |
monit_add_alert | write | Add a new Monit alert recipient (email address for notifications) |
monit_add_service | write | Add a new Monit monitored service (process, host, custom script, filesystem, network, etc.) |
monit_add_test | write | Add a new Monit test condition (CPU, memory, disk, custom, etc.) |
monit_delete_alert | destructive | Delete a Monit alert recipient |
monit_delete_service | destructive | Delete a Monit monitored service |
monit_delete_test | destructive | Delete a Monit test |
monit_get_settings | read | Get full Monit configuration (general settings, services, tests, alerts) |
monit_status | read | Get Monit live status — shows if Monit is running and the state of all monitored services |
monit_update_alert | write | Update an existing Monit alert recipient |
monit_update_service | write | Update an existing Monit service |
monit_update_test | write | Update an existing Monit test |
monitoring_get_cpu_usage | read | Get CPU usage statistics |
monitoring_get_disk_usage | read | Get disk usage statistics |
monitoring_get_memory_usage | read | Get memory usage statistics |
monitoring_get_metrics | read | Get current system metrics |
monitoring_get_network_stats | read | Get network interface statistics |
nat_analyze_config | read | Analyze NAT configuration for issues |
nat_apply_changes | write | Apply NAT configuration changes |
nat_cleanup_dmz_fix | destructive | Remove all MCP-created NAT fix rules |
nat_create_outbound_rule | write | Create an outbound NAT rule |
nat_create_port_forward | write | Create a port forward rule |
nat_delete_outbound_rule | destructive | Delete an outbound NAT rule by description (SSH mode) or UUID (API mode) |
nat_delete_port_forward | destructive | Delete a port forward rule |
nat_fix_dmz | read | Fix DMZ NAT issue - adds no-NAT rules for inter-VLAN traffic |
nat_get_mode | read | Get current NAT mode (automatic, hybrid, manual, disabled) |
nat_list_outbound | read | List all outbound NAT rules |
nat_list_port_forwards | read | List all port forward rules |
nat_quick_fix_dmz | read | Quick fix for DMZ NAT issue with minimal configuration |
nat_set_mode | write | Set NAT mode (automatic, hybrid, manual, disabled) |
network_query | read | Query network devices using natural language |
openvpn_create_server | write | Create a new OpenVPN server instance |
openvpn_disconnect_client | read | Disconnect a specific VPN client |
openvpn_get_connections | read | Get active OpenVPN connections |
openvpn_list_clients | read | List all OpenVPN client configurations |
openvpn_list_servers | read | List all OpenVPN server instances |
remove_dnsbl_subscription | destructive | Remove a DNSBL subscription list. Deletes the entry if no lists remain. |
restore_backup | read | Restore a configuration backup |
routing_create_intervlan_rules | write | Create firewall rules for inter-VLAN routing |
routing_diagnostics | write | Run comprehensive inter-VLAN routing diagnostics |
routing_fix_all | read | Automatically fix all detected inter-VLAN routing issues |
routing_fix_dmz | read | Quick fix for DMZ to LAN routing (includes NFS rules) |
search_dns_blocklist | read | Search DNS blocklist entries |
ssh_backup_config | read | Backup OPNsense configuration via SSH |
ssh_batch_execute | write | Execute multiple commands in sequence via SSH |
ssh_check_nfs_connectivity | read | Check NFS connectivity from OPNsense |
ssh_enable_intervlan_routing | write | Enable inter-VLAN routing via SSH |
ssh_execute | write | Execute arbitrary command via SSH on OPNsense (full CLI access) |
ssh_fix_dmz_routing | write | Apply comprehensive DMZ routing fix via SSH |
ssh_fix_interface_blocking | read | Fix interface blocking settings via SSH (resolves DMZ routing issues) |
ssh_quick_dmz_fix | write | Apply quick DMZ fix (streamlined version) |
ssh_reload_firewall | read | Reload firewall rules via SSH |
ssh_restore_config | read | Restore OPNsense configuration via SSH |
ssh_show_pf_rules | read | Show packet filter rules via SSH |
ssh_show_routing | read | Show routing table via SSH |
ssh_system_status | read | Get comprehensive system status via SSH |
ssh_test_vlan_connectivity | read | Test connectivity between VLANs |
sync_network_data | write | Sync network data from OPNsense |
system_enable_intervlan_routing | write | Enable inter-VLAN routing at the system level |
system_get_settings | read | Get system-level firewall and routing settings |
system_update_firewall_settings | write | Update system firewall settings |
test_connection | read | Test API connection and authentication |
test_tool | read | A test tool |
toggle_blocklist_entry | write | Enable/disable a DNS blocklist entry |
toggle_firewall_rule | read | Toggle firewall rule enabled/disabled |
toggle_firewall_rule_log | write | Toggle logging on/off for a firewall rule, or set it explicitly with the |
traffic_apply_changes | write | Apply traffic shaper changes |
traffic_create_pipe | write | Create a traffic shaper pipe |
traffic_create_queue | write | Create a traffic shaper queue |
traffic_create_rule | write | Create a traffic shaper rule |
traffic_delete_pipe | destructive | Delete a traffic shaper pipe |
traffic_get_statistics | read | Get traffic shaper statistics |
traffic_list_pipes | read | List traffic shaper pipes (bandwidth limiters) |
traffic_list_queues | read | List traffic shaper queues |
traffic_list_rules | read | List traffic shaper rules |
traffic_update_pipe | write | Update a traffic shaper pipe |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (11 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (24)
console.log('OPNSENSE_SSH_KEY_PATH=~/.ssh/id_rsa');privateKeyPath: process.env.OPNSENSE_SSH_KEY_PATH || join(homedir(), '.ssh', 'id_rsa'),
OPNSENSE_HOST=https://192.168.1.1
acme_delete_action, acme_revoke_certificate, applyResource, cert_delete, delete_firewall_rule, delete_vlan, firewall_delete_rule, haproxy_acl_delete, haproxy_action_delete, haproxy_backend_delete, hap
.env.iac-example
.createHash('md5')import { OPNSenseAPIClient } from '../../src/api/client.js';import { FirewallRuleResource, FirewallRule } from '../../src/resources/firewall/rule.js';import { OPNSenseAPIClient } from '../../src/api/client.js';import { OPNSenseAPIClient } from '../../src/api/client.js';import { OPNSenseAPIClient } from '../../src/api/client.js';"OPNSENSE_HOST": "https://192.168.1.1",
"OPNSENSE_HOST": "https://192.168.1.1",
| `OPNSENSE_HOST` | Full URL to OPNsense | `https://192.168.1.1` |
"OPNSENSE_HOST": "https://192.168.1.1",
react, react-dom, react-router-dom, @tanstack/react-query, recharts, lucide-react, clsx, date-fns
@modelcontextprotocol/sdk, @types/cors, @types/express, @types/uuid, @types/xml2js, axios, cors, dotenv
- Add "GUI - All pages" for full access
4. Verify API user has full permissions
- Generates access credentials
6. **Use read-only API keys** when possible
Both variables are read once from `process.env` and applied *after* any
- **API Access**: Enabled with valid credentials
curl -fsSL https://bun.sh/install | bash
Gates applied: no_behavioural_pass.
0a1353a0df07full audit observations/trust-audit/mcp-server/vespo92__opnsense-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 0a1353a0df07 | BLOCK | D | 69 | first audit |
Questions
What is the OPNSense MCP server?
MCP Server for OPNSense to act as IaC proxy
What tools does OPNSense expose?
200 in total: 109 read-only, 73 that write, and 23 that can delete or overwrite (acme_delete_action, acme_revoke_certificate, applyResource, cert_delete, delete_firewall_rule). Every one is listed on this page with its risk.
Is OPNSense safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 23 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does OPNSense need?
It reads OPNSENSE_API_KEY, OPNSENSE_API_SECRET, OPNSENSE_CLIENT_CERT_PASSPHRASE, OPNSENSE_CLIENT_KEY_PATH, OPNSENSE_SSH_KEY_PATH, OPNSENSE_SSH_PASSPHRASE, OPNSENSE_SSH_PASSWORD, POSTGRES_PASSWORD, REDIS_KEY_PREFIX, REDIS_PASSWORD, SSH_PASSWORD and STATE_ENCRYPTION_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does OPNSense run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as opnsense-mcp-server at 0.11.0.
How current is this page?
The grade is for one exact copy of the source (0a1353a0df07), read on 2026-10-07. The repository is watched and re-audited when it changes.