pfSense MCP Server is an open-source MCP server that connects large language model interfaces like Claude Desktop and Claude Code to pfSense firewalls. Built for network engineers, system administrators, and security teams, it provides direct programmatic control over network infrastructure using natural language prompts. The server interfaces with the pfSense REST API v2 package, exposing 333 distinct tools across core networking and firewall subsystems. Users can inspect active firewall rules, filter logs, deploy VPN peers, alter routing tables, and update DHCP or DNS settings without manually navigating the web interface. To protect production network environments, the server implements nine protective layers including rate limiting, input sanitization, automated configuration backups before changes, and mandatory confirmation gates on destructive operations like rule deletions or appliance reboots. Users can also configure a strictly read-only mode or restrict access to specific whitelisted commands, ensuring safe and verifiable diagnostic workflows across the entire pfSense ecosystem.
Category: Cloud & Infrastructure
Tags: administration, firewall, networking, pfsense, security
~/Library/Application Support/Claude/claude_desktop_config.json. 4. Add the pfSense server under mcpServers using uvx: json { "mcpServers": { "pfsense": { "command": "uvx", "args": ["--from", "git+https://github.com/gensecaihq/pfsense-mcp-server", "pfsense-mcp-server"], "env": { "PFSENSE_URL": "https://192.168.1.1", "AUTH_METHOD": "basic", "PFSENSE_USERNAME": "admin", "PFSENSE_PASSWORD": "your-password", "PFSENSE_VERSION": "CE_2_8_1", "PFSENSE_CA_FILE": "/path/to/pfsense-ca.pem" } } } } 5. Restart Claude Desktop to start managing your firewall.Part of MCP Servers
You can install it without cloning the repository by running uvx pointing to the official Git repository, or by cloning the repository locally and installing dependencies with pip. Both approaches require Python 3.11 or newer and the pfSense REST API v2 package installed on your firewall.
It provides 333 operational tools to query and manage pfSense subsystems. Capabilities include creating firewall rules, updating NAT configurations, managing WireGuard and OpenVPN tunnels, querying DHCP leases, parsing filter logs, restarting services, updating DNS overrides, and diagnosing gateway connectivity issues using conversational AI.
The server connects with Claude Desktop, Claude Code, and any other client that complies with the Model Context Protocol specification over standard input and output.
It includes a nine-layer guardrail system requiring explicit user confirmation before destructive actions like deletions or reboots. It automatically creates configuration backups before changes, provides rollback commands, rate-limits mutating tools, validates inputs against schemas, and supports a read-only environment mode.
Yes, pfSense MCP Server is open source and distributed under the MIT license on GitHub.