pfSense MCP Server

pfSense MCP Server is an open-source MCP server that connects large language model interfaces like Claude Desktop and Claude Code to pfSense firewalls. Built for network engineers, system administrators, and security teams, it provides direct programmatic control over network infrastructure using natural language prompts. The server interfaces with the pfSense REST API v2 package, exposing 333 distinct tools across core networking and firewall subsystems. Users can inspect active firewall rules, filter logs, deploy VPN peers, alter routing tables, and update DHCP or DNS settings without manually navigating the web interface. To protect production network environments, the server implements nine protective layers including rate limiting, input sanitization, automated configuration backups before changes, and mandatory confirmation gates on destructive operations like rule deletions or appliance reboots. Users can also configure a strictly read-only mode or restrict access to specific whitelisted commands, ensuring safe and verifiable diagnostic workflows across the entire pfSense ecosystem.

Category: Cloud & Infrastructure

Tags: administration, firewall, networking, pfsense, security

Visit pfSense MCP Server

How to install and configure pfSense MCP Server

  1. Ensure Python 3.11+ is installed, and install the REST API v2 package on your pfSense firewall. 2. Export your pfSense Certificate Authority certificate from System > Cert. Manager > CAs, save it locally as a PEM file, and note its path. 3. Open your Claude Desktop configuration file at ~/Library/Application Support/Claude/claude_desktop_config.json. 4. Add the pfSense server under mcpServers using uvx: json { "mcpServers": { "pfsense": { "command": "uvx", "args": ["--from", "git+https://github.com/gensecaihq/pfsense-mcp-server", "pfsense-mcp-server"], "env": { "PFSENSE_URL": "https://192.168.1.1", "AUTH_METHOD": "basic", "PFSENSE_USERNAME": "admin", "PFSENSE_PASSWORD": "your-password", "PFSENSE_VERSION": "CE_2_8_1", "PFSENSE_CA_FILE": "/path/to/pfsense-ca.pem" } } } } 5. Restart Claude Desktop to start managing your firewall.

What you can do with pfSense MCP Server

  • Analyze firewall log files and identify which active rules blocked specific internal IP addresses within recent timeframes. - Create, reorder, or delete network firewall rules and bulk block suspicious WAN IP addresses using plain English commands. - Provision and export WireGuard or OpenVPN configurations, tunnels, and client peers directly from the conversational interface. - Perform comprehensive network troubleshooting and health checks covering DHCP leases, gateway uptime, DNS resolution, and interface status. - Manage DNS records, Unbound host overrides, and DHCP static mappings without logging into the pfSense web administrator interface.

Key facts

  • Open Source
  • https://github.com/gensecaihq/pfsense-mcp-server
  • Cloud & Infrastructure, Security & Compliance
  • administration, firewall, networking, pfsense, security

Part of MCP Servers

Related MCP servers

  • MCP KQL Server โ€” MCP KQL Server is an MCP server that connects AI assistants to Azure Data Explorer clusters using Azure CLI authentication.โ€ฆ
  • MCP Media Player โ€” MCP Media Player is an MCP server that exposes playback controls for Home Assistant media players to AI agents. Itโ€ฆ
  • MCP Kubernetes Server โ€” MCP Kubernetes Server is an MCP server that provides tools for managing and inspecting Kubernetes clusters directly through Large Languageโ€ฆ
  • MCP Nomad Go โ€” MCP Nomad Go is an MCP server that connects AI assistants to HashiCorp Nomad clusters. Written in Go, it allowsโ€ฆ
  • MCP Minecraft Remote โ€” MCP Minecraft Remote is an MCP server that enables AI assistants to remotely connect to and control a player characterโ€ฆ
  • MCP My Mac โ€” MCP My Mac is an MCP server that exposes macOS system hardware specifications, system configurations, and environment details to AIโ€ฆ

How do I install pfSense MCP Server?

You can install it without cloning the repository by running uvx pointing to the official Git repository, or by cloning the repository locally and installing dependencies with pip. Both approaches require Python 3.11 or newer and the pfSense REST API v2 package installed on your firewall.

What can pfSense MCP Server do?

It provides 333 operational tools to query and manage pfSense subsystems. Capabilities include creating firewall rules, updating NAT configurations, managing WireGuard and OpenVPN tunnels, querying DHCP leases, parsing filter logs, restarting services, updating DNS overrides, and diagnosing gateway connectivity issues using conversational AI.

Which MCP clients work with pfSense MCP Server?

The server connects with Claude Desktop, Claude Code, and any other client that complies with the Model Context Protocol specification over standard input and output.

How does pfSense MCP Server prevent accidental configuration damage?

It includes a nine-layer guardrail system requiring explicit user confirmation before destructive actions like deletions or reboots. It automatically creates configuration backups before changes, provides rollback commands, rate-limits mutating tools, validates inputs against schemas, and supports a read-only environment mode.

Is pfSense MCP Server open source?

Yes, pfSense MCP Server is open source and distributed under the MIT license on GitHub.

  • AI Tools
  • Categories
  • Industries
  • CLI Coding Agents
  • MCP Servers
  • MCP Categories