OPNsense MCP Server
OPNsense MCP Server — 72 tools for DNS, Firewall, DHCP, ACME, Routing, VLANs & more
Usage numbers are collected on the next scan
Reviews
Write oneNobody has reviewed OPNsense MCP Server yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
OPNsense MCP Server tools (91, 22 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
opnsense_acme_add_accountRegister a new ACME account with a certificate authority (Let's Encrypt, ZeroSSL, etc.). Run opnsense_acme_apply afterwards.
opnsense_acme_add_challengeAdd a DNS-01 challenge configuration for automated certificate validation. For Cloudflare, use the dedicated dns_cf_* fields instead of dns_environment. Run opnsense_acme_apply afterwards.
opnsense_acme_applyApply pending ACME configuration changes (reconfigure service)
opnsense_acme_create_certwrite actionCreate a new ACME certificate request. Requires an account and challenge to be configured first. Run opnsense_acme_apply afterwards.
opnsense_acme_delete_accountwrite actionDelete an ACME account by UUID. Run opnsense_acme_apply afterwards.
opnsense_acme_delete_certwrite actionDelete an ACME certificate by UUID. Run opnsense_acme_apply afterwards.
opnsense_acme_delete_challengewrite actionDelete an ACME challenge/validation method by UUID. Run opnsense_acme_apply afterwards.
opnsense_acme_list_accountsList all ACME accounts (Let's Encrypt, ZeroSSL, etc.) configured in the os-acme-client plugin
opnsense_acme_list_certsList all ACME certificates and their status (issued, pending, expired)
opnsense_acme_list_challengesList all configured ACME challenge/validation methods (DNS-01, HTTP-01, etc.)
opnsense_acme_register_accountTrigger registration of an ACME account with its certificate authority. Use after adding an account to verify it registers successfully.
opnsense_acme_renew_certTrigger immediate renewal/signing of an ACME certificate by UUID
opnsense_acme_settingsGet or update ACME service settings (enable/disable, environment, auto-renewal, log level). When called with no parameters, returns current settings. Run opnsense_acme_apply afterwards when updating.
opnsense_acme_update_challengewrite actionUpdate an existing ACME challenge/validation by UUID. Use to change credentials or settings. Run opnsense_acme_apply afterwards.
opnsense_dhcp_add_staticAdd a static DHCP mapping (MAC-to-IP reservation). Supports both Kea DHCP and ISC DHCP (legacy) backends — auto-detected. Requires DHCP service restart to take effect.
opnsense_dhcp_delete_staticwrite actionDelete a static DHCP mapping by UUID. Supports both Kea DHCP and ISC DHCP (legacy) backends — auto-detected.
opnsense_dhcp_find_leaseSearch DHCPv4 leases by IP address, MAC address, or hostname
opnsense_dhcp_list_leasesList all current DHCPv4 leases
opnsense_dhcp_list_staticList all static DHCP mappings (MAC-to-IP reservations). Supports both Kea DHCP and ISC DHCP (legacy) backends — auto-detected.
opnsense_diag_arp_tableShow the ARP table (IP-to-MAC mappings). Optionally filter by IP, MAC, or interface.
opnsense_diag_dns_lookupPerform a DNS lookup from the OPNsense firewall
opnsense_diag_fw_logsRetrieve recent firewall log entries
opnsense_diag_fw_statesList active firewall connection tracking states
opnsense_diag_pingPing a host from the OPNsense firewall
opnsense_diag_reverse_dnsPerform a reverse DNS lookup (IP to hostname) from the OPNsense firewall
opnsense_diag_routesShow the routing table
opnsense_diag_system_infoGet system status information (CPU, memory, uptime, disk, versions)
opnsense_diag_traceroutewrite actionRun a traceroute from the OPNsense firewall to a destination
opnsense_dns_add_forwardAdd a DNS forwarding server (DNS-over-TLS). Run opnsense_dns_apply afterwards to activate.
opnsense_dns_add_overrideAdd a DNS host override (A/AAAA/CNAME record) to Unbound. Run opnsense_dns_apply afterwards to activate.
opnsense_dns_applyApply pending DNS/Unbound configuration changes (reconfigure service)
opnsense_dns_block_domainBlock a domain by adding a domain override with an empty server. Run opnsense_dns_apply afterwards to activate.
opnsense_dns_cache_searchSearch the Unbound DNS cache for entries matching a domain. Useful for diagnosing cached SERVFAIL, stale records, or verifying cache state.
opnsense_dns_delete_forwardwrite actionDelete a DNS forwarding entry by UUID. Run opnsense_dns_apply afterwards to activate.
opnsense_dns_delete_overridewrite actionDelete a DNS host override by UUID. Run opnsense_dns_apply afterwards to activate.
opnsense_dns_diagnosticsDump the current Unbound DNS cache for diagnostic purposes
opnsense_dns_flush_cacheFlush the Unbound DNS resolver cache
opnsense_dns_flush_zoneFlush all cached DNS entries for a specific domain/zone. Use this to clear stale SERVFAIL or outdated records for a domain. Restarts Unbound to ensure complete cache clearing.
opnsense_dns_infraDump the Unbound infrastructure cache showing upstream server RTT, EDNS support, and lame delegation status. Useful for diagnosing upstream DNS connectivity issues.
opnsense_dns_list_blocklistList all domain overrides (used for domain blocking) in Unbound
opnsense_dns_list_forwardsList all DNS-over-TLS forwarding servers configured in Unbound
opnsense_dns_list_overridesList all DNS host overrides (A/AAAA/CNAME records) configured in Unbound
opnsense_dns_statsGet Unbound DNS resolver statistics: query counts, cache hits/misses, uptime, and memory usage
opnsense_dns_unblock_domainUnblock a domain by deleting its domain override. Run opnsense_dns_apply afterwards to activate.
opnsense_firmware_infoGet firmware version, architecture, and update status of the OPNsense system
opnsense_firmware_installInstall an OPNsense plugin package by name (e.g. 'os-acme-client'). May require a service restart.
opnsense_firmware_list_pluginsList all available and installed OPNsense plugins with their versions and status
opnsense_firmware_removewrite actionRemove an installed OPNsense plugin package. DESTRUCTIVE: requires explicit confirmation.
opnsense_firmware_statusCheck for available firmware upgrades and their status (running, pending, done)
opnsense_fw_add_ruleAdd a new firewall filter rule. Run opnsense_fw_apply afterwards to activate.
opnsense_fw_applyApply pending firewall configuration changes
opnsense_fw_delete_rulewrite actionDelete a firewall filter rule by UUID. Run opnsense_fw_apply afterwards to activate.
opnsense_fw_drift_checkAudit firewall filter rules for description hygiene. Returns rules whose description does not match the given regex (default: '^#\d+:' — issue-reference prefix) and rules with empty descriptions. Read-only.
opnsense_fw_list_aliasesList all firewall aliases (host groups, networks, ports, URLs)
opnsense_fw_list_rulesList all firewall filter rules
opnsense_fw_manage_aliaswrite actionCreate, update, or delete a firewall alias. Run opnsense_fw_apply afterwards to activate.
opnsense_fw_reorder_rulesChange the sequence (ordering) of a firewall filter rule by UUID. Rules with lower sequence values are evaluated first. Use this to enforce whitelist-before-deny ordering. Run opnsense_fw_apply afterwards to activate.
opnsense_fw_toggle_ruleEnable or disable a firewall rule by UUID. Run opnsense_fw_apply afterwards to activate.
opnsense_fw_update_rulewrite actionUpdate an existing firewall filter rule by UUID. Run opnsense_fw_apply afterwards to activate.
opnsense_if_assignAssign an existing VLAN or NIC device to a free optN slot via SSH. Requires OPNSENSE_SSH_ENABLED=true and the opnsense-helpers/if_assign.php script installed on the target host. Fills the gap where the OPNsense REST API has no 'Interfaces → Assignments' endpoint.
opnsense_if_configureConfigure IPv4/IPv6 on an already-assigned optN slot via SSH. Supports static, dhcp, dhcp6, track6, and 'none'. Requires OPNSENSE_SSH_ENABLED=true and the opnsense-helpers/if_configure.php script installed on the target host.
opnsense_if_getGet detailed configuration for a specific network interface (IP addresses, status, MTU, etc.)
opnsense_if_listList all network interface names and their device mappings
opnsense_if_statsGet traffic statistics for all interfaces (bytes, packets, errors, collisions)
opnsense_kea_applyApply pending Kea DHCP configuration changes (reconfigure service). Run after subnet or reservation changes.
opnsense_kea_subnet_createwrite actionCreate a new Kea DHCPv4 subnet. Run opnsense_kea_apply afterwards to activate.
opnsense_kea_subnet_deletewrite actionDelete a Kea DHCPv4 subnet by UUID. Run opnsense_kea_apply afterwards to activate.
opnsense_kea_subnet_getGet detailed configuration of a specific Kea DHCPv4 subnet by UUID.
opnsense_kea_subnet_listList all Kea DHCPv4 subnets with their pools, options, and reservation counts.
opnsense_kea_subnet_updatewrite actionUpdate an existing Kea DHCPv4 subnet. Run opnsense_kea_apply afterwards to activate.
opnsense_route_addAdd a static route. The gateway parameter must be a gateway name from opnsense_route_gateway_list. Run opnsense_route_apply afterwards to activate.
opnsense_route_applyApply static route configuration changes (reconfigure routing)
opnsense_route_deletewrite actionDelete a static route. Run opnsense_route_apply afterwards to activate.
opnsense_route_gateway_listList all available gateways (used as targets for static routes)
opnsense_route_listList all configured static routes
opnsense_route_updatewrite actionUpdate an existing static route. Run opnsense_route_apply afterwards to activate.
opnsense_svc_controlStart, stop, or restart a service by name
opnsense_svc_listList all services and their running status
opnsense_sys_backup_downloadDownload an OPNsense configuration backup as XML. Downloads the current running config if no backup_id is specified.
opnsense_sys_backup_listList all configuration backups stored on the OPNsense filesystem with timestamps, descriptions, and file sizes
opnsense_sys_backup_revertRevert OPNsense configuration to a previous backup. DESTRUCTIVE: replaces the running config with the specified backup.
opnsense_sys_infoGet system status information (hostname, versions, CPU, memory, uptime, disk usage)
opnsense_sys_list_certsList all certificates in the OPNsense trust store with their refids, descriptions, and validity dates
opnsense_tailscale_service_controlControl the Tailscale service: start, stop, restart, or reconfigure (apply settings changes).
opnsense_tailscale_service_statusCheck if the Tailscale service (tailscaled) is running.
opnsense_tailscale_settings_getGet current Tailscale plugin settings (enabled, port, auth-key, advertise-routes, accept-routes, accept-dns, exit-node).
opnsense_tailscale_settings_setwrite actionUpdate Tailscale plugin settings. Only provided fields are changed. Run opnsense_tailscale_service_control with action 'reconfigure' afterwards to apply.
opnsense_vlan_createwrite actionCreate a new 802.1Q VLAN interface on a parent interface. After create, run opnsense_if_assign to bind the VLAN to a logical interface (opt1, opt2, ...) and opnsense_if_configure to assign an IP.
opnsense_vlan_deletewrite actionDelete a VLAN interface by UUID. Fails if the VLAN is still assigned to a logical interface — unassign it first via opnsense_if_assign.
opnsense_vlan_listList all configured 802.1Q VLAN interfaces (parent interface, VLAN tag, description, priority)
opnsense_vlan_updatewrite actionUpdate an existing VLAN interface by UUID. Only provided fields are changed.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan41 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Install OPNsense MCP Server in Claude Code, Cursor or VS Code
Runs npx -y @itunified.io/mcp-opnsense on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add opnsense -- npx -y @itunified.io/mcp-opnsense
OPNsense MCP Server: common questions
- Is OPNsense MCP Server safe?
- With care: it is graded C, so read the findings first (65/100). Read the OPNsense MCP Server safety report
- How do I install OPNsense MCP Server?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does OPNsense MCP Server need an API key?
- No secret keys are declared. It reads 4 settings from the environment.
- Is OPNsense MCP Server maintained?
- The latest release is v2026.4.10.
- What can I use instead of OPNsense MCP Server?
- Servers from other publishers that do the same job: Mikrotik MCP server and UniFi Network MCP server.
Alternatives to OPNsense MCP Server
Same job from other publishers: the closest match first, then the best rated.
- MikrotikMCP server for MikroTik routers: firewall, NAT, routing, DHCP, DNS, WireGuard and more via SSH.not reviewedEstablishedB
- UniFi Network MCPManage UniFi Network devices, clients, firewall, VLANs, VPNs, and more via MCP.not reviewedEstablishedB