Mmcp.market

OPNsense MCP Server

by itunified-io·io.github.itunified-io/opnsense·v2026.4.10

OPNsense MCP Server — 72 tools for DNS, Firewall, DHCP, ACME, Routing, VLANs & more

C65/100grade C
What users say
No reviews yet
Be the first
Safety scan
C65/100

full report

Adoption
Not measured yet

Usage numbers are collected on the next scan

Reviews

Write one

Nobody has reviewed OPNsense MCP Server yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

OPNsense MCP Server tools (91, 22 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • opnsense_acme_add_account

    Register a new ACME account with a certificate authority (Let's Encrypt, ZeroSSL, etc.). Run opnsense_acme_apply afterwards.

  • opnsense_acme_add_challenge

    Add a DNS-01 challenge configuration for automated certificate validation. For Cloudflare, use the dedicated dns_cf_* fields instead of dns_environment. Run opnsense_acme_apply afterwards.

  • opnsense_acme_apply

    Apply pending ACME configuration changes (reconfigure service)

  • opnsense_acme_create_certwrite action

    Create a new ACME certificate request. Requires an account and challenge to be configured first. Run opnsense_acme_apply afterwards.

  • opnsense_acme_delete_accountwrite action

    Delete an ACME account by UUID. Run opnsense_acme_apply afterwards.

  • opnsense_acme_delete_certwrite action

    Delete an ACME certificate by UUID. Run opnsense_acme_apply afterwards.

  • opnsense_acme_delete_challengewrite action

    Delete an ACME challenge/validation method by UUID. Run opnsense_acme_apply afterwards.

  • opnsense_acme_list_accounts

    List all ACME accounts (Let's Encrypt, ZeroSSL, etc.) configured in the os-acme-client plugin

  • opnsense_acme_list_certs

    List all ACME certificates and their status (issued, pending, expired)

  • opnsense_acme_list_challenges

    List all configured ACME challenge/validation methods (DNS-01, HTTP-01, etc.)

  • opnsense_acme_register_account

    Trigger registration of an ACME account with its certificate authority. Use after adding an account to verify it registers successfully.

  • opnsense_acme_renew_cert

    Trigger immediate renewal/signing of an ACME certificate by UUID

  • opnsense_acme_settings

    Get or update ACME service settings (enable/disable, environment, auto-renewal, log level). When called with no parameters, returns current settings. Run opnsense_acme_apply afterwards when updating.

  • opnsense_acme_update_challengewrite action

    Update an existing ACME challenge/validation by UUID. Use to change credentials or settings. Run opnsense_acme_apply afterwards.

  • opnsense_dhcp_add_static

    Add a static DHCP mapping (MAC-to-IP reservation). Supports both Kea DHCP and ISC DHCP (legacy) backends — auto-detected. Requires DHCP service restart to take effect.

  • opnsense_dhcp_delete_staticwrite action

    Delete a static DHCP mapping by UUID. Supports both Kea DHCP and ISC DHCP (legacy) backends — auto-detected.

  • opnsense_dhcp_find_lease

    Search DHCPv4 leases by IP address, MAC address, or hostname

  • opnsense_dhcp_list_leases

    List all current DHCPv4 leases

  • opnsense_dhcp_list_static

    List all static DHCP mappings (MAC-to-IP reservations). Supports both Kea DHCP and ISC DHCP (legacy) backends — auto-detected.

  • opnsense_diag_arp_table

    Show the ARP table (IP-to-MAC mappings). Optionally filter by IP, MAC, or interface.

  • opnsense_diag_dns_lookup

    Perform a DNS lookup from the OPNsense firewall

  • opnsense_diag_fw_logs

    Retrieve recent firewall log entries

  • opnsense_diag_fw_states

    List active firewall connection tracking states

  • opnsense_diag_ping

    Ping a host from the OPNsense firewall

  • opnsense_diag_reverse_dns

    Perform a reverse DNS lookup (IP to hostname) from the OPNsense firewall

  • opnsense_diag_routes

    Show the routing table

  • opnsense_diag_system_info

    Get system status information (CPU, memory, uptime, disk, versions)

  • opnsense_diag_traceroutewrite action

    Run a traceroute from the OPNsense firewall to a destination

  • opnsense_dns_add_forward

    Add a DNS forwarding server (DNS-over-TLS). Run opnsense_dns_apply afterwards to activate.

  • opnsense_dns_add_override

    Add a DNS host override (A/AAAA/CNAME record) to Unbound. Run opnsense_dns_apply afterwards to activate.

  • opnsense_dns_apply

    Apply pending DNS/Unbound configuration changes (reconfigure service)

  • opnsense_dns_block_domain

    Block a domain by adding a domain override with an empty server. Run opnsense_dns_apply afterwards to activate.

  • opnsense_dns_cache_search

    Search the Unbound DNS cache for entries matching a domain. Useful for diagnosing cached SERVFAIL, stale records, or verifying cache state.

  • opnsense_dns_delete_forwardwrite action

    Delete a DNS forwarding entry by UUID. Run opnsense_dns_apply afterwards to activate.

  • opnsense_dns_delete_overridewrite action

    Delete a DNS host override by UUID. Run opnsense_dns_apply afterwards to activate.

  • opnsense_dns_diagnostics

    Dump the current Unbound DNS cache for diagnostic purposes

  • opnsense_dns_flush_cache

    Flush the Unbound DNS resolver cache

  • opnsense_dns_flush_zone

    Flush all cached DNS entries for a specific domain/zone. Use this to clear stale SERVFAIL or outdated records for a domain. Restarts Unbound to ensure complete cache clearing.

  • opnsense_dns_infra

    Dump the Unbound infrastructure cache showing upstream server RTT, EDNS support, and lame delegation status. Useful for diagnosing upstream DNS connectivity issues.

  • opnsense_dns_list_blocklist

    List all domain overrides (used for domain blocking) in Unbound

  • opnsense_dns_list_forwards

    List all DNS-over-TLS forwarding servers configured in Unbound

  • opnsense_dns_list_overrides

    List all DNS host overrides (A/AAAA/CNAME records) configured in Unbound

  • opnsense_dns_stats

    Get Unbound DNS resolver statistics: query counts, cache hits/misses, uptime, and memory usage

  • opnsense_dns_unblock_domain

    Unblock a domain by deleting its domain override. Run opnsense_dns_apply afterwards to activate.

  • opnsense_firmware_info

    Get firmware version, architecture, and update status of the OPNsense system

  • opnsense_firmware_install

    Install an OPNsense plugin package by name (e.g. 'os-acme-client'). May require a service restart.

  • opnsense_firmware_list_plugins

    List all available and installed OPNsense plugins with their versions and status

  • opnsense_firmware_removewrite action

    Remove an installed OPNsense plugin package. DESTRUCTIVE: requires explicit confirmation.

  • opnsense_firmware_status

    Check for available firmware upgrades and their status (running, pending, done)

  • opnsense_fw_add_rule

    Add a new firewall filter rule. Run opnsense_fw_apply afterwards to activate.

  • opnsense_fw_apply

    Apply pending firewall configuration changes

  • opnsense_fw_delete_rulewrite action

    Delete a firewall filter rule by UUID. Run opnsense_fw_apply afterwards to activate.

  • opnsense_fw_drift_check

    Audit firewall filter rules for description hygiene. Returns rules whose description does not match the given regex (default: '^#\d+:' — issue-reference prefix) and rules with empty descriptions. Read-only.

  • opnsense_fw_list_aliases

    List all firewall aliases (host groups, networks, ports, URLs)

  • opnsense_fw_list_rules

    List all firewall filter rules

  • opnsense_fw_manage_aliaswrite action

    Create, update, or delete a firewall alias. Run opnsense_fw_apply afterwards to activate.

  • opnsense_fw_reorder_rules

    Change the sequence (ordering) of a firewall filter rule by UUID. Rules with lower sequence values are evaluated first. Use this to enforce whitelist-before-deny ordering. Run opnsense_fw_apply afterwards to activate.

  • opnsense_fw_toggle_rule

    Enable or disable a firewall rule by UUID. Run opnsense_fw_apply afterwards to activate.

  • opnsense_fw_update_rulewrite action

    Update an existing firewall filter rule by UUID. Run opnsense_fw_apply afterwards to activate.

  • opnsense_if_assign

    Assign an existing VLAN or NIC device to a free optN slot via SSH. Requires OPNSENSE_SSH_ENABLED=true and the opnsense-helpers/if_assign.php script installed on the target host. Fills the gap where the OPNsense REST API has no 'Interfaces → Assignments' endpoint.

  • opnsense_if_configure

    Configure IPv4/IPv6 on an already-assigned optN slot via SSH. Supports static, dhcp, dhcp6, track6, and 'none'. Requires OPNSENSE_SSH_ENABLED=true and the opnsense-helpers/if_configure.php script installed on the target host.

  • opnsense_if_get

    Get detailed configuration for a specific network interface (IP addresses, status, MTU, etc.)

  • opnsense_if_list

    List all network interface names and their device mappings

  • opnsense_if_stats

    Get traffic statistics for all interfaces (bytes, packets, errors, collisions)

  • opnsense_kea_apply

    Apply pending Kea DHCP configuration changes (reconfigure service). Run after subnet or reservation changes.

  • opnsense_kea_subnet_createwrite action

    Create a new Kea DHCPv4 subnet. Run opnsense_kea_apply afterwards to activate.

  • opnsense_kea_subnet_deletewrite action

    Delete a Kea DHCPv4 subnet by UUID. Run opnsense_kea_apply afterwards to activate.

  • opnsense_kea_subnet_get

    Get detailed configuration of a specific Kea DHCPv4 subnet by UUID.

  • opnsense_kea_subnet_list

    List all Kea DHCPv4 subnets with their pools, options, and reservation counts.

  • opnsense_kea_subnet_updatewrite action

    Update an existing Kea DHCPv4 subnet. Run opnsense_kea_apply afterwards to activate.

  • opnsense_route_add

    Add a static route. The gateway parameter must be a gateway name from opnsense_route_gateway_list. Run opnsense_route_apply afterwards to activate.

  • opnsense_route_apply

    Apply static route configuration changes (reconfigure routing)

  • opnsense_route_deletewrite action

    Delete a static route. Run opnsense_route_apply afterwards to activate.

  • opnsense_route_gateway_list

    List all available gateways (used as targets for static routes)

  • opnsense_route_list

    List all configured static routes

  • opnsense_route_updatewrite action

    Update an existing static route. Run opnsense_route_apply afterwards to activate.

  • opnsense_svc_control

    Start, stop, or restart a service by name

  • opnsense_svc_list

    List all services and their running status

  • opnsense_sys_backup_download

    Download an OPNsense configuration backup as XML. Downloads the current running config if no backup_id is specified.

  • opnsense_sys_backup_list

    List all configuration backups stored on the OPNsense filesystem with timestamps, descriptions, and file sizes

  • opnsense_sys_backup_revert

    Revert OPNsense configuration to a previous backup. DESTRUCTIVE: replaces the running config with the specified backup.

  • opnsense_sys_info

    Get system status information (hostname, versions, CPU, memory, uptime, disk usage)

  • opnsense_sys_list_certs

    List all certificates in the OPNsense trust store with their refids, descriptions, and validity dates

  • opnsense_tailscale_service_control

    Control the Tailscale service: start, stop, restart, or reconfigure (apply settings changes).

  • opnsense_tailscale_service_status

    Check if the Tailscale service (tailscaled) is running.

  • opnsense_tailscale_settings_get

    Get current Tailscale plugin settings (enabled, port, auth-key, advertise-routes, accept-routes, accept-dns, exit-node).

  • opnsense_tailscale_settings_setwrite action

    Update Tailscale plugin settings. Only provided fields are changed. Run opnsense_tailscale_service_control with action 'reconfigure' afterwards to apply.

  • opnsense_vlan_createwrite action

    Create a new 802.1Q VLAN interface on a parent interface. After create, run opnsense_if_assign to bind the VLAN to a logical interface (opt1, opt2, ...) and opnsense_if_configure to assign an IP.

  • opnsense_vlan_deletewrite action

    Delete a VLAN interface by UUID. Fails if the VLAN is still assigned to a logical interface — unassign it first via opnsense_if_assign.

  • opnsense_vlan_list

    List all configured 802.1Q VLAN interfaces (parent interface, VLAN tag, description, priority)

  • opnsense_vlan_updatewrite action

    Update an existing VLAN interface by UUID. Only provided fields are changed.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • Code scan41 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancerepository not readable: repo not found3/15
  • Maintainer identityno repository or website to verify2/10
Overall 65/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install OPNsense MCP Server in Claude Code, Cursor or VS Code

Runs npx -y @itunified.io/mcp-opnsense on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add opnsense -- npx -y @itunified.io/mcp-opnsense
Add to Cursor

OPNsense MCP Server: common questions

Is OPNsense MCP Server safe?
With care: it is graded C, so read the findings first (65/100). Read the OPNsense MCP Server safety report
How do I install OPNsense MCP Server?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does OPNsense MCP Server need an API key?
No secret keys are declared. It reads 4 settings from the environment.
Is OPNsense MCP Server maintained?
The latest release is v2026.4.10.
What can I use instead of OPNsense MCP Server?
Servers from other publishers that do the same job: Mikrotik MCP server and UniFi Network MCP server.

Alternatives to OPNsense MCP Server

Same job from other publishers: the closest match first, then the best rated.

  • Mikrotik
    MCP server for MikroTik routers: firewall, NAT, routing, DHCP, DNS, WireGuard and more via SSH.
    B
  • UniFi Network MCP
    Manage UniFi Network devices, clients, firewall, VLANs, VPNs, and more via MCP.
    B

More from itunified-io →