gensecaihq/pfsense-mcp-server
Model Context Protocol (MCP) server for pfSense firewall management. Control firewall rules, VPNs, DNS, DHCP and diagnostics in natural language from Claude Desktop, Claude Code or any MCP client — 333 wire-format-verified tools for the pfS
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code
$ claude mcp add pfsense -e AUTH_METHOD=YOUR_AUTH_METHOD -e ENABLE_HATEOAS=YOUR_ENABLE_HATEOAS -e LOG_LEVEL=YOUR_LOG_LEVEL -e PFSENSE_<redacted> -e PFSENSE_URL=YOUR_PFSENSE_URL -e PFSENSE_VERSION=YOUR_PFSENSE_VERSION -e VERIFY_SSL=YOUR_VERIFY_SSL -- python3.11 -m src.main MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add pfsense -e AUTH_METHOD=YOUR_AUTH_METHOD -e ENABLE_HATEOAS=YOUR_ENABLE_HATEOAS -e LOG_LEVEL=YOUR_LOG_LEVEL -e PFSENSE_<redacted> -e PFSENSE_URL=YOUR_PFSENSE_URL -e PFSENSE_VERSION=YOUR_PFSENSE_VERSION -e VERIFY_SSL=YOUR_VERIFY_SSL -- python3.11 -m src.main This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 6,974 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(~/.aws/**)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(.env)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/.env.*)",
"Read(**/*.key)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(npm publish:*)",
"Bash(wget *)",
"Bash(git rebase *)",
"Bash(gh pr merge *)",
"Bash(git commit *)"
]
}
} MCP servers (1)
| server | source | est. tokens |
|---|---|---|
| python3.11 · "pfsense" env: AUTH_METHOD, ENABLE_HATEOAS, LOG_LEVEL, PFSENSE_API_KEY, PFSENSE_URL +2 | binary | 2.5k |
Similar rigs
omega-memory/omega-memory
Persistent memory for AI coding agents
Pragmatist 2.6k tok ·
anomalyco/opencode
The open source coding agent.
Pragmatist 4.2k tok ·
DietrichGebert/ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
Pragmatist 1.6k tok ·
Shubhamsaboo/awesome-llm-apps
100+ AI Agents, Agent Skills and RAG Apps - Free and Open Source.
Pragmatist 4.2k tok ·