Releases: ry-ops/fortigate-mcp-server
Releases · ry-ops/fortigate-mcp-server
Release list
v0.4.1 — Report the server's own version
Fixed
- The server reported the MCP SDK's version (1.30.0) to clients instead of its own.
uvx --from git+https://github.com/ry-ops/fortigate-mcp-server@v0.4.1 fortigate-mcp-serverFull changelog: v0.4.0...v0.4.1
v0.4.0 — Free-license aware, with k3s and Proxmox integrations
Added
get_license_limits: policies, static routes and interfaces in use against the free
FortiGate-VM evaluation license's limits of 3 each (applied only onvm_eval).- Port forwards:
list_port_forwards,create_port_forward,delete_port_forward.
create_port_forwardcan attach the VIP to an existing policy instead of needing a new one,
checks first that the policy takes traffic from the VIP's interface and does not mix VIPs
with ordinary addresses (replace_destinations=trueconverts it on purpose), deletes the VIP
again if the policy refuses it, and says when no policy slot is free.delete_port_forward
can detach the VIP from policies first. get_top_traffic(FortiView realtime statistics by source, destination, application,
country, interface, policy or protocol, with application names) andget_arp_table.- Application control:
search_applications,list_app_categories,
list_app_control_profiles,add_app_control_rule(by application or category name; new
rules go above the built-in catch-all pass rule) anddelete_app_control_rule. - Service groups:
list_service_groups,create_service_group,update_service_group,
delete_service_group. - Optional Kubernetes integration (
K8S_KUBECONFIG):k8s_cluster_overview,
k8s_sync_ingress_dns(Ingress and Traefik IngressRoute hostnames become FortiGate DNS
records, standing in for the wildcard records FortiOS cannot hold) and
k8s_sync_node_addresses(node IPs kept in an address range or group). Both sync tools
default todry_run=true; the cluster is only read. - Optional Proxmox VE integration (
PROXMOX_*, a PVEAuditor token is enough):
identify_clients, plusresolve_vms=trueonget_logs,list_sessions,
get_top_trafficandlist_dhcp_leasesto label IPs and MACs with the owning VM. - README rebuilt with animated visuals, a tool catalog generated from the code, and a
zero to firewall walkthrough;CHANGELOG.md; CI running ruff,
the tests on Python 3.10 to 3.13 and a README catalog check.
Install
uvx --from git+https://github.com/ry-ops/fortigate-mcp-server@v0.4.0 fortigate-mcp-serverFull changelog: v0.3.0...v0.4.0
v0.3.0 — Logs, inspection, certificates and license activation
Added
get_logs: traffic, app-ctrl, event, IPS, web filter and other logs from memory, disk or
FortiAnalyzer, with filters, paging and field selection.- Policy tools take security profiles (
ssl_ssh_profile,application_list,ips_sensor,
av_profile,webfilter_profile), enableutm-statuswhen one is attached, and warn when an
SSL profile sits on a policy with no security profile (it inspects nothing in flow mode). list_ssl_ssh_profilesandupdate_ssl_ssh_profile(built-in read-only profiles refused).list_certificateswith key type and size, flagging RSA keys under 2048 bits, and
download_certificate(PEM and SHA-256 fingerprint).activate_vm_eval_license: activates the free permanent evaluation license through
FortiCloud. Credentials come fromFORTICLOUD_ACCOUNT/FORTICLOUD_PASSWORDonly, it needs
confirm=true, and it does nothing on a licensed VM.
Install
uvx --from git+https://github.com/ry-ops/fortigate-mcp-server@v0.3.0 fortigate-mcp-serverFull changelog: v0.2.0...v0.3.0
v0.2.0 — Hide the FortiConverter setup popup
Added
forticonverter_setup_prompt: reads or hides the GUI setup popup's "Migrate Config with
FortiConverter" step, which never completes on evaluation VMs, through the undocumented
POST /api/v2/monitor/forticonverter/show-in-startup/set.
Install
uvx --from git+https://github.com/ry-ops/fortigate-mcp-server@v0.2.0 fortigate-mcp-serverFull changelog: v0.1.0...v0.2.0
v0.1.0 — Initial release
Initial release: 48 tools for FortiOS 7.6 (system, firewall policies, addresses, services,
routing, DNS and DHCP, and a raw /api/v2/ tool), API-token or session auth with the 7.6 JSON
login, FORTIGATE_READ_ONLY, and FortiOS error details in every failure.
Install
uvx --from git+https://github.com/ry-ops/fortigate-mcp-server@v0.1.0 fortigate-mcp-server