Coding

firewall-aiops

Try it

Governed firewall operations for OPNsense and pfSense — read, write, audit, and undo with 35 tools.

What it does

Run governed operations against OPNsense (REST) or pfSense (REST v2) firewalls. Every tool is wrapped in a local audit harness that records timestamps, risk tiers, and undo descriptors. Use the read-only tools to pull a full snapshot, investigate gateway health, audit rules for never-hit or shadowed entries, classify blocked traffic, and inspect NAT, aliases, VPN tunnels, and DHCP leases. When a change is needed, governed writes capture the real before-state so they are reversible up until you commit with apply_changes. High-risk operations (apply, reconfigure, reboot) are labelled as such and refuse to proceed if a staged change would cut off management access.

When to use it

  • Internet drops — diagnose WAN gateway health with transparent loss/latency ranking
  • Ruleset audit — find never-hit, shadowed, or duplicate rules
  • Brute-force or scan on WAN — classify blocked sources and block them via alias
  • Change window — stage edits, dry-run, then commit with audit trail and rollback available

The skill document

Firewall AIops

Disclaimer: Community-maintained open-source project, not affiliated with, endorsed by, or sponsored by the OPNsense project, Deciso, Netgate, or the pfSense project. OPNsense, pfSense and Netgate are trademarks of their respective owners. Source at github.com/AIops-tools/Firewall-AIops under the MIT license.

Governed firewall operations — 35 MCP tools across OPNsense (REST /api/...) and pfSense (REST v2 /api/v2/...), every one wrapped with the bundled @governed_tool harness: a local unified audit log under ~/.firewall-aiops/, policy engine, token/runaway budget guard, undo-token recording, and descriptive risk-tier labelling. A per-target platform field selects the API shape, so the same tools work on both firewalls and one config can span a mixed estate. The OPNsense API secret / pfSense API key is stored encrypted (~/.firewall-aiops/secrets.enc, Fernet + scrypt) — never plaintext on disk.

Standalone: the governance harness is bundled in the package (firewall_aiops.governance) — no external skill-family dependency. Behaviour is covered by a mock-based test suite; docs/VERIFICATION.md is the checklist for a live run against a real firewall (both platforms are free/self-hostable).

What This Skill Does

GroupToolsCountR/W
Systemfirmware_status, health_status, interface_status, gateway_status4read
Ruleslist_rules, rule_detail, rule_stats, rule_states, pending_changes5read
NATnat_port_forwards, nat_outbound, nat_one_to_one3read
Aliaseslist_aliases, alias_entries2read
VPNwireguard_status, openvpn_sessions, ipsec_sas3read
DHCPdhcp_leases, dhcp_static_mappings2read
Diagnosticsfirewall_log, states_table, top_talkers3read
Flagship analysesgateway_health_rca, rule_hit_and_shadow_analysis, blocked_traffic_rca3read
Writestoggle_rule, add_alias_entry, remove_alias_entry, kill_states, restart_service5write (med)
Writesapply_changes, reconfigure, reboot3write (high)
Undoundo_list, undo_apply2read / write

The three flagship analyses are transparent heuristics that report their numbers, never a black-box verdict: gateway_health_rca ranks gateways by loss + latency and maps each down/degraded one to a cause + action; rule_hit_and_shadow_analysis finds never-hit and shadowed/redundant rules; blocked_traffic_rca classifies the noisiest blocked sources as scan / brute-force / probe.

Quick Install

uv tool install firewall-aiops
firewall-aiops init       # wizard: pick platform (opnsense/pfsense) + encrypted secret
firewall-aiops doctor

When to Use This Skill

  • Get a one-shot snapshot (overview / firmware_status / gateway_status)
  • Investigate a down/degraded WAN (gateway_health_rca) → cause + action
  • Audit the ruleset (rule_stats hit counts, rule_hit_and_shadow_analysis for never-hit / shadowed / redundant rules)
  • Triage hostile traffic (firewall_log --action block, blocked_traffic_rca, top_talkers)
  • Inspect NAT, aliases, VPN tunnels (WireGuard/OpenVPN/IPsec), and DHCP leases
  • Safely toggle a rule or edit an alias (toggle_rule / add_alias_entry / remove_alias_entry, reversible + undo-recorded), then make it live with apply_changes (dry-run + audit)

Do NOT use when the target is not an OPNsense/pfSense firewall — route hypervisor, storage, backup, cluster, multi-vendor router/switch config, or OT/industrial work to the appropriate other AIops-tools skill.

If the user wants…Use
OPNsense / pfSense firewall opsfirewall-aiops (this skill)
A non-firewall platform (hypervisor, storage, backup, cluster, network config, OT edge)the appropriate other AIops-tools skill
Cloud security groups / vendor firewall appliancesout of scope for this tool

Common Workflows

The CLI surface is init / doctor / overview / log / rules / secret / undo; the flagship RCAs, NAT / alias / VPN / DHCP reads, and the remaining governed writes are MCP tools (start the server with firewall-aiops mcp). Recipes below say which is which.

1. "The internet keeps dropping" — WAN gateway triage

  1. firewall-aiops doctor → confirm the firewall is reachable and the secret unlocks (a red doctor means you are debugging credentials, not the WAN).
  2. firewall-aiops overview → one-shot: firmware/version, gateway + interface health, rule count. Down interfaces sort first.
  3. MCP gateway_health_rca → gateways ranked worst-first, each row citing its measured loss % and RTT, mapped to a cause (last-mile loss / congestion / latency / hard down) and a concrete action.
  4. If the RCA points at a stuck daemon rather than the circuit, MCP restart_service(service="dpinger", dry_run=true) to preview, then re-run for real (medium risk, audited, undo-recorded).
  5. Re-run firewall-aiops overview to confirm the gateway came back green.
  6. Failure branch: if the restart does not clear it, the gateway is genuinely down upstream — stop touching the firewall and escalate to the ISP. If the restart made things worse, firewall-aiops undo list → firewall-aiops undo apply reverses the recorded inverse. Do not reach for reboot (high risk, irreversible, no undo) until a read confirms it is the only remaining option.

2. Ruleset spring-clean — retire a rule that never fires

  1. MCP rule_hit_and_shadow_analysis → enabled rules with 0 evaluations (dead or misordered), rules shadowed by an earlier terminating rule, and exact duplicates — each finding names the offending and the covering rule uuid.
  2. firewall-aiops rules list --interface wan → confirm the candidate's position in the evaluation order (a "never hit" rule below a broad allow is misordered, not useless).
  3. firewall-aiops rules show → read the full rule before touching it.
  4. firewall-aiops rules toggle --disable --dry-run → prints the exact call, changes nothing.
  5. firewall-aiops rules toggle --disable → double-confirm; the write fetches the rule's real prior enabled flag and records an inverse undo descriptor with an _undo_id.
  6. MCP pending_changes → read what the commit would actually make live, including whether any staged rule covers the endpoint this tool manages the firewall through. toggle_rule already reported managementImpact in step 5 if so.
  7. MCP apply_changes to commit the staged config — risk=high, so set FIREWALL_AUDIT_APPROVED_BY and FIREWALL_AUDIT_RATIONALE first. It refuses outright if a staged rule would provably cut management access; pass override=True only with console access in hand.
  8. Failure branch: if traffic breaks after the commit, firewall-aiops undo apply restores the rule's prior enabled state, then apply_changes again to make the restoration live. The toggle is staged until applied — before step 6 you can simply toggle it back with no commit at all.

3. Brute-force against the WAN — block the source with an alias

  1. firewall-aiops log --action block --limit 100 → the raw recent blocks, so you are reading real log lines and not just a summary.
  2. MCP blocked_traffic_rca → noisiest blocked sources ranked and classified (port scan, service brute-force on 22/3389/…, or generic probe), each with a recommended action.
  3. MCP top_talkers and states_table → cross-check whether the source also has established states, i.e. whether anything already got through.
  4. MCP list_aliases → find your blocklist alias, then alias_entries() to see what is already in it.
  5. MCP add_alias_entry(alias=, entry=) → medium risk, reversible, undo descriptor recorded from the fetched before-state.
  6. MCP apply_changes (high risk, audited) to make the alias live, then kill_states(source=) to tear down any states the attacker already holds.
  7. Failure branch: if you blocked too wide a range and locked out legitimate traffic, MCP remove_alias_entry (or firewall-aiops undo apply ) and apply_changes again. If you locked yourself out of the web UI, the CLI still works over the API as long as the management rule was untouched — recover there before rebooting.

4. Verify and roll back a change window

  1. Before the window: firewall-aiops overview and firewall-aiops rules list → capture the baseline you intend to return to.
  2. Make the staged changes (rules toggle, MCP alias edits), each one dry-run first.
  3. MCP apply_changes with FIREWALL_AUDIT_APPROVED_BY set → commit.
  4. Validate: firewall-aiops overview, MCP gateway_health_rca, and firewall-aiops log --action block --limit 50 → make sure the change did not start silently dropping wanted traffic.
  5. firewall-aiops undo list → every reversible write in the window, newest first, with its _undo_id.
  6. Failure branch: roll the window back in reverse order with firewall-aiops undo apply per entry, then one final apply_changes to commit the rollback. Writes that declare no undo (reboot, and apply_changes itself) cannot be reversed this way — they are audit-only, which is why every reversible edit goes in before the commit.

Authorization is not this skill's job: there is no read-only switch, policy file, or approval gate. Whether a write runs is the agent's judgement or the connecting account's permissions — point the tool at an API user without write scope and writes fail at the server. Every call is still audited. FIREWALL_AUDIT_APPROVED_BY / FIREWALL_AUDIT_RATIONALE are optional audit annotations, recorded when set but never required.

Governance & Safety

  • Every tool is audited to ~/.firewall-aiops/audit.db (relocatable via FIREWALL_AIOPS_HOME).
  • High-risk ops (apply_changes, reconfigure, reboot) are labelled risk=high and audited; FIREWALL_AUDIT_APPROVED_BY / FIREWALL_AUDIT_RATIONALE are optional audit annotations, recorded when set but never required.
  • Writes support --dry-run and double confirmation at the CLI. reboot is irreversible (audit only).
  • Reversible writes capture the real fetched before-state and record an inverse descriptor (toggle→toggle-back, add-alias↔remove-alias).

References

  • references/capabilities.md — full tool + platform + API-path reference
  • references/cli-reference.md — CLI command reference
  • references/setup-guide.md — onboarding, credentials, and connectivity
  • docs/VERIFICATION.md — live-verification checklist (what the mock suite covers, and what a real-firewall run must prove)

Questions people ask

What platforms does this support?
OPNsense and pfSense only. Each tool uses the platform's native REST API. Other firewalls, hypervisors, or network devices are out of scope.
Can I undo a change before it goes live?
Yes, for reversible writes (toggle rule, add/remove alias entries, restart service). The harness records the fetched before-state and an inverse descriptor. Run undo_list to see recorded entries, then undo_apply to reverse. apply_changes and reboot have no undo.
What happens if I accidentally disable the management rule?
apply_changes will refuse to commit if a staged rule would cut off the management interface. override=True bypasses this check, but only attempt it with console access in hand.

Related skills

Operate Kubernetes clusters with 55 audited tools — list resources, diagnose pod health, scale workloads, and manage rollouts safely.

by zw0081 installs1 stars

Escape the scarcity trap — diagnose bandwidth consumption and design protected slack to restore strategic capacity.

by deciqai1 installs2 stars

Join video meetings as a voice bot, visual avatar, or avatar with live screen sharing.

by johnpatternai22 installs8 stars

Turn China 3C launch inputs into executable routes, messaging, channel actions, risk checks, and review decisions.

by killsnake0126 installs112 stars

End-of-day options analytics ranked against each ticker's own history: IV rank, put/call percentile, skew, max pain, and unusually active contracts.

by thesentitrader2 installs2 stars

Operate TaskTime Pro through MCP: manage tasks, track time, handle expenses, and prepare invoices from a paired browser session.

by tasktimepro1 installs1 stars

More from zw008

Browse all skills

Operate VMware VMs, deployments, clusters, guest tasks, and alarms with plan and rollback support.

by zw00878 installs1 stars

Inspect VMware health, inventory, alarms, events, and performance without changing infrastructure.

by zw00876 installs

Query Aria Operations metrics, alerts, capacity forecasts, anomalies, and reports from CLI or MCP.

by zw00853 installs

Manage AVI services and pools, and diagnose AKO ingress, sync, certificates, analytics, and health.

by zw00851 installs

Manage Supervisor Namespaces and TKC cluster lifecycles in vSphere Kubernetes Service.

by zw00851 installs

Manage NSX segments, gateways, routing, IP pools, health checks, and connectivity diagnostics.

by zw00850 installs