Prisma SD-WAN
БесплатноНе проверенMCP server for querying Palo Alto Networks Prisma SD-WAN with 15+ read-only tools for network inventory and topology.
Описание
MCP server for querying Palo Alto Networks Prisma SD-WAN with 15+ read-only tools for network inventory and topology.
README
Disclaimer: This project is a personal work developed independently for educational and open-source purposes. It is not an official product of Palo Alto Networks, Inc. or any of its affiliates. All trademarks, service marks, and company names are the property of their respective owners.
Two complementary, independently-runnable Model Context Protocol (MCP) servers for Palo Alto Networks Prisma SD-WAN, packaged together because they cover the two ways an agent needs to reach the fabric: the cloud controller API, and the device CLI directly.
| api-mcp/ | cli-mcp/ | |
|---|---|---|
| Transport to the fabric | Prisma SASE / SD-WAN REST API | SSH (Netmiko) straight to the ION |
| Auth model | Service-account credentials, loaded once from .env |
Credentials supplied per call by the caller, never stored |
| Tools | 39 semantic, read-only tools (inventory, topology, monitoring, policy, routing, config export) | One generic tool, run_commands, for a fixed allow-list of read-only ION CLI command families (dump, inspect) |
| Resources | prisma://sites, prisma://topology, prisma://policy-sets, prisma://site/{site_id}/elements |
prisma-cli://policy — the enforced command allow-list, generated from the same policy the server runs |
| Prompts | diagnose_vpn_link_down, audit_site_inventory |
troubleshoot_ion |
| Docs | api-mcp/README.md | cli-mcp/README.md, cli-mcp/RESEARCH.md |
Both servers implement all three MCP primitives — Tools, Resources, and Prompts — not just tool-calling.
webtester/ is a browser UI for exercising api-mcp's tools interactively — a third top-level piece, run separately from either server (see webtester/README.md).
Why two servers instead of one
They don't share a trust boundary. api-mcp holds a long-lived service-account credential and talks to the controller. cli-mcp never holds a credential at all — the caller passes host/username/password (or an inline private key) on every single call, and the server opens a fresh SSH session per request with strict host-key checking. Collapsing them into one process would mean either the CLI tool inherits the API server's stored credential (wrong — it doesn't need one and shouldn't be able to reach one), or the API server starts accepting per-call SSH creds (wrong — it doesn't do SSH). Keeping them as separate deployables keeps each one's blast radius honest.
Run whichever one (or both) a given agent needs; nothing in either depends on the other being present.
Quick start
# API server (needs a Prisma SD-WAN service account — see api-mcp/README.md)
cd api-mcp
python -m pip install -r requirements.txt
python prisma_sdwan_mcp_server.py
# CLI passthrough server (no stored credentials — see cli-mcp/README.md)
cd ../cli-mcp
python -m pip install -r requirements.txt
python prisma_sdwan_cli_mcp_server.py
License
MIT — see LICENSE.
Установка Prisma SD-WAN
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/iamdheerajdubey/prisma-sdwan-mcpFAQ
Prisma SD-WAN MCP бесплатный?
Да, Prisma SD-WAN MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Prisma SD-WAN?
Нет, Prisma SD-WAN работает без API-ключей и переменных окружения.
Prisma SD-WAN — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить Prisma SD-WAN в Claude Desktop, Claude Code или Cursor?
Открой Prisma SD-WAN на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
GitHub
PRs, issues, code search, CI status
автор: GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
автор: mcpdotdirectCompare Prisma SD-WAN with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории development
