Sophos XGS MCP Server
A read-only MCP server that provides 60+ tools to query Sophos XGS firewall configurations via the XML API, covering firewall rules, NAT, VPN, web filtering, and more.
README
Sophos XGS MCP Server
A read-only Model Context Protocol (MCP) server for the Sophos XGS Firewall XML API. Gives AI assistants like Claude visibility into your firewall configuration without any ability to modify it.
Features
- 60+ read-only tools covering firewall rules, NAT, VPN, web filtering, network config, routing, DHCP, DNS, IPS, SSL/TLS inspection, and admin settings
- Read-only by design — only uses
<Get>API operations, no<Set>or<Remove> - XML injection protection — entity name validation and XML escaping on all inputs
- Credential isolation — credentials loaded from protected config files, never hardcoded
- Error sanitization — passwords are stripped from error messages before reaching the MCP client
- Scoped TLS handling — self-signed cert bypass is scoped per-request, not global
Tools
| Category | Tools |
|---|---|
| Firewall | list_firewall_rules, list_firewall_rule_groups, get_firewall_rule, search_firewall_rules |
| Network Objects | list_ip_hosts, list_ip_host_groups, list_fqdn_hosts, list_fqdn_host_groups, list_mac_hosts, get_ip_host, search_ip_hosts |
| Services | list_services, list_service_groups, get_service |
| Zones & Interfaces | list_zones, list_interfaces, list_vlans, list_interface_aliases, list_lag_interfaces, get_zone, get_interface |
| NAT | list_nat_rules |
| VPN | list_sslvpn_policies, list_vpn_ipsec_connections |
| Web Filtering | list_web_filter_policies, list_url_groups, list_web_filter_exceptions |
| SSL/TLS Inspection | list_ssl_tls_inspection_rules, get_ssl_tls_inspection_settings, list_decryption_profiles |
| IPS | list_ips_policies |
| Routing & SD-WAN | list_static_routes, list_sdwan_policy_routes, list_sdwan_profiles, list_gateway_hosts, list_gateway_configurations |
| DHCP & DNS | list_dhcp_servers, list_dns_forwarders, list_dns_request_routes, list_dns_host_entries |
| Users & Admin | list_users, list_admin_profiles, get_admin_settings, get_admin_authen, get_user_activity |
| System | get_backup_config, get_backup_restore_settings, get_time_settings, get_reports_retention, list_syslog_servers, list_notifications, list_snmpv3_users, get_pim_settings, get_captive_portal |
list_smtp_policies |
|
| Access Control | list_acl_rules, list_local_service_acl, list_schedules, list_access_time_policies, list_surfing_quota_policies, list_data_transfer_policies |
| IPv6 | list_router_advertisements |
| Advanced | raw_api_query — query any entity with optional filters |
Prerequisites
- Node.js 18+
- Sophos XGS Firewall with the XML API enabled (port 4444 by default)
- An API admin account (a read-only profile is strongly recommended)
Enabling the Sophos XML API
- Log into your Sophos XGS web admin
- Go to Backup & firmware > API
- Enable the API and allow access from the host running the MCP server
Setup
1. Install
git clone https://github.com/Leon69924/sophos-xgs-mcp.git
cd sophos-xgs-mcp
pnpm install
pnpm build
2. Configure credentials
Create the config directory:
mkdir -p ~/.config/sophos-xgs
chmod 700 ~/.config/sophos-xgs
Create ~/.config/sophos-xgs/config.json:
{
"host": "your-sophos-hostname-or-ip",
"port": "4444",
"username": "your-api-user"
}
Create ~/.config/sophos-xgs/credentials with just the password:
echo -n "your-password" > ~/.config/sophos-xgs/credentials
chmod 600 ~/.config/sophos-xgs/config.json ~/.config/sophos-xgs/credentials
Alternatively, use environment variables:
export SOPHOS_HOST=your-sophos-hostname-or-ip
export SOPHOS_PORT=4444
export SOPHOS_USERNAME=your-api-user
export SOPHOS_PASSWORD=your-password
3. Add to your MCP client
For Claude Code, add to ~/.mcp.json:
{
"mcpServers": {
"sophos-xgs": {
"type": "stdio",
"command": "node",
"args": ["/path/to/sophos-xgs-mcp/dist/index.js"]
}
}
}
Security
- Read-only — the server only uses
<Get>XML API operations - No hardcoded credentials — loaded from
~/.config/sophos-xgs/or environment variables - XML injection prevention — entity names are validated against
^[A-Za-z][A-Za-z0-9]*$, all interpolated values are XML-escaped - Error sanitization — credentials are stripped from error messages
- TLS — all connections use HTTPS; self-signed cert bypass is scoped to the Sophos connection only
- Best practice: Create a dedicated read-only admin profile on your Sophos for API access
License
AGPL-3.0-only — see LICENSE
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
Neon Database
MCP server for interacting with Neon Management API and databases
E2B
Using MCP to run code via e2b.
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.