
MikroTik
STDIOBridge for AI assistants to interact with MikroTik RouterOS through natural language commands.
Bridge for AI assistants to interact with MikroTik RouterOS through natural language commands.
MikroTik MCP provides a bridge between AI assistants and MikroTik RouterOS devices. It allows AI assistants to interact with MikroTik routers through natural language requests, executing commands like managing VLANs, configuring firewall rules, handling DNS settings, and more.
https://github.com/user-attachments/assets/24fadcdc-c6a8-48ed-90ac-74baf8f94b59
https://github.com/user-attachments/assets/e0301ff2-8144-4503-83d0-48589d95027d
# Clone the repository git clone https://github.com/jeff-nasseri/mikrotik-mcp/tree/master cd mcp-mikrotik # Create virtual environment python -m venv .venv source .venv/bin/activate # On Windows: .venv\Scripts\activate # Install dependencies pip install -e . # Run the server mcp-server-mikrotik
Here are the available tools in the MikroTik MCP server:
mikrotik_create_vlan_interface
Creates a VLAN interface on MikroTik device.
name
(required): VLAN interface namevlan_id
(required): VLAN ID (1-4094)interface
(required): Parent interfacecomment
(optional): Descriptiondisabled
(optional): Disable interfacemtu
(optional): MTU sizeuse_service_tag
(optional): Use service tagarp
(optional): ARP modearp_timeout
(optional): ARP timeoutmikrotik_create_vlan_interface(name="vlan100", vlan_id=100, interface="ether1")
mikrotik_list_vlan_interfaces
Lists VLAN interfaces on MikroTik device.
name_filter
(optional): Filter by namevlan_id_filter
(optional): Filter by VLAN IDinterface_filter
(optional): Filter by parent interfacedisabled_only
(optional): Show only disabled interfacesmikrotik_list_vlan_interfaces(vlan_id_filter=100)
mikrotik_get_vlan_interface
Gets detailed information about a specific VLAN interface.
name
(required): VLAN interface namemikrotik_get_vlan_interface(name="vlan100")
mikrotik_update_vlan_interface
Updates an existing VLAN interface.
name
(required): Current VLAN interface namenew_name
(optional): New namevlan_id
(optional): New VLAN IDinterface
(optional): New parent interfacecomment
(optional): New descriptiondisabled
(optional): Enable/disable interfacemtu
(optional): New MTU sizeuse_service_tag
(optional): Use service tagarp
(optional): ARP modearp_timeout
(optional): ARP timeoutmikrotik_update_vlan_interface(name="vlan100", comment="Production VLAN")
mikrotik_remove_vlan_interface
Removes a VLAN interface from MikroTik device.
name
(required): VLAN interface namemikrotik_remove_vlan_interface(name="vlan100")
mikrotik_add_ip_address
Adds an IP address to an interface.
address
(required): IP address with CIDR notationinterface
(required): Interface namenetwork
(optional): Network addressbroadcast
(optional): Broadcast addresscomment
(optional): Descriptiondisabled
(optional): Disable addressmikrotik_add_ip_address(address="192.168.1.1/24", interface="vlan100")
mikrotik_list_ip_addresses
Lists IP addresses on MikroTik device.
interface_filter
(optional): Filter by interfaceaddress_filter
(optional): Filter by addressnetwork_filter
(optional): Filter by networkdisabled_only
(optional): Show only disabled addressesdynamic_only
(optional): Show only dynamic addressesmikrotik_list_ip_addresses(interface_filter="vlan100")
mikrotik_get_ip_address
Gets detailed information about a specific IP address.
address_id
(required): Address IDmikrotik_get_ip_address(address_id="*1")
mikrotik_remove_ip_address
Removes an IP address from MikroTik device.
address_id
(required): Address IDmikrotik_remove_ip_address(address_id="*1")
mikrotik_create_dhcp_server
Creates a DHCP server on MikroTik device.
name
(required): DHCP server nameinterface
(required): Interface to bind tolease_time
(optional): Lease time (default: "1d")address_pool
(optional): IP pool namedisabled
(optional): Disable serverauthoritative
(optional): Authoritative modedelay_threshold
(optional): Delay thresholdcomment
(optional): Descriptionmikrotik_create_dhcp_server(name="dhcp-vlan100", interface="vlan100", address_pool="pool-vlan100")
mikrotik_list_dhcp_servers
Lists DHCP servers on MikroTik device.
name_filter
(optional): Filter by nameinterface_filter
(optional): Filter by interfacedisabled_only
(optional): Show only disabled serversinvalid_only
(optional): Show only invalid serversmikrotik_list_dhcp_servers()
mikrotik_get_dhcp_server
Gets detailed information about a specific DHCP server.
name
(required): DHCP server namemikrotik_get_dhcp_server(name="dhcp-vlan100")
mikrotik_create_dhcp_network
Creates a DHCP network configuration.
network
(required): Network addressgateway
(required): Gateway addressnetmask
(optional): Network maskdns_servers
(optional): DNS server listdomain
(optional): Domain namewins_servers
(optional): WINS server listntp_servers
(optional): NTP server listdhcp_option
(optional): DHCP optionscomment
(optional): Descriptionmikrotik_create_dhcp_network(network="192.168.1.0/24", gateway="192.168.1.1", dns_servers=["8.8.8.8", "8.8.4.4"])
mikrotik_create_dhcp_pool
Creates a DHCP address pool.
name
(required): Pool nameranges
(required): IP rangesnext_pool
(optional): Next pool namecomment
(optional): Descriptionmikrotik_create_dhcp_pool(name="pool-vlan100", ranges="192.168.1.10-192.168.1.250")
mikrotik_remove_dhcp_server
Removes a DHCP server from MikroTik device.
name
(required): DHCP server namemikrotik_remove_dhcp_server(name="dhcp-vlan100")
mikrotik_create_nat_rule
Creates a NAT rule on MikroTik device.
chain
(required): Chain type ("srcnat" or "dstnat")action
(required): Action typesrc_address
(optional): Source addressdst_address
(optional): Destination addresssrc_port
(optional): Source portdst_port
(optional): Destination portprotocol
(optional): Protocolin_interface
(optional): Input interfaceout_interface
(optional): Output interfaceto_addresses
(optional): Translation addressesto_ports
(optional): Translation portscomment
(optional): Descriptiondisabled
(optional): Disable rulelog
(optional): Enable logginglog_prefix
(optional): Log prefixplace_before
(optional): Rule placementmikrotik_create_nat_rule(chain="srcnat", action="masquerade", out_interface="ether1")
mikrotik_list_nat_rules
Lists NAT rules on MikroTik device.
chain_filter
(optional): Filter by chainaction_filter
(optional): Filter by actionsrc_address_filter
(optional): Filter by source addressdst_address_filter
(optional): Filter by destination addressprotocol_filter
(optional): Filter by protocolinterface_filter
(optional): Filter by interfacedisabled_only
(optional): Show only disabled rulesinvalid_only
(optional): Show only invalid rulesmikrotik_list_nat_rules(chain_filter="srcnat")
mikrotik_get_nat_rule
Gets detailed information about a specific NAT rule.
rule_id
(required): Rule IDmikrotik_get_nat_rule(rule_id="*1")
mikrotik_update_nat_rule
Updates an existing NAT rule.
rule_id
(required): Rule IDcreate_nat_rule
(optional)mikrotik_update_nat_rule(rule_id="*1", comment="Updated NAT rule")
mikrotik_remove_nat_rule
Removes a NAT rule from MikroTik device.
rule_id
(required): Rule IDmikrotik_remove_nat_rule(rule_id="*1")
mikrotik_move_nat_rule
Moves a NAT rule to a different position.
rule_id
(required): Rule IDdestination
(required): New positionmikrotik_move_nat_rule(rule_id="*1", destination=0)
mikrotik_enable_nat_rule
Enables a NAT rule.
rule_id
(required): Rule IDmikrotik_enable_nat_rule(rule_id="*1")
mikrotik_disable_nat_rule
Disables a NAT rule.
rule_id
(required): Rule IDmikrotik_disable_nat_rule(rule_id="*1")
mikrotik_create_ip_pool
Creates an IP pool on MikroTik device.
name
(required): Pool nameranges
(required): IP rangesnext_pool
(optional): Next pool namecomment
(optional): Descriptionmikrotik_create_ip_pool(name="pool1", ranges="192.168.1.100-192.168.1.200")
mikrotik_list_ip_pools
Lists IP pools on MikroTik device.
name_filter
(optional): Filter by nameranges_filter
(optional): Filter by rangesinclude_used
(optional): Include used addressesmikrotik_list_ip_pools()
mikrotik_get_ip_pool
Gets detailed information about a specific IP pool.
name
(required): Pool namemikrotik_get_ip_pool(name="pool1")
mikrotik_update_ip_pool
Updates an existing IP pool.
name
(required): Current pool namenew_name
(optional): New nameranges
(optional): New rangesnext_pool
(optional): New next poolcomment
(optional): New descriptionmikrotik_update_ip_pool(name="pool1", ranges="192.168.1.100-192.168.1.250")
mikrotik_remove_ip_pool
Removes an IP pool from MikroTik device.
name
(required): Pool namemikrotik_remove_ip_pool(name="pool1")
mikrotik_list_ip_pool_used
Lists used addresses from IP pools.
pool_name
(optional): Filter by pool nameaddress_filter
(optional): Filter by addressmac_filter
(optional): Filter by MAC addressinfo_filter
(optional): Filter by infomikrotik_list_ip_pool_used(pool_name="pool1")
mikrotik_expand_ip_pool
Expands an existing IP pool by adding more ranges.
name
(required): Pool nameadditional_ranges
(required): Additional IP rangesmikrotik_expand_ip_pool(name="pool1", additional_ranges="192.168.1.251-192.168.1.254")
mikrotik_create_backup
Creates a system backup on MikroTik device.
name
(optional): Backup filenamedont_encrypt
(optional): Don't encrypt backupinclude_password
(optional): Include passwordscomment
(optional): Descriptionmikrotik_create_backup(name="backup-2024-01-01")
mikrotik_list_backups
Lists backup files on MikroTik device.
name_filter
(optional): Filter by nameinclude_exports
(optional): Include export filesmikrotik_list_backups()
mikrotik_create_export
Creates a configuration export on MikroTik device.
name
(optional): Export filenamefile_format
(optional): Format ("rsc", "json", "xml")export_type
(optional): Type ("full", "compact", "verbose")hide_sensitive
(optional): Hide sensitive dataverbose
(optional): Verbose outputcompact
(optional): Compact outputcomment
(optional): Descriptionmikrotik_create_export(name="config-export", file_format="rsc")
mikrotik_export_section
Exports a specific configuration section.
section
(required): Section to exportname
(optional): Export filenamehide_sensitive
(optional): Hide sensitive datacompact
(optional): Compact outputmikrotik_export_section(section="/ip/firewall", name="firewall-config")
mikrotik_download_file
Downloads a file from MikroTik device.
filename
(required): Filename to downloadfile_type
(optional): File type ("backup" or "export")mikrotik_download_file(filename="backup-2024-01-01.backup")
mikrotik_upload_file
Uploads a file to MikroTik device.
filename
(required): Filenamecontent_base64
(required): Base64 encoded contentmikrotik_upload_file(filename="config.rsc", content_base64="...")
mikrotik_restore_backup
Restores a system backup on MikroTik device.
filename
(required): Backup filenamepassword
(optional): Backup passwordmikrotik_restore_backup(filename="backup-2024-01-01.backup")
mikrotik_import_configuration
Imports a configuration script file.
filename
(required): Script filenamerun_after_reset
(optional): Run after resetverbose
(optional): Verbose outputmikrotik_import_configuration(filename="config.rsc")
mikrotik_remove_file
Removes a file from MikroTik device.
filename
(required): Filename to removemikrotik_remove_file(filename="old-backup.backup")
mikrotik_backup_info
Gets detailed information about a backup file.
filename
(required): Backup filenamemikrotik_backup_info(filename="backup-2024-01-01.backup")
mikrotik_get_logs
Gets logs from MikroTik device with filtering options.
topics
(optional): Log topicsaction
(optional): Log actiontime_filter
(optional): Time filtermessage_filter
(optional): Message filterprefix_filter
(optional): Prefix filterlimit
(optional): Result limitfollow
(optional): Follow logsprint_as
(optional): Output formatmikrotik_get_logs(topics="firewall", limit=100)
mikrotik_get_logs_by_severity
Gets logs filtered by severity level.
severity
(required): Severity level ("debug", "info", "warning", "error", "critical")time_filter
(optional): Time filterlimit
(optional): Result limitmikrotik_get_logs_by_severity(severity="error", limit=50)
mikrotik_get_logs_by_topic
Gets logs for a specific topic/facility.
topic
(required): Log topictime_filter
(optional): Time filterlimit
(optional): Result limitmikrotik_get_logs_by_topic(topic="system")
mikrotik_search_logs
Searches logs for a specific term.
search_term
(required): Search termtime_filter
(optional): Time filtercase_sensitive
(optional): Case sensitive searchlimit
(optional): Result limitmikrotik_search_logs(search_term="login failed")
mikrotik_get_system_events
Gets system-related log events.
event_type
(optional): Event typetime_filter
(optional): Time filterlimit
(optional): Result limitmikrotik_get_system_events(event_type="reboot")
mikrotik_get_security_logs
Gets security-related log entries.
time_filter
(optional): Time filterlimit
(optional): Result limitmikrotik_get_security_logs(limit=100)
mikrotik_clear_logs
Clears all logs from MikroTik device.
mikrotik_clear_logs()
mikrotik_get_log_statistics
Gets statistics about log entries.
mikrotik_get_log_statistics()
mikrotik_export_logs
Exports logs to a file on the MikroTik device.
filename
(optional): Export filenametopics
(optional): Log topicstime_filter
(optional): Time filterformat
(optional): Export format ("plain" or "csv")mikrotik_export_logs(filename="security-logs.txt", topics="firewall")
mikrotik_monitor_logs
Monitors logs in real-time for a specified duration.
topics
(optional): Log topicsaction
(optional): Log actionduration
(optional): Monitor duration in secondsmikrotik_monitor_logs(topics="firewall", duration=30)
mikrotik_create_filter_rule
Creates a firewall filter rule on MikroTik device.
chain
(required): Chain type ("input", "forward", "output")action
(required): Action typesrc_address
(optional): Source addressdst_address
(optional): Destination addresssrc_port
(optional): Source portdst_port
(optional): Destination portprotocol
(optional): Protocolin_interface
(optional): Input interfaceout_interface
(optional): Output interfaceconnection_state
(optional): Connection stateconnection_nat_state
(optional): Connection NAT statesrc_address_list
(optional): Source address listdst_address_list
(optional): Destination address listlimit
(optional): Rate limittcp_flags
(optional): TCP flagscomment
(optional): Descriptiondisabled
(optional): Disable rulelog
(optional): Enable logginglog_prefix
(optional): Log prefixplace_before
(optional): Rule placementmikrotik_create_filter_rule(chain="input", action="accept", protocol="tcp", dst_port="22", src_address="192.168.1.0/24")
mikrotik_list_filter_rules
Lists firewall filter rules on MikroTik device.
chain_filter
(optional): Filter by chainaction_filter
(optional): Filter by actionsrc_address_filter
(optional): Filter by source addressdst_address_filter
(optional): Filter by destination addressprotocol_filter
(optional): Filter by protocolinterface_filter
(optional): Filter by interfacedisabled_only
(optional): Show only disabled rulesinvalid_only
(optional): Show only invalid rulesdynamic_only
(optional): Show only dynamic rulesmikrotik_list_filter_rules(chain_filter="input")
mikrotik_get_filter_rule
Gets detailed information about a specific firewall filter rule.
rule_id
(required): Rule IDmikrotik_get_filter_rule(rule_id="*1")
mikrotik_update_filter_rule
Updates an existing firewall filter rule.
rule_id
(required): Rule IDcreate_filter_rule
(optional)mikrotik_update_filter_rule(rule_id="*1", comment="Updated rule")
mikrotik_remove_filter_rule
Removes a firewall filter rule from MikroTik device.
rule_id
(required): Rule IDmikrotik_remove_filter_rule(rule_id="*1")
mikrotik_move_filter_rule
Moves a firewall filter rule to a different position.
rule_id
(required): Rule IDdestination
(required): New positionmikrotik_move_filter_rule(rule_id="*1", destination=0)
mikrotik_enable_filter_rule
Enables a firewall filter rule.
rule_id
(required): Rule IDmikrotik_enable_filter_rule(rule_id="*1")
mikrotik_disable_filter_rule
Disables a firewall filter rule.
rule_id
(required): Rule IDmikrotik_disable_filter_rule(rule_id="*1")
mikrotik_create_basic_firewall_setup
Creates a basic firewall setup with common security rules.
mikrotik_create_basic_firewall_setup()
mikrotik_add_route
Adds a route to MikroTik routing table.
dst_address
(required): Destination addressgateway
(required): Gateway addressdistance
(optional): Administrative distancescope
(optional): Route scopetarget_scope
(optional): Target scoperouting_mark
(optional): Routing markcomment
(optional): Descriptiondisabled
(optional): Disable routevrf_interface
(optional): VRF interfacepref_src
(optional): Preferred sourcecheck_gateway
(optional): Gateway check methodmikrotik_add_route(dst_address="10.0.0.0/8", gateway="192.168.1.1")
mikrotik_list_routes
Lists routes in MikroTik routing table.
dst_filter
(optional): Filter by destinationgateway_filter
(optional): Filter by gatewayrouting_mark_filter
(optional): Filter by routing markdistance_filter
(optional): Filter by distanceactive_only
(optional): Show only active routesdisabled_only
(optional): Show only disabled routesdynamic_only
(optional): Show only dynamic routesstatic_only
(optional): Show only static routesmikrotik_list_routes(active_only=true)
mikrotik_get_route
Gets detailed information about a specific route.
route_id
(required): Route IDmikrotik_get_route(route_id="*1")
mikrotik_update_route
Updates an existing route in MikroTik routing table.
route_id
(required): Route IDadd_route
(optional)mikrotik_update_route(route_id="*1", comment="Updated route")
mikrotik_remove_route
Removes a route from MikroTik routing table.
route_id
(required): Route IDmikrotik_remove_route(route_id="*1")
mikrotik_enable_route
Enables a route.
route_id
(required): Route IDmikrotik_enable_route(route_id="*1")
mikrotik_disable_route
Disables a route.
route_id
(required): Route IDmikrotik_disable_route(route_id="*1")
mikrotik_get_routing_table
Gets a specific routing table.
table_name
(optional): Table name (default: "main")protocol_filter
(optional): Filter by protocolactive_only
(optional): Show only active routesmikrotik_get_routing_table(table_name="main")
mikrotik_check_route_path
Checks the route path to a destination.
destination
(required): Destination addresssource
(optional): Source addressrouting_mark
(optional): Routing markmikrotik_check_route_path(destination="8.8.8.8")
mikrotik_get_route_cache
Gets the route cache.
mikrotik_get_route_cache()
mikrotik_flush_route_cache
Flushes the route cache.
mikrotik_flush_route_cache()
mikrotik_add_default_route
Adds a default route (0.0.0.0/0).
gateway
(required): Gateway addressdistance
(optional): Administrative distancecomment
(optional): Descriptioncheck_gateway
(optional): Gateway check methodmikrotik_add_default_route(gateway="192.168.1.1")
mikrotik_add_blackhole_route
Adds a blackhole route.
dst_address
(required): Destination addressdistance
(optional): Administrative distancecomment
(optional): Descriptionmikrotik_add_blackhole_route(dst_address="10.0.0.0/8")
mikrotik_get_route_statistics
Gets routing table statistics.
mikrotik_get_route_statistics()
mikrotik_set_dns_servers
Sets DNS server configuration on MikroTik device.
servers
(required): DNS server listallow_remote_requests
(optional): Allow remote requestsmax_udp_packet_size
(optional): Max UDP packet sizemax_concurrent_queries
(optional): Max concurrent queriescache_size
(optional): Cache sizecache_max_ttl
(optional): Max cache TTLuse_doh
(optional): Use DNS over HTTPSdoh_server
(optional): DoH server URLverify_doh_cert
(optional): Verify DoH certificatemikrotik_set_dns_servers(servers=["8.8.8.8", "8.8.4.4"], allow_remote_requests=true)
mikrotik_get_dns_settings
Gets current DNS configuration.
mikrotik_get_dns_settings()
mikrotik_add_dns_static
Adds a static DNS entry.
name
(required): DNS nameaddress
(optional): IP addresscname
(optional): CNAME recordmx_preference
(optional): MX preferencemx_exchange
(optional): MX exchangetext
(optional): TXT recordsrv_priority
(optional): SRV prioritysrv_weight
(optional): SRV weightsrv_port
(optional): SRV portsrv_target
(optional): SRV targetttl
(optional): Time to livecomment
(optional): Descriptiondisabled
(optional): Disable entryregexp
(optional): Regular expressionmikrotik_add_dns_static(name="router.local", address="192.168.1.1")
mikrotik_list_dns_static
Lists static DNS entries.
name_filter
(optional): Filter by nameaddress_filter
(optional): Filter by addresstype_filter
(optional): Filter by typedisabled_only
(optional): Show only disabled entriesregexp_only
(optional): Show only regexp entriesmikrotik_list_dns_static()
mikrotik_get_dns_static
Gets details of a specific static DNS entry.
entry_id
(required): Entry IDmikrotik_get_dns_static(entry_id="*1")
mikrotik_update_dns_static
Updates an existing static DNS entry.
entry_id
(required): Entry IDadd_dns_static
(optional)mikrotik_update_dns_static(entry_id="*1", address="192.168.1.2")
mikrotik_remove_dns_static
Removes a static DNS entry.
entry_id
(required): Entry IDmikrotik_remove_dns_static(entry_id="*1")
mikrotik_enable_dns_static
Enables a static DNS entry.
entry_id
(required): Entry IDmikrotik_enable_dns_static(entry_id="*1")
mikrotik_disable_dns_static
Disables a static DNS entry.
entry_id
(required): Entry IDmikrotik_disable_dns_static(entry_id="*1")
mikrotik_get_dns_cache
Gets the current DNS cache.
mikrotik_get_dns_cache()
mikrotik_flush_dns_cache
Flushes the DNS cache.
mikrotik_flush_dns_cache()
mikrotik_get_dns_cache_statistics
Gets DNS cache statistics.
mikrotik_get_dns_cache_statistics()
mikrotik_add_dns_regexp
Adds a DNS regexp entry for pattern matching.
regexp
(required): Regular expressionaddress
(required): IP addressttl
(optional): Time to livecomment
(optional): Descriptiondisabled
(optional): Disable entrymikrotik_add_dns_regexp(regexp="^ad[0-9]*\\.doubleclick\\.net$", address="127.0.0.1")
mikrotik_test_dns_query
Tests a DNS query.
name
(required): DNS name to queryserver
(optional): DNS server to usetype
(optional): Query typemikrotik_test_dns_query(name="google.com")
mikrotik_export_dns_config
Exports DNS configuration to a file.
filename
(optional): Export filenamemikrotik_export_dns_config(filename="dns-config.rsc")
mikrotik_add_user
Adds a new user to MikroTik device.
name
(required): Usernamepassword
(required): Passwordgroup
(optional): User groupaddress
(optional): Allowed addresscomment
(optional): Descriptiondisabled
(optional): Disable usermikrotik_add_user(name="john", password="secure123", group="full")
mikrotik_list_users
Lists users on MikroTik device.
name_filter
(optional): Filter by namegroup_filter
(optional): Filter by groupdisabled_only
(optional): Show only disabled usersactive_only
(optional): Show only active usersmikrotik_list_users(group_filter="full")
mikrotik_get_user
Gets detailed information about a specific user.
name
(required): Usernamemikrotik_get_user(name="john")
mikrotik_update_user
Updates an existing user on MikroTik device.
name
(required): Current usernamenew_name
(optional): New usernamepassword
(optional): New passwordgroup
(optional): New groupaddress
(optional): New allowed addresscomment
(optional): New descriptiondisabled
(optional): Enable/disable usermikrotik_update_user(name="john", group="read")
mikrotik_remove_user
Removes a user from MikroTik device.
name
(required): Usernamemikrotik_remove_user(name="john")
mikrotik_disable_user
Disables a user account.
name
(required): Usernamemikrotik_disable_user(name="john")
mikrotik_enable_user
Enables a user account.
name
(required): Usernamemikrotik_enable_user(name="john")
mikrotik_add_user_group
Adds a new user group to MikroTik device.
name
(required): Group namepolicy
(required): Policy listskin
(optional): UI skincomment
(optional): Descriptionmikrotik_add_user_group(name="operators", policy=["read", "write", "reboot"])
mikrotik_list_user_groups
Lists user groups on MikroTik device.
name_filter
(optional): Filter by namepolicy_filter
(optional): Filter by policymikrotik_list_user_groups()
mikrotik_get_user_group
Gets detailed information about a specific user group.
name
(required): Group namemikrotik_get_user_group(name="operators")
mikrotik_update_user_group
Updates an existing user group on MikroTik device.
name
(required): Current group namenew_name
(optional): New namepolicy
(optional): New policy listskin
(optional): New UI skincomment
(optional): New descriptionmikrotik_update_user_group(name="operators", policy=["read", "write"])
mikrotik_remove_user_group
Removes a user group from MikroTik device.
name
(required): Group namemikrotik_remove_user_group(name="operators")
mikrotik_get_active_users
Gets currently active/logged-in users.
mikrotik_get_active_users()
mikrotik_disconnect_user
Disconnects an active user session.
user_id
(required): User session IDmikrotik_disconnect_user(user_id="*1")
mikrotik_export_user_config
Exports user configuration to a file.
filename
(optional): Export filenamemikrotik_export_user_config(filename="users.rsc")
mikrotik_set_user_ssh_keys
Sets SSH public keys for a user.
username
(required): Usernamekey_file
(required): SSH key filenamemikrotik_set_user_ssh_keys(username="john", key_file="id_rsa.pub")
mikrotik_list_user_ssh_keys
Lists SSH keys for a specific user.
username
(required): Usernamemikrotik_list_user_ssh_keys(username="john")
mikrotik_remove_user_ssh_key
Removes an SSH key.
key_id
(required): SSH key IDmikrotik_remove_user_ssh_key(key_id="*1")
Add this to your claude_desktop_config.json
:
{ "mcpServers": { "mikrotik": { "command": "uvx", "args": ["mcp-server-mikrotik", "--host", "<HOST>", "--username", "<USERNAME>", "--password", "<PASSWORD>", "--port", "22"] } } }
# Run the inspector against the mcp-server-mikrotik npx @modelcontextprotocol/inspector uvx mcp-server-mikrotik --host <HOST> --username <USERNAME> --password <PASSWORD> --port 22
Here's the new markdown content that you should add after the Inspector section and before the License section:
# Create a VLAN interface uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_vlan_interface --tool-args '{"name": "vlan100", "vlan_id": 100, "interface": "ether1", "comment": "Production VLAN"}' # List all VLANs uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_vlan_interfaces --tool-args '{}' # Get specific VLAN details uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_vlan_interface --tool-args '{"name": "vlan100"}' # Update VLAN interface uv run mcp-cli cmd --server mikrotik --tool mikrotik_update_vlan_interface --tool-args '{"name": "vlan100", "comment": "Updated Production VLAN"}' # Remove VLAN interface uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_vlan_interface --tool-args '{"name": "vlan100"}'
# Add IP address to interface uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_ip_address --tool-args '{"address": "192.168.100.1/24", "interface": "vlan100", "comment": "Gateway address"}' # List IP addresses uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_ip_addresses --tool-args '{"interface_filter": "vlan100"}' # Get specific IP address uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_ip_address --tool-args '{"address_id": "*1"}' # Remove IP address uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_ip_address --tool-args '{"address_id": "*1"}'
# Create DHCP pool uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_dhcp_pool --tool-args '{"name": "pool-vlan100", "ranges": "192.168.100.10-192.168.100.200"}' # Create DHCP network uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_dhcp_network --tool-args '{"network": "192.168.100.0/24", "gateway": "192.168.100.1", "dns_servers": ["8.8.8.8", "8.8.4.4"]}' # Create DHCP server uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_dhcp_server --tool-args '{"name": "dhcp-vlan100", "interface": "vlan100", "address_pool": "pool-vlan100"}' # List DHCP servers uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_dhcp_servers --tool-args '{}' # Get DHCP server details uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_dhcp_server --tool-args '{"name": "dhcp-vlan100"}' # Remove DHCP server uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_dhcp_server --tool-args '{"name": "dhcp-vlan100"}'
# Create masquerade rule uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_nat_rule --tool-args '{"chain": "srcnat", "action": "masquerade", "out_interface": "ether1", "comment": "Internet access"}' # Create port forwarding rule uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_nat_rule --tool-args '{"chain": "dstnat", "action": "dst-nat", "dst_port": "80", "protocol": "tcp", "to_addresses": "192.168.100.10", "to_ports": "80", "comment": "Web server"}' # List NAT rules uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_nat_rules --tool-args '{"chain_filter": "srcnat"}' # Get NAT rule details uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_nat_rule --tool-args '{"rule_id": "*1"}' # Move NAT rule uv run mcp-cli cmd --server mikrotik --tool mikrotik_move_nat_rule --tool-args '{"rule_id": "*1", "destination": 0}' # Enable/Disable NAT rule uv run mcp-cli cmd --server mikrotik --tool mikrotik_disable_nat_rule --tool-args '{"rule_id": "*1"}' uv run mcp-cli cmd --server mikrotik --tool mikrotik_enable_nat_rule --tool-args '{"rule_id": "*1"}' # Remove NAT rule uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_nat_rule --tool-args '{"rule_id": "*1"}'
# Create IP pool uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_ip_pool --tool-args '{"name": "main-pool", "ranges": "192.168.1.100-192.168.1.200"}' # List IP pools uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_ip_pools --tool-args '{"include_used": true}' # Get IP pool details uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_ip_pool --tool-args '{"name": "main-pool"}' # List used addresses in pool uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_ip_pool_used --tool-args '{"pool_name": "main-pool"}' # Expand IP pool uv run mcp-cli cmd --server mikrotik --tool mikrotik_expand_ip_pool --tool-args '{"name": "main-pool", "additional_ranges": "192.168.1.201-192.168.1.250"}' # Remove IP pool uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_ip_pool --tool-args '{"name": "main-pool"}'
# Create system backup uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_backup --tool-args '{"name": "full_backup", "include_password": true}' # Create configuration export uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_export --tool-args '{"name": "config_export", "file_format": "rsc", "export_type": "full"}' # Export specific section uv run mcp-cli cmd --server mikrotik --tool mikrotik_export_section --tool-args '{"section": "/ip/firewall", "name": "firewall_export"}' # List backups uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_backups --tool-args '{"include_exports": true}' # Download file uv run mcp-cli cmd --server mikrotik --tool mikrotik_download_file --tool-args '{"filename": "full_backup.backup"}' # Upload file uv run mcp-cli cmd --server mikrotik --tool mikrotik_upload_file --tool-args '{"filename": "config.rsc", "content_base64": "base64_encoded_content"}' # Restore backup uv run mcp-cli cmd --server mikrotik --tool mikrotik_restore_backup --tool-args '{"filename": "full_backup.backup"}' # Import configuration uv run mcp-cli cmd --server mikrotik --tool mikrotik_import_configuration --tool-args '{"filename": "config.rsc"}' # Remove file uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_file --tool-args '{"filename": "old_backup.backup"}'
# Get logs uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_logs --tool-args '{"topics": "firewall", "limit": 100}' # Get logs by severity uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_logs_by_severity --tool-args '{"severity": "error", "limit": 50}' # Search logs uv run mcp-cli cmd --server mikrotik --tool mikrotik_search_logs --tool-args '{"search_term": "login failed", "case_sensitive": false}' # Get security logs uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_security_logs --tool-args '{"limit": 100}' # Get log statistics uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_log_statistics --tool-args '{}' # Export logs uv run mcp-cli cmd --server mikrotik --tool mikrotik_export_logs --tool-args '{"filename": "firewall_logs", "topics": "firewall", "format": "csv"}' # Monitor logs uv run mcp-cli cmd --server mikrotik --tool mikrotik_monitor_logs --tool-args '{"topics": "firewall", "duration": 30}' # Clear logs uv run mcp-cli cmd --server mikrotik --tool mikrotik_clear_logs --tool-args '{}'
# Create basic firewall rules uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_filter_rule --tool-args '{"chain": "input", "action": "accept", "connection_state": "established,related", "comment": "Accept established"}' uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_filter_rule --tool-args '{"chain": "input", "action": "drop", "connection_state": "invalid", "comment": "Drop invalid"}' uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_filter_rule --tool-args '{"chain": "input", "action": "accept", "protocol": "icmp", "comment": "Accept ICMP"}' # List firewall rules uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_filter_rules --tool-args '{"chain_filter": "input"}' # Get firewall rule details uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_filter_rule --tool-args '{"rule_id": "*1"}' # Move firewall rule uv run mcp-cli cmd --server mikrotik --tool mikrotik_move_filter_rule --tool-args '{"rule_id": "*1", "destination": 0}' # Enable/Disable firewall rule uv run mcp-cli cmd --server mikrotik --tool mikrotik_disable_filter_rule --tool-args '{"rule_id": "*1"}' uv run mcp-cli cmd --server mikrotik --tool mikrotik_enable_filter_rule --tool-args '{"rule_id": "*1"}' # Create basic firewall setup uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_basic_firewall_setup --tool-args '{}' # Remove firewall rule uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_filter_rule --tool-args '{"rule_id": "*1"}'
# Add route uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_route --tool-args '{"dst_address": "10.0.0.0/8", "gateway": "192.168.1.1", "comment": "Corporate network"}' # Add default route uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_default_route --tool-args '{"gateway": "192.168.1.1", "distance": 1}' # Add blackhole route uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_blackhole_route --tool-args '{"dst_address": "192.168.99.0/24", "comment": "Block subnet"}' # List routes uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_routes --tool-args '{"active_only": true}' # Get route details uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_route --tool-args '{"route_id": "*1"}' # Check route path uv run mcp-cli cmd --server mikrotik --tool mikrotik_check_route_path --tool-args '{"destination": "8.8.8.8"}' # Get routing table uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_routing_table --tool-args '{"table_name": "main"}' # Get route statistics uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_route_statistics --tool-args '{}' # Enable/Disable route uv run mcp-cli cmd --server mikrotik --tool mikrotik_disable_route --tool-args '{"route_id": "*1"}' uv run mcp-cli cmd --server mikrotik --tool mikrotik_enable_route --tool-args '{"route_id": "*1"}' # Remove route uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_route --tool-args '{"route_id": "*1"}'
# Set DNS servers uv run mcp-cli cmd --server mikrotik --tool mikrotik_set_dns_servers --tool-args '{"servers": ["8.8.8.8", "8.8.4.4"], "allow_remote_requests": true}' # Get DNS settings uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_dns_settings --tool-args '{}' # Add static DNS entry uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_dns_static --tool-args '{"name": "router.local", "address": "192.168.1.1", "comment": "Local router"}' # Add CNAME record uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_dns_static --tool-args '{"name": "www.example.com", "cname": "example.com"}' # List static DNS entries uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_dns_static --tool-args '{"name_filter": "local"}' # Update DNS entry uv run mcp-cli cmd --server mikrotik --tool mikrotik_update_dns_static --tool-args '{"entry_id": "*1", "address": "192.168.1.2"}' # Add DNS regexp uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_dns_regexp --tool-args '{"regexp": ".*\\.ads\\..*", "address": "0.0.0.0", "comment": "Block ads"}' # Test DNS query uv run mcp-cli cmd --server mikrotik --tool mikrotik_test_dns_query --tool-args '{"name": "google.com"}' # Get DNS cache uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_dns_cache --tool-args '{}' # Flush DNS cache uv run mcp-cli cmd --server mikrotik --tool mikrotik_flush_dns_cache --tool-args '{}' # Export DNS config uv run mcp-cli cmd --server mikrotik --tool mikrotik_export_dns_config --tool-args '{"filename": "dns_config"}' # Remove DNS entry uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_dns_static --tool-args '{"entry_id": "*1"}'
# Add user uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_user --tool-args '{"name": "newuser", "password": "SecurePass123", "group": "write", "comment": "New operator"}' # List users uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_users --tool-args '{"group_filter": "write"}' # Get user details uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_user --tool-args '{"name": "newuser"}' # Update user uv run mcp-cli cmd --server mikrotik --tool mikrotik_update_user --tool-args '{"name": "newuser", "password": "NewSecurePass456"}' # Enable/Disable user uv run mcp-cli cmd --server mikrotik --tool mikrotik_disable_user --tool-args '{"name": "newuser"}' uv run mcp-cli cmd --server mikrotik --tool mikrotik_enable_user --tool-args '{"name": "newuser"}' # Add user group uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_user_group --tool-args '{"name": "operators", "policy": ["read", "write", "test"], "comment": "Operator group"}' # List user groups uv run mcp-cli cmd --server mikrotik --tool mikrotik_list_user_groups --tool-args '{}' # Get active users uv run mcp-cli cmd --server mikrotik --tool mikrotik_get_active_users --tool-args '{}' # Export user config uv run mcp-cli cmd --server mikrotik --tool mikrotik_export_user_config --tool-args '{"filename": "user_config"}' # Remove user uv run mcp-cli cmd --server mikrotik --tool mikrotik_remove_user --tool-args '{"name": "newuser"}'
# Create VLAN uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_vlan_interface --tool-args '{"name": "vlan200", "vlan_id": 200, "interface": "ether1", "comment": "Guest Network"}' # Add IP address uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_ip_address --tool-args '{"address": "192.168.200.1/24", "interface": "vlan200"}' # Create DHCP pool uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_dhcp_pool --tool-args '{"name": "pool-200", "ranges": "192.168.200.10-192.168.200.100"}' # Create DHCP network uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_dhcp_network --tool-args '{"network": "192.168.200.0/24", "gateway": "192.168.200.1", "dns_servers": ["8.8.8.8", "8.8.4.4"]}' # Create DHCP server uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_dhcp_server --tool-args '{"name": "dhcp-200", "interface": "vlan200", "address_pool": "pool-200"}' # Create NAT rule uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_nat_rule --tool-args '{"chain": "srcnat", "action": "masquerade", "out_interface": "ether1", "comment": "Internet access for VLAN 200"}'
# Forward HTTP traffic uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_nat_rule --tool-args '{"chain": "dstnat", "action": "dst-nat", "dst_address": "203.0.113.1", "dst_port": "80", "protocol": "tcp", "to_addresses": "192.168.100.10", "to_ports": "80", "comment": "Web server"}' # Forward HTTPS traffic uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_nat_rule --tool-args '{"chain": "dstnat", "action": "dst-nat", "dst_address": "203.0.113.1", "dst_port": "443", "protocol": "tcp", "to_addresses": "192.168.100.10", "to_ports": "443", "comment": "HTTPS server"}' # Forward custom SSH port uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_nat_rule --tool-args '{"chain": "dstnat", "action": "dst-nat", "dst_address": "203.0.113.1", "dst_port": "2222", "protocol": "tcp", "to_addresses": "192.168.100.10", "to_ports": "22", "comment": "SSH server"}'
# Create backup user uv run mcp-cli cmd --server mikrotik --tool mikrotik_add_user --tool-args '{"name": "backup_user", "password": "BackupPass123", "group": "read", "comment": "Backup account"}' # Create full backup uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_backup --tool-args '{"name": "daily_backup", "include_password": true}' # Export configuration uv run mcp-cli cmd --server mikrotik --tool mikrotik_create_export --tool-args '{"name": "config_export", "file_format": "rsc", "export_type": "full"}' # Export firewall rules uv run mcp-cli cmd --server mikrotik --tool mikrotik_export_section --tool-args '{"section": "/ip/firewall/filter", "name": "firewall_backup"}' # Export NAT rules uv run mcp-cli cmd --server mikrotik --tool mikrotik_export_section --tool-args '{"section": "/ip/firewall/nat", "name": "nat_backup"}'
This MCP server is licensed under the MIT License. This means you are free to use, modify, and distribute the software, subject to the terms and conditions of the MIT License. For more details, please see the LICENSE file in the project repository.