# edgeconnect_set_zones

Replace EdgeConnect firewall zones with write guards.

Agent View of the PolicyLayer registry record for `edgeconnect_set_zones`. HTML page: https://policylayer.com/tools/hpe-networking-mcp/edgeconnect-set-zones

## Facts

- Tool: `edgeconnect_set_zones`
- Server: Hpe Networking (`secure-ssid/hpe-networking-mcp`) — https://policylayer.com/tools/hpe-networking-mcp.md
- Homepage: https://github.com/secure-ssid/hpe-networking-mcp
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "edgeconnect_set_zones",
    "arguments": {}
  }
}
```

## Why edgeconnect_set_zones is rated Medium

The tool modifies firewall zone configurations, which is a write operation. It carries high severity due to the blast radius—misconfigured firewall zones can disrupt network security and traffic flow, potentially affecting many devices. The 'write guards' mechanism suggests some safeguards are in place, preventing critical classification, but the impact on network security infrastructure justifies high severity.

From the tool's own definition: "'Replace EdgeConnect firewall zones with write guards' indicates modification of firewall configuration zones. 'Replace' and 'set' demonstrate reversible data modification rather than irreversible deletion."

## Use case

AI agents use edgeconnect_set_zones to create or update resources in Hpe Networking, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Hpe Networking environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Hpe Networking:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "edgeconnect_set_zones": {
      "limits": [
        {
          "counter": "edgeconnect_set_zones_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Hpe Networking (594)

- `aos8_execute_migration_rollback` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/aos8-execute-migration-rollback.md
- `aos8_logout` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/aos8-logout.md
- `apstra_delete_connectivity_template` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/apstra-delete-connectivity-template.md
- `clear_alerts` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/clear-alerts.md
- `clearpass_delete_endpoint` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/clearpass-delete-endpoint.md
- `clearpass_delete_guest` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/clearpass-delete-guest.md
- `delete_aaa_profile` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-aaa-profile.md
- `delete_auth_profile` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-auth-profile.md
- `delete_auth_server` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-auth-server.md
- `delete_authz_policy` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-authz-policy.md
- `delete_config_assignment` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-config-assignment.md
- `delete_device_groups` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-device-groups.md
- `delete_device_notes` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-device-notes.md
- `delete_glp_role_assignment` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-glp-role-assignment.md
- `delete_glp_scope_group` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-glp-scope-group.md
- `delete_glp_scope_group_scopes` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-glp-scope-group-scopes.md
- `delete_gw_policy` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-gw-policy.md
- `delete_mac_registration` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-mac-registration.md
- `delete_mpsk_registration` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-mpsk-registration.md
- `delete_network_profile` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-network-profile.md
- `delete_notification_rule` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-notification-rule.md
- `delete_overlay_ssid` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-overlay-ssid.md
- `delete_report` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-report.md
- `delete_report_run` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-report-run.md
- `delete_role` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-role.md
- `delete_role_acl` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-role-acl.md
- `delete_server_group` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-server-group.md
- `delete_site_collections_bulk` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-site-collections-bulk.md
- `delete_sites_bulk` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-sites-bulk.md
- `delete_static_tag` — Destructive — https://policylayer.com/tools/hpe-networking-mcp/delete-static-tag.md
- …and 564 more: https://policylayer.com/tools/hpe-networking-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=hpe-networking-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/hpe-networking-mcp
