FORTIMANAGER TOOLS

584 tools from the Fortimanager MCP Server, categorised by risk level.

READ 358 tools
Read analyze_policy_package_complexity analyze_policy_package_complexity Read check_adom_integrity check_adom_integrity Read check_device_connectivity check_device_connectivity Read download_firmware download_firmware Read fetch_nested_configuration fetch_nested_configuration Read fetch_object_members fetch_object_members Read fetch_sub_objects fetch_sub_objects Read find_fortimanager_tool Discover FortiManager tools by operation name/keywords. Read find_policy_by_name Find firewall policy by name instead of ID. Read fortimanager_help Get help on using FortiManager MCP tools in dynamic mode. Read get_active_user_sessions get_active_user_sessions Read get_address_where_used get_address_where_used Read get_admin_config Get administrative settings including session timeout and lockout policy. Read get_admin_user Get detailed information about a specific administrator user. Read get_administrator_activity Get administrator activity log for audit purposes. Read get_adom_checksum get_adom_checksum Read get_adom_details get_adom_details Read get_adom_device_summary Get summary statistics of all devices in an ADOM. Read get_adom_disk_usage Get disk usage statistics for ADOM data storage. Read get_adom_display_settings get_adom_display_settings Read get_adom_health Get health status of ADOM including all managed devices. Read get_adom_limits get_adom_limits Read get_adom_lock_status get_adom_lock_status Read get_adom_metadata_fields get_adom_metadata_fields Read get_adom_object_statistics get_adom_object_statistics Read get_adom_object_summary Get summary statistics of all objects in an ADOM. Read get_adom_object_usage get_adom_object_usage Read get_adom_policy_statistics Get comprehensive policy count statistics for an ADOM. Read get_adom_policy_summary Get summary statistics of all policies in an ADOM. Read get_adom_policy_sync_status get_adom_policy_sync_status Read get_adom_revision Get detailed information about a specific configuration revision. Read get_adom_revision_list get_adom_revision_list Read get_adom_statistics Get comprehensive statistics for an ADOM including devices, policies, and objects count. Read get_adom_where_used get_adom_where_used Read get_alert_console_config Get alert console configuration for system notifications. Read get_alert_history Get system alert history. Read get_antivirus_profile get_antivirus_profile Read get_api_user_info get_api_user_info Read get_auto_update_configuration Get automatic update status and schedule. Read get_available_package_versions get_available_package_versions Read get_available_timezones Get list of available timezones for device configuration. Read get_backup_settings get_backup_settings Read get_backup_status Get backup status and history. Read get_bandwidth_statistics Get bandwidth usage statistics for a specific device. Read get_central_dnat_policy Get central DNAT policy details. Read get_central_snat_policy Get central SNAT policy details. Read get_certificate_details get_certificate_details Read get_certificate_template get_certificate_template Read get_cli_script get_cli_script Read get_cli_script_history get_cli_script_history Read get_cli_script_log get_cli_script_log Read get_cli_template Get detailed information about a specific CLI template. Read get_cli_template_assigned_devices get_cli_template_assigned_devices Read get_cli_template_group Get detailed information about a specific CLI template group. Read get_cli_template_group_assigned_devices get_cli_template_group_assigned_devices Read get_cloud_account_info get_cloud_account_info Read get_cloud_connector_services get_cloud_connector_services Read get_cloud_service_status get_cloud_service_status Read get_cluster_members Get HA cluster member information. Read get_cluster_status Get HA cluster members status. Read get_configuration_changes Get recent configuration changes for audit trail. Read get_connector_route_table get_connector_route_table Read get_current_api_user get_current_api_user Read get_current_device_config Get current device database configuration. Read get_custom_application Get details of a custom application. Read get_database_cache_statistics Get database cache statistics and performance metrics. Read get_database_size Get database size statistics. Read get_default_port_config_all Get default port configuration for all FortiSwitch models. Read get_default_port_config_model get_default_port_config_model Read get_device_certificate_details get_device_certificate_details Read get_device_connectivity_status Get connectivity status for all managed devices in an ADOM. Read get_device_details get_device_details Read get_device_fortiguard_contracts get_device_fortiguard_contracts Read get_device_group Get device group details. Read get_device_group_members Get members of a device group. Read get_device_ha_configuration Get device HA (High Availability) status and configuration. Read get_device_install_history Get installation history for a specific device. Read get_device_interface_configuration Get list of device network interfaces. Read get_device_meta_fields get_device_meta_fields Read get_device_oid get_device_oid Read get_device_profile Get detailed information about a specific device profile. Read get_device_proxy_capabilities get_device_proxy_capabilities Read get_device_qos_statistics get_device_qos_statistics Read get_device_revision get_device_revision Read get_device_rma_status Get RMA status of a device. Read get_device_routing_configuration Get device routing table configuration. Read get_device_system_information Get detailed device system status. Read get_device_vpn_monitoring Get device VPN tunnel monitoring information. Read get_device_vulnerabilities get_device_vulnerabilities Read get_disk_usage get_disk_usage Read get_dlp_sensor get_dlp_sensor Read get_dns_filter_domain Get details of a DNS filter domain list. Read get_docker_container_status get_docker_container_status Read get_downloaded_fortiguard_objects Get list of FortiGuard objects downloaded by FortiManager. Read get_dynamic_interface Get detailed information about a specific dynamic interface. Read get_email_server_config Get email server configuration for system notifications. Read get_event_log Get system event log with optional severity filter (critical, warning, info). Read get_external_threat_feed Get details of a specific external threat feed. Read get_fabric_authorization_status get_fabric_authorization_status Read get_fabric_connector_devices get_fabric_connector_devices Read get_fabric_topology get_fabric_topology Read get_firewall_policy get_firewall_policy Read get_firewall_zone get_firewall_zone Read get_firmware_upgrade_preview get_firmware_upgrade_preview Read get_firmware_upgrade_report get_firmware_upgrade_report Read get_firmware_upgrade_status Get firmware upgrade status for a specific device. Read get_fmg_gui_settings Get GUI display settings and configuration. Read get_fmg_ha_cluster_status Get FortiManager HA cluster status. Read get_fmg_license Get FortiManager license and contract information. Read get_fmg_uptime Get FortiManager system uptime and boot time. Read get_fortiap_profile Get FortiAP profile details. Read get_fortiap_status get_fortiap_status Read get_forticare_registration Get FortiCare registration and support status. Read get_fortiextender_status get_fortiextender_status Read get_fortiguard_category_overrides get_fortiguard_category_overrides Read get_fortiguard_database_versions get_fortiguard_database_versions Read get_fortiguard_servers Get FortiGuard upstream server list and connection status. Read get_fortiguard_service_status get_fortiguard_service_status Read get_fortiguard_update_history get_fortiguard_update_history Read get_fortiguard_update_schedule get_fortiguard_update_schedule Read get_fortiguard_update_status get_fortiguard_update_status Read get_fortiguard_upstream_config get_fortiguard_upstream_config Read get_fortiguard_upstream_servers get_fortiguard_upstream_servers Read get_fortimanager_tool_info get_fortimanager_tool_info Read get_full_device_db_syntax get_full_device_db_syntax Read get_global_firewall_address Get details of a specific global firewall address. Read get_global_firewall_service Get details of a specific global firewall service. Read get_global_policy_hit_statistics Get aggregated policy hit count statistics across all policy packages. Read get_global_policy_package_details get_global_policy_package_details Read get_global_system_config Get global FortiManager system configuration. Read get_ha_cluster_status Get High Availability cluster status if configured. Read get_ha_configuration get_ha_configuration Read get_ha_status get_ha_status Read get_ha_sync_status Get High Availability synchronization status. Read get_install_preview get_install_preview Read get_install_progress_detailed Get real-time detailed installation progress with line-by-line output. Read get_install_targets Get list of devices available for policy installation. Read get_ip_pool Get details of a specific IP pool. Read get_ips_sensor get_ips_sensor Read get_ipsec_phase1_interface Get detailed information about a specific IPsec Phase1 interface. Read get_ipsec_phase2_interface Get detailed information about a specific IPsec Phase2 interface. Read get_ipsec_template Get detailed information about a specific IPsec tunnel template. Read get_ipsec_tunnel_status get_ipsec_tunnel_status Read get_license_status get_license_status Read get_log_config Get log configuration and retention settings. Read get_log_settings get_log_settings Read get_log_statistics Get log storage and processing statistics for an ADOM. Read get_lte_modem_status Get LTE modem status for a device. Read get_meta_field get_meta_field Read get_multicast_address get_multicast_address Read get_network_interface_stats Get network interface statistics with optional interface filter. Read get_normalized_interface_mappings get_normalized_interface_mappings Read get_nth_policy get_nth_policy Read get_object_dependencies get_object_dependencies Read get_object_meta_fields get_object_meta_fields Read get_object_metadata get_object_metadata Read get_object_type_option_attributes get_object_type_option_attributes Read get_package_dependencies Get installation dependencies for a policy package. Read get_package_lock_status Get lock status for a policy package. Read get_platform_type Get list of supported FortiAP platform types. Read get_policy_block get_policy_block Read get_policy_hit_count Get hit count statistics showing which policies are actively used. Read get_policy_hitcount get_policy_hitcount Read get_policy_package_changes get_policy_package_changes Read get_policy_package_checksum get_policy_package_checksum Read get_policy_package_status get_policy_package_status Read get_policy_references_list Get all objects referenced by a specific policy. Read get_policy_usage_stats get_policy_usage_stats Read get_sdn_connector get_sdn_connector Read get_sdn_connector_status get_sdn_connector_status Read get_sdwan_health_check Get SD-WAN health check details. Read get_sdwan_service Get SD-WAN service rule details. Read get_sdwan_template Get detailed information about a specific SD-WAN template. Read get_sdwan_template_assigned_devices Get list of devices assigned to an SD-WAN template. Read get_sdwan_zone Get SD-WAN zone details. Read get_security_profile_entry_count get_security_profile_entry_count Read get_security_profile_group Get details of a security profile group. Read get_service_where_used get_service_where_used Read get_session_statistics Get session statistics for a specific device. Read get_snmp_config Get SNMP configuration including communities and trap destinations. Read get_sql_config Get SQL database configuration. Read get_sslvpn_host_check_software Get detailed information about a specific SSL-VPN host check software configuration. Read get_sslvpn_portal Get detailed information about a specific SSL-VPN portal. Read get_sslvpn_tunnel_status get_sslvpn_tunnel_status Read get_static_route_template Get detailed information about a specific static route template. Read get_supported_model_devices Get list of supported model device platforms. Read get_syslog_config Get syslog server configuration. Read get_system_backup_status Get system backup status and history. Read get_system_dns_settings get_system_dns_settings Read get_system_global_settings get_system_global_settings Read get_system_interface Get detailed information about a specific system interface. Read get_system_interfaces Get network interface configuration for FortiManager. Read get_system_ntp_settings get_system_ntp_settings Read get_system_performance get_system_performance Read get_system_performance_stats Get detailed system performance statistics including CPU, memory, and disk. Read get_system_resource_usage Get system resource usage including CPU, memory, and disk statistics. Read get_system_routes get_system_routes Read get_system_status Get FortiManager system status. Read get_system_template get_system_template Read get_system_template_assigned_devices get_system_template_assigned_devices Read get_tacacs_plus_server_details get_tacacs_plus_server_details Read get_task_details get_task_details Read get_task_history Get task execution history with optional filtering. Read get_task_status get_task_status Read get_template_interface_actions get_template_interface_actions Read get_threat_statistics Get threat detection statistics for specified time range (24h, 7d, 30d). Read get_traffic_class Get traffic class details. Read get_unauthorized_devices get_unauthorized_devices Read get_update_service_config Get FortiManager update service configuration. Read get_upgrade_history get_upgrade_history Read get_upgrade_path get_upgrade_path Read get_vdom_meta_fields get_vdom_meta_fields Read get_virtual_ip Get details of a specific virtual IP. Read get_vpn_ca_certificate Get detailed information about a specific VPN CA certificate. Read get_vpn_remote_certificate Get detailed information about a specific VPN remote certificate. Read get_vpn_statistics get_vpn_statistics Read get_vpn_tunnel_status Get VPN tunnel status/details for a device. Read get_wan_profile Get WAN profile details. Read get_webfilter_profile get_webfilter_profile Read get_workspace_mode_configuration Get workspace mode configuration settings. Read list_address_filters list_address_filters Read list_address_groups list_address_groups Read list_admin_sessions list_admin_sessions Read list_admin_users list_admin_users Read list_adom_revisions list_adom_revisions Read list_adom_templates List all CLI templates configured in an ADOM. Read list_adoms List all Administrative Domains (ADOMs). Read list_all_tasks list_all_tasks Read list_antivirus_profiles List antivirus profiles. Read list_appctrl_profiles list_appctrl_profiles Read list_application_categories list_application_categories Read list_applications list_applications Read list_available_connector_types List available connector types and capabilities. Read list_available_firmware list_available_firmware Read list_ca_certificates list_ca_certificates Read list_central_dnat_policies list_central_dnat_policies Read list_central_snat_policies list_central_snat_policies Read list_certificate_templates list_certificate_templates Read list_cli_script_history list_cli_script_history Read list_cli_scripts list_cli_scripts Read list_cli_template_groups list_cli_template_groups Read list_cli_templates list_cli_templates Read list_cloud_connectors list_cloud_connectors Read list_custom_applications List custom application signatures. Read list_device_blueprints List device blueprints. Read list_device_groups List all device groups. Read list_device_profiles list_device_profiles Read list_device_revisions list_device_revisions Read list_device_vdoms List VDOMs for a device. Read list_devices list_devices Read list_dlp_dictionaries list_dlp_dictionaries Read list_dlp_filepatterns List DLP file patterns. Read list_dlp_fortiguard_elements list_dlp_fortiguard_elements Read list_dlp_sensors list_dlp_sensors Read list_dns_filter_domains List DNS filter domain lists. Read list_docker_containers list_docker_containers Read list_dynamic_firewall_addresses list_dynamic_firewall_addresses Read list_dynamic_interfaces list_dynamic_interfaces Read list_email_filter_profiles list_email_filter_profiles Read list_external_threat_feeds list_external_threat_feeds Read list_fabric_connector_addresses list_fabric_connector_addresses Read list_fabric_connectors list_fabric_connectors Read list_fabric_devices list_fabric_devices Read list_failed_tasks list_failed_tasks Read list_file_filter_profiles list_file_filter_profiles Read list_firewall_addresses list_firewall_addresses Read list_firewall_policies list_firewall_policies Read list_firewall_recurring_schedules List recurring firewall schedules. Read list_firewall_schedules List one-time firewall schedules. Read list_firewall_services list_firewall_services Read list_firewall_traffic_shapers List traffic shapers. Read list_firewall_zones list_firewall_zones Read list_fortiaps list_fortiaps Read list_fortiextenders list_fortiextenders Read list_fortimanager_categories List high-level FortiManager operation categories (metadata-only). Read list_fortiswitches list_fortiswitches Read list_geography_addresses list_geography_addresses Read list_global_address_groups List global address groups shared across all ADOMs. Read list_global_firewall_addresses list_global_firewall_addresses Read list_global_firewall_services list_global_firewall_services Read list_global_policy_packages list_global_policy_packages Read list_icap_profiles list_icap_profiles Read list_interface_addresses list_interface_addresses Read list_internet_service_definitions List custom internet service definitions. Read list_internet_service_fqdns list_internet_service_fqdns Read list_internet_service_groups List internet service groups. Read list_internet_services List internet service name objects. Read list_ip_pools List all IP pools in an ADOM. Read list_ips_protocols list_ips_protocols Read list_ips_sensors list_ips_sensors Read list_ips_signatures list_ips_signatures Read list_ipsec_concentrators list_ipsec_concentrators Read list_ipsec_forticlient_templates list_ipsec_forticlient_templates Read list_ipsec_manualkey_interfaces list_ipsec_manualkey_interfaces Read list_ipsec_phase1_interfaces list_ipsec_phase1_interfaces Read list_ipsec_phase2_interfaces list_ipsec_phase2_interfaces Read list_ipsec_templates list_ipsec_templates Read list_ipv6_firewall_address_groups List IPv6 address groups. Read list_ipv6_firewall_addresses List IPv6 firewall addresses. Read list_meta_fields list_meta_fields Read list_model_devices List model devices. Read list_multicast_addresses list_multicast_addresses Read list_objects_by_metadata list_objects_by_metadata Read list_objects_with_meta_field list_objects_with_meta_field Read list_onetime_schedules List all one-time schedules in an ADOM. Read list_policy_blocks list_policy_blocks Read list_policy_packages list_policy_packages Read list_proxy_addresses list_proxy_addresses Read list_qos_shaping_policies list_qos_shaping_policies Read list_recent_tasks list_recent_tasks Read list_recurring_schedules List all recurring schedules in an ADOM. Read list_replacement_message_groups list_replacement_message_groups Read list_running_tasks list_running_tasks Read list_scheduled_installs list_scheduled_installs Read list_sdn_connectors list_sdn_connectors Read list_sdwan_health_checks List SD-WAN health check monitors. Read list_sdwan_members List SD-WAN member interfaces. Read list_sdwan_services list_sdwan_services Read list_sdwan_templates list_sdwan_templates Read list_sdwan_zones List SD-WAN zones in an ADOM. Read list_security_profile_groups list_security_profile_groups Read list_service_categories list_service_categories Read list_ssh_filter_profiles list_ssh_filter_profiles Read list_sslvpn_host_check_software list_sslvpn_host_check_software Read list_sslvpn_portals list_sslvpn_portals Read list_static_route_templates list_static_route_templates Read list_system_administrators list_system_administrators Read list_system_certificates list_system_certificates Read list_system_interfaces list_system_interfaces Read list_system_templates list_system_templates Read list_tacacs_plus_servers list_tacacs_plus_servers Read list_tasks list_tasks Read list_traffic_classes List traffic classes for SD-WAN application-based routing. Read list_traffic_shaping_profiles List traffic shaping profiles. Read list_url_filters List URL filter objects. Read list_vip_groups List all VIP groups in an ADOM. Read list_virtual_ips list_virtual_ips Read list_virtual_wire_pairs list_virtual_wire_pairs Read list_voip_profiles list_voip_profiles Read list_vpn_ca_certificates list_vpn_ca_certificates Read list_vpn_remote_certificates list_vpn_remote_certificates Read list_wan_profiles List WAN profiles (SD-WAN templates). Read list_webfilter_profiles list_webfilter_profiles Read list_wildcard_fqdn_addresses list_wildcard_fqdn_addresses Read list_wildcard_fqdns List all wildcard FQDNs in an ADOM. Read query_fortiguard_outbreak query_fortiguard_outbreak Read query_ips_applications query_ips_applications Read retrieve_device_config retrieve_device_config Read search_fortimanager_tools search_fortimanager_tools Read validate_policy_package Validate policy package before installation to check for errors. Read validate_policy_package_errors Validate policy package configuration for errors. Read validate_provisioning_template validate_provisioning_template Read validate_security_profile_entries validate_security_profile_entries Read verify_package_installation Verify that a package was successfully installed on a device. Read export_adom_config Export ADOM configuration for backup purposes. Read export_fortiguard_configuration export_fortiguard_configuration Read export_policy_configuration export_policy_configuration Read export_templates export_templates
WRITE 130 tools
Write authorize_device authorize_device Write change_device_serial_number change_device_serial_number Write clone_adom clone_adom Write clone_firewall_policy clone_firewall_policy Write clone_fortiswitch_template clone_fortiswitch_template Write clone_policy_block clone_policy_block Write clone_system_template clone_system_template Write duplicate_firewall_policy duplicate_firewall_policy Write unassign_certificate_template unassign_certificate_template Write unassign_cli_template unassign_cli_template Write unassign_cli_template_group unassign_cli_template_group Write unassign_ipsec_template Unassign an IPsec tunnel template from a device. Write unassign_sdwan_template Unassign an SD-WAN template from a device. Write unassign_static_route_template unassign_static_route_template Write unassign_system_template unassign_system_template Write add_custom_command_to_template add_custom_command_to_template Write add_device_to_group add_device_to_group Write add_interface_to_zone add_interface_to_zone Write add_ips_rule add_ips_rule Write add_ospf_network_entry add_ospf_network_entry Write add_policies_to_block add_policies_to_block Write add_real_device add_real_device Write add_template_to_group add_template_to_group Write add_url_to_filter add_url_to_filter Write add_vdom add_vdom Write add_vlan_interface add_vlan_interface Write assign_certificate_template assign_certificate_template Write assign_cli_template assign_cli_template Write assign_cli_template_group assign_cli_template_group Write assign_device_to_adom assign_device_to_adom Write assign_fortiswitch_template assign_fortiswitch_template Write assign_ipsec_template Assign an IPsec tunnel template to a device. Write assign_metadata_to_objects assign_metadata_to_objects Write assign_sdwan_template Assign an SD-WAN template to a device. Write assign_static_route_template Assign a static route template to a device. Write assign_system_template assign_system_template Write assign_template_group_to_device_group assign_template_group_to_device_group Write assign_vdom_to_adom assign_vdom_to_adom Write bulk_add_security_profile_entries bulk_add_security_profile_entries Write bulk_update_security_profile_entries bulk_update_security_profile_entries Write commit_adom_workspace commit_adom_workspace Write commit_device_workspace Commit changes to a device configuration. Write commit_policy_package_workspace Commit changes to a policy package. Write create_address_group create_address_group Write create_adom_revision create_adom_revision Write create_adom_with_device_assignment create_adom_with_device_assignment Write create_advanced_adom create_advanced_adom Write create_central_dnat_policy create_central_dnat_policy Write create_central_snat_policy create_central_snat_policy Write create_certificate_template create_certificate_template Write create_cli_template create_cli_template Write create_cli_template_group create_cli_template_group Write create_custom_application create_custom_application Write create_custom_command create_custom_command Write create_device_blueprint Create a device blueprint. Write create_device_group create_device_group Write create_dns_filter_domain create_dns_filter_domain Write create_dynamic_interface create_dynamic_interface Write create_external_threat_feed create_external_threat_feed Write create_firewall_address create_firewall_address Write create_firewall_policy create_firewall_policy Write create_firewall_service create_firewall_service Write create_firewall_zone create_firewall_zone Write create_fortianalyzer_adom create_fortianalyzer_adom Write create_fortiswitch_template create_fortiswitch_template Write create_ha_cluster create_ha_cluster Write create_internet_service_fqdn create_internet_service_fqdn Write create_internet_service_group create_internet_service_group Write create_ip_pool create_ip_pool Write create_ips_sensor create_ips_sensor Write create_ipsec_phase1_interface create_ipsec_phase1_interface Write create_ipsec_phase2_interface create_ipsec_phase2_interface Write create_ipsec_template Create a new IPsec tunnel template. Write create_meta_field create_meta_field Write create_model_device create_model_device Write create_model_fortiap create_model_fortiap Write create_model_fortiextender create_model_fortiextender Write create_model_fortiswitch create_model_fortiswitch Write create_policy_block create_policy_block Write create_policy_folder create_policy_folder Write create_policy_section create_policy_section Write create_recurring_schedule create_recurring_schedule Write create_sdwan_health_check create_sdwan_health_check Write create_sdwan_service create_sdwan_service Write create_sdwan_template Create a new SD-WAN template. Write create_sdwan_zone Create an SD-WAN zone. Write create_security_profile_group create_security_profile_group Write create_sslvpn_portal create_sslvpn_portal Write create_static_route_template Create a new static route template. Write create_system_template create_system_template Write create_template_group create_template_group Write create_traffic_class Create a traffic class. Write create_vip_group create_vip_group Write create_virtual_ip create_virtual_ip Write create_wildcard_fqdn create_wildcard_fqdn Write disable_device_auto_link disable_device_auto_link Write enable_device_auto_link enable_device_auto_link Write import_fortiguard_configuration import_fortiguard_configuration Write import_fortiswitch_template Import a FortiSwitch template. Write import_policy_configuration import_policy_configuration Write insert_policy_at_position insert_policy_at_position Write insert_policy_block insert_policy_block Write lock_adom_workspace lock_adom_workspace Write lock_device_workspace lock_device_workspace Write lock_policy_package_workspace lock_policy_package_workspace Write move_device_to_adom move_device_to_adom Write move_firewall_policy move_firewall_policy Write move_policy_package_to_folder move_policy_package_to_folder Write move_policy_to_section move_policy_to_section Write move_vdom_to_adom move_vdom_to_adom Write rename_device rename_device Write rename_fortiap Rename a managed FortiAP. Write replace_security_profile_entries replace_security_profile_entries Write set_device_meta_fields set_device_meta_fields Write set_device_rma_status set_device_rma_status Write set_object_meta_field set_object_meta_field Write set_object_metadata set_object_metadata Write set_policy_label set_policy_label Write set_vdom_meta_fields set_vdom_meta_fields Write unlock_adom_workspace unlock_adom_workspace Write unlock_device_workspace Unlock a device. Write unlock_policy_package_workspace Unlock a policy package. Write update_cli_script update_cli_script Write update_cli_template update_cli_template Write update_cluster_serial_numbers update_cluster_serial_numbers Write update_firewall_address update_firewall_address Write update_fortiap_config update_fortiap_config Write update_fortiswitch_port update_fortiswitch_port Write update_system_template Update an existing system template. Write upload_device_certificate upload_device_certificate
DESTRUCTIVE 55 tools
Destructive bulk_delete_security_profile_entries bulk_delete_security_profile_entries Destructive clear_database_cache clear_database_cache Destructive delete_adom_revision delete_adom_revision Destructive delete_central_dnat_policy Delete a central DNAT policy. Destructive delete_central_snat_policy Delete a central SNAT policy. Destructive delete_certificate_template delete_certificate_template Destructive delete_cli_script delete_cli_script Destructive delete_cli_template Delete a CLI template. Destructive delete_cli_template_group Delete a CLI template group. Destructive delete_custom_application Delete a custom application. Destructive delete_device_blueprint Delete a device blueprint. Destructive delete_device_group Delete a device group. Destructive delete_dns_filter_domain Delete a DNS filter domain list. Destructive delete_dynamic_interface Delete a dynamic interface. Destructive delete_external_threat_feed Delete an external threat feed. Destructive delete_firewall_address delete_firewall_address Destructive delete_firewall_policy delete_firewall_policy Destructive delete_firewall_zone delete_firewall_zone Destructive delete_fortiap_profile Delete a FortiAP profile. Destructive delete_fortiextender delete_fortiextender Destructive delete_internet_service_fqdn delete_internet_service_fqdn Destructive delete_internet_service_group Delete an internet service group. Destructive delete_ip_pool Delete an IP pool. Destructive delete_ips_sensor delete_ips_sensor Destructive delete_ipsec_phase1_interface delete_ipsec_phase1_interface Destructive delete_ipsec_phase2_interface Delete an IPsec Phase2 interface. Destructive delete_ipsec_template Delete an IPsec tunnel template. Destructive delete_meta_field delete_meta_field Destructive delete_object_metadata delete_object_metadata Destructive delete_policy_block delete_policy_block Destructive delete_policy_folder delete_policy_folder Destructive delete_recurring_schedule Delete a recurring schedule. Destructive delete_sdwan_health_check Delete an SD-WAN health check. Destructive delete_sdwan_service Delete an SD-WAN service rule. Destructive delete_sdwan_template Delete an SD-WAN template. Destructive delete_sdwan_zone Delete an SD-WAN zone. Destructive delete_security_profile_group Delete a security profile group. Destructive delete_sslvpn_portal Delete an SSL-VPN portal. Destructive delete_static_route_template Delete a static route template. Destructive delete_system_template Delete a system template. Destructive delete_template_group Delete a template group. Destructive delete_traffic_class Delete a traffic class. Destructive delete_vdom Delete a VDOM from a device. Destructive delete_vip_group Delete a VIP group. Destructive delete_virtual_ip Delete a virtual IP. Destructive delete_wildcard_fqdn Delete a wildcard FQDN. Destructive remove_device_from_group remove_device_from_group Destructive remove_interface_from_zone remove_interface_from_zone Destructive remove_template_from_group remove_template_from_group Destructive revert_adom_revision revert_adom_revision Destructive revert_adom_to_revision revert_adom_to_revision Destructive revert_device_revision revert_device_revision Destructive revert_policy_package revert_policy_package Destructive restore_system_config restore_system_config Destructive rollback_device_install Rollback a device to previous installation state.
EXECUTE 27 tools
Execute cancel_scheduled_install cancel_scheduled_install Execute execute_advanced_tool Execute a FortiManager operation dynamically by tool name. Execute execute_cli_script execute_cli_script Execute execute_device_json_commands execute_device_json_commands Execute execute_fortimanager_tool execute_fortimanager_tool Execute run_device_cli_commands run_device_cli_commands Execute trigger_fortiguard_update trigger_fortiguard_update Execute wait_for_task_completion wait_for_task_completion Execute clone_cli_script clone_cli_script Execute reboot_system reboot_system Execute refresh_device refresh_device Execute refresh_external_threat_feed Manually refresh an external threat feed. Execute refresh_sdn_connector refresh_sdn_connector Execute upgrade_adom upgrade_adom Execute upgrade_device_firmware upgrade_device_firmware Execute validate_cli_script validate_cli_script Execute validate_cli_template validate_cli_template Execute abort_policy_install Abort an ongoing policy installation task. Execute create_cli_script create_cli_script Execute enable_vdom enable_vdom Execute install_device_settings install_device_settings Execute install_package_offline install_package_offline Execute install_package_to_device_db install_package_to_device_db Execute install_policy_package install_policy_package Execute schedule_cli_script schedule_cli_script Execute schedule_package_install Schedule a policy package installation for future time. Execute schedule_policy_install schedule_policy_install

Route Fortimanager through PolicyLayer and every one of its 584 tools is checked against your policy before it runs.

CHECK YOUR STACK →

See every tool, the dangerous ones, and the token cost across your stack.

How many tools does the Fortimanager MCP server have? +

The Fortimanager MCP server exposes 584 tools across 5 categories: Read, Write, Destructive, Execute, Other.

How do I enforce policies on Fortimanager tools? +

Route the Fortimanager server through the PolicyLayer gateway. Define allow, deny, or approval rules per tool in the dashboard; they are enforced on every call before it reaches the server.

What risk categories do Fortimanager tools fall into? +

Fortimanager tools are categorised as Read (358), Write (130), Destructive (55), Execute (27), Other (14). Each category has a recommended default policy.

Enforce policy on every Fortimanager tool call.

Start from Fortimanager, add the rest of your stack, and see everything your agents can call. Then put policy on all of it.

Free to start. No card required.

43,000+ MCP servers and 220,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.