Agent skill

Fmc Firewall Ops

by automateyournetwork in automateyournetwork/netclaw

Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management.

Apache-2.0Auto-check: notesDevOps & Cloud

Install Fmc Firewall Ops

skills CLI
$ npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw fmc-firewall-ops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/fmc-firewall-ops .claude/skills/fmc-firewall-ops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fmc-firewall-ops
GitHub stars
676
Token cost
~1.8k tokens
SKILL.md length
771 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management.

  • Works in 5 steps: Discover FMCs: list_fmc_profiles —… → Search rules: search_access_rules with… → For each match: Extract rule name,… → …
  • Searching firewall rules by IP
  • SKILL.md covers MCP Server, Available Tools (4), Key Concepts and Workflow: Firewall Rule Audit, plus 8 more sections
  • Calls git, pip and python; needs FMC_PASSWORD

What it does

Fmc Firewall Ops is an agent skill from automateyournetwork/netclaw. Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management. Use when searching firewall rules by IP or FQDN, checking if host A can reach host B through the firewall, auditing FMC access policies, or reviewing SGT-based segmentation rules.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud networking. It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Searching firewall rules by IP
  • Checking if host A can reach host B through the firewall
  • Auditing FMC access policies
  • Reviewing SGT-based segmentation rules

Example prompts

  • “/fmc-firewall-ops”

Requirements

  • Python 3
  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Discover FMCs: list_fmc_profiles — identify which FMCs manage this network
  2. Search rules: search_access_rules with network indicator 10.1.1.0/24
  3. For each match: Extract rule name, action (allow/block), source/dest zones, source/dest networks, ports, logging settings
  4. Cross-reference: Check if rules are overly permissive (any/any), redundant, or shadowed
  5. Report: Formatted rule table with security assessment

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • pip
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FMC_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fmc Firewall Ops loads about 1.8k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 771 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:95
    Single FMC mode (set in `.env`):
  • NoteMentions a .env fileSKILL.md:111
    Each profile `.env` contains:

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 771 words, ~1,813 tokens.

Download SKILL.mdSave it as .claude/skills/fmc-firewall-ops/SKILL.md (or your agent's skills folder).
name
fmc-firewall-ops
description
Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management. Use when searching firewall rules by IP or FQDN, checking if host A can reach host B through the firewall, auditing FMC access policies, or reviewing SGT-based segmentation rules.
version
1.0.0
license
Apache-2.0
tags
cisco, fmc, firewall, ftd, security, access-policy, firepower

Cisco FMC Firewall Operations

MCP Server

  • Repository: CiscoDevNet/CiscoFMC-MCP-server-community
  • Transport: HTTP (http://<host>:8000/mcp) — requires HTTPS reverse proxy for production
  • Install: git clone + pip install -r requirements.txt + python -m sfw_mcp_fmc.server (or Docker)
  • Requires: FMC_BASE_URL, FMC_USERNAME, FMC_PASSWORD

Available Tools (4)

ToolWhat It Does
list_fmc_profilesDiscover all configured FMC instances (single or multi-FMC mode). Returns profile IDs, display names, and aliases. Use this first to select which FMC to query.
find_rules_by_ip_or_fqdnSearch rules within a specific access policy by IP address or FQDN. Matches source/destination network objects against the given indicator.
find_rules_for_targetResolve FTD devices or HA clusters to their assigned access policies, then search those policies. Use when you know the firewall device name but not the policy name.
search_access_rulesFMC-wide rule search with multiple filter types: network indicators (IP, FQDN), identity indicators (SGT tags, realm users/groups), and policy name filters. The most powerful search tool.

Key Concepts

ConceptWhat It Means
FMCFirepower Management Center — centralized management for Cisco Secure Firewalls (FTD)
FTDFirepower Threat Defense — the firewall appliance/virtual managed by FMC
Access PolicyCollection of access rules (ACLs) applied to FTD devices — permit/deny by source/dest/port/app
Access RuleIndividual rule within a policy — source zones, dest zones, source/dest networks, ports, action (allow/block/monitor)
SGTSecurity Group Tag — TrustSec identity-based tag for micro-segmentation
HA ClusterHigh Availability pair of FTD devices sharing the same policy
ProfileFMC connection configuration (URL, credentials) — supports multi-FMC environments

Workflow: Firewall Rule Audit

When a user asks "what firewall rules exist for 10.1.1.0/24?":

  1. Discover FMCs: list_fmc_profiles — identify which FMCs manage this network
  2. Search rules: search_access_rules with network indicator 10.1.1.0/24
  3. For each match: Extract rule name, action (allow/block), source/dest zones, source/dest networks, ports, logging settings
  4. Cross-reference: Check if rules are overly permissive (any/any), redundant, or shadowed
  5. Report: Formatted rule table with security assessment

Workflow: "Can Host A Reach Host B?"

When investigating connectivity through the firewall:

  1. Identify FTD: Which firewall sits between source and destination?
  2. Resolve policy: find_rules_for_target with the FTD device name
  3. Search source IP: find_rules_by_ip_or_fqdn for the source IP in the resolved policy
  4. Search dest IP: Same for destination IP
  5. Analyze: Do the matching rules permit the required port/protocol?
  6. Report: "Traffic from 10.1.1.50 to 10.2.1.100:443 is ALLOWED by rule 'Web-Servers-Inbound' (line 47)" or "BLOCKED by implicit deny"

Workflow: Security Group Tag (SGT) Policy Review

When auditing TrustSec/SGT-based policies:

  1. Search by SGT: search_access_rules with identity indicator for a specific SGT value
  2. List matching rules: Which rules reference this SGT in source or destination?
  3. Check actions: Are SGT-based rules enforcing proper segmentation?
  4. Cross-reference: Use ise-posture-audit to verify SGT assignment policies in ISE
  5. Report: SGT policy coverage analysis
Show full SKILL.md (328 more words)Show less

Workflow: Multi-FMC Environment Audit

When managing multiple FMC instances:

  1. List all FMCs: list_fmc_profiles — see all managed FMC instances
  2. For each FMC: search_access_rules with common indicators
  3. Compare policies: Are policies consistent across FMCs?
  4. Identify drift: Rules present in one FMC but not another
  5. Report: Cross-FMC policy consistency analysis

Integration with Other Skills

SkillHow They Work Together
pyats-securityFMC rule audit + device-level ACL verification via pyATS
ise-posture-auditFMC SGT rules + ISE SGT assignment and TrustSec matrix
ise-incident-responseFMC rules for quarantine verification + ISE endpoint investigation
aws-security-auditCross-platform security: FMC on-prem + AWS cloud security posture
gcp-cloud-loggingFMC firewall logs vs GCP firewall logs for hybrid environments
nso-device-opsFMC policies + NSO device config for end-to-end policy view
servicenow-change-workflowServiceNow CR gating before any FMC policy modifications
github-opsCommit FMC rule snapshots to Git for config-as-code tracking

Multi-FMC Configuration

Single FMC mode (set in .env):

FMC_BASE_URL=https://fmc.example.com
FMC_USERNAME=api-user
FMC_PASSWORD=changeme
FMC_VERIFY_SSL=false

Multi-FMC mode (profile directory):

profiles/
  dc-east.env    # FMC for DC East
  dc-west.env    # FMC for DC West
  dmz.env        # FMC for DMZ firewalls

Each profile .env contains:

FMC_PROFILE_ID=dc-east
FMC_PROFILE_DISPLAY_NAME=DC East FMC
FMC_PROFILE_ALIASES=10.1.1.10,fmc-east
FMC_BASE_URL=https://fmc-east.example.com
FMC_USERNAME=api-user
FMC_PASSWORD=changeme
FMC_VERIFY_SSL=false

Important Rules

  • Read-only — all 4 tools are search/query operations; no rule modifications
  • HTTP transport — server runs on port 8000, front with HTTPS proxy for production
  • Multi-FMC — always call list_fmc_profiles first to select the right FMC instance
  • FMC API rate limits — FMC REST API has per-user rate limits; avoid rapid-fire queries
  • Record in GAIT — log all firewall policy investigations for audit trail

Environment Variables

  • FMC_BASE_URL — FMC URL (e.g., https://fmc.example.com)
  • FMC_USERNAME — FMC API username
  • FMC_PASSWORD — FMC API password
  • FMC_VERIFY_SSL — SSL verification (true/false)
  • FMC_PROFILES_DIR — path to multi-FMC profiles directory (optional)
  • FMC_PROFILE_DEFAULT — default profile name (optional)

Failure Behavior

  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/fmc-firewall-ops of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Fmc Firewall Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fmc Firewall Ops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fmc Firewall Ops this skillautomateyournetwork/netclaw676—~1.8kAutomated safety check: NotesApache-2.0
Unifienuno/unifi-mcp-server282—~1kAutomated safety check: PassApache-2.0
Frontmcp Deploymentagentfront/frontmcp146—~9.2kAutomated safety check: NotesApache-2.0
Openfdd Railway CLIbbartling/open-fdd173—~2.3kAutomated safety check: NotesCustom licence
Azure Computemicrosoft/GitHub-Copilot-for-Azure255—~657Automated safety check: PassMIT
AWS Containersaws/agent-toolkit-for-aws2.8k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Unifi

    enuno/unifi-mcp-server

    Manage UniFi network infrastructure via the UniFi MCP Server.

    282 GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Frontmcp Deployment

    agentfront/frontmcp

    A skill your agent uses when deploying, building for production, packaging, or shipping a FrontMCP server.

    146 GitHub stars~9.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Openfdd Railway CLI

    bbartling/open-fdd

    A skill your agent uses when installing, authenticating, linking, or re-pinning the Open-FDD Railway hub (central/mqtt/web) via the Railway CLI on bensbench.

    173 GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Azure Compute

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure VM/VMSS router. An agent skill from microsoft/GitHub-Copilot-for-Azure.

    255 GitHub stars~657 tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Containers

    aws/agent-toolkit-for-aws

    Official

    Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry).

    2.8k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated today
    Auto-check passed

Categories

Questions about Fmc Firewall Ops

What does Fmc Firewall Ops do?

Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management. Fmc Firewall Ops is an agent skill from automateyournetwork/netclaw. Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management.

When should I use Fmc Firewall Ops?

Fmc Firewall Ops fits situations like: searching firewall rules by IP; checking if host A can reach host B through the firewall; auditing FMC access policies; reviewing SGT-based segmentation rules.

How do I install Fmc Firewall Ops in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a claude-code`. Or copy the skill folder (workspace/skills/fmc-firewall-ops in automateyournetwork/netclaw) into .claude/skills/fmc-firewall-ops in your project. Claude Code loads it when a task matches its description.

How do I install Fmc Firewall Ops in Codex?

Run `npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a codex`. Or copy the skill folder (workspace/skills/fmc-firewall-ops in automateyournetwork/netclaw) into .agents/skills/fmc-firewall-ops in your project. Codex loads it when a task matches its description.

Can I use Fmc Firewall Ops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fmc-firewall-ops, .gemini/skills/fmc-firewall-ops, .github/skills/fmc-firewall-ops and .opencode/skills/fmc-firewall-ops in your project.

What does Fmc Firewall Ops need to run?

Going by SKILL.md and its folder, Fmc Firewall Ops needs the command-line tools its instructions call (git, pip and python) and credentials named FMC_PASSWORD. Our summary lists: Python 3; Docker.

Does Fmc Firewall Ops access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Fmc Firewall Ops safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Fmc Firewall Ops use?

Fmc Firewall Ops is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fmc Firewall Ops use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fmc Firewall Ops?

Skills that share tags, products or a category with Fmc Firewall Ops: Unifi (enuno/unifi-mcp-server, 282 stars), Frontmcp Deployment (agentfront/frontmcp, 146 stars), Openfdd Railway CLI (bbartling/open-fdd, 173 stars) and Azure Compute (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fmc Firewall Ops?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.