Letting Claude Read My Firewall: an OPNsense MCP Server, and What It Found on My Network
I gave Claude a read-only window into my firewall. Not “pasted some logs into a chat” — an actual Model Context Protocol server wrapping the OPNsense API, so Claude Code could call leasesSearchLease, dnsReverseLookup, and dozens of other firewall functions on demand. Then I pointed it at a simple question — what is actually on my network, and where does it all phone home? — and got a genuinely uncomfortable answer.
This post is two things: how to stand up an OPNsense MCP server in Docker safely, and the little network-forensics session it enabled, which is the real reason to build one.
/ipad-internet off: A Claude Code Skill That Cuts One Device's Internet at the Firewall
I wanted one command — /ipad-internet off — that instantly cuts the household iPad’s internet, and /ipad-internet on to give it back. Simple ask. The interesting part is doing it correctly: instantly (no waiting on a config save), reversibly, without disturbing the LAN (AirPlay, printers, local media should all keep working), and — most importantly — in a way that can never accidentally knock a different device offline.
It ended up as a Claude Code skill backed by a careful bit of OPNsense / pf design. This post is about that design: why it uses a pf table instead of editing the config, how it survives the iPad’s shifting IP and Apple’s private Wi-Fi MAC, and the ownership guard that makes the “wrong device” failure mode structurally impossible.
Own Your Devices: Building a Reliable Home Network Infrastructure
Tired of overworked ISP-provided modems and unreliable WiFi? This guide covers how I built a robust home network infrastructure using OPNSense, OpenWrt, and strategic hardware redundancy. Learn how to separate network functions across dedicated devices for better performance, reliability, and control—all while meeting strict uptime requirements and avoiding subscription services.