MCP servers for networking and infrastructure are proliferating across every layer of the stack. Here’s the most comprehensive curated list available for AI-driven network automation and what it means for how your team operates.
MCP (Model Context Protocol) servers are standardized interfaces that give AI agents governed access to real infrastructure tools, enabling natural language control over network devices, cloud platforms, observability stacks, and ITSM systems. As of September 2026, 78 production-ready MCP servers span every major layer of the network and infrastructure stack, making AI-native operations a practical reality today.
Network automation has always had the same core problem. The tools were powerful, but the people who could use them were scarce. Ansible, Terraform, Nornir, pyATS – brilliant technologies that required a level of Python fluency, API literacy, and vendor-specific knowledge that most operational teams simply didn’t possess at scale. The automation gap wasn’t a technology gap. It was a translation gap.
Then large language models arrived, and the calculus changed entirely. LLMs demonstrated that natural language could be a legitimate interface to complex systems. But an LLM on its own is a brain in a jar – it can reason, plan, and generate, but it cannot act. On its own, an LLM cannot reach into your network, query your CMDB, push a config, or check your cloud spend. For that, it needs standardized, discoverable, governed tools it can call reliably and safely.
MCP provides the bridge between the LLM and your network, systems, data, apps, and other resources – enabling the replacement of business logic with reasoning.
What follows is the most comprehensive curated list of network automation and infrastructure MCP servers available today. These aren’t aspirations or roadmap items. These MCP servers are shipping, usable, and in many cases production-ready.
Several of the servers below were built by John Capobianco – a prolific contributor to the network automation MCP ecosystem. His work across pyATS, ACI, ISE, Markmap, and Wikipedia has helped lay the open-source foundation for AI-native network ops.
CAT 01
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| Itential | stdio Python | The richest MCP tool surface on this list at 65+ tools. Network automation orchestration covering config management, compliance, workflows, golden config, and full lifecycle automation. |
| ⭐ pyATS | stdio Python | Cisco’s pyATS framework – the gold standard for network testing – now directly accessible to AI agents. Structured device interaction, Genie parsers, config push, and dynamic test generation. |
| F5 BIG-IP | stdio Python | Full iControl REST API coverage: virtual servers, pools, iRules, profiles, and stats. Lets an AI agent reason about your load balancer without writing a line of code. |
| Catalyst Center (Official) | Streamable HTTP | Now shipping as an official Cisco open-source server (Aug 2026), superseding the earlier community build this guide originally listed. Devices, clients, sites, and interfaces – all queryable through natural language, backed by Cisco DevNet. Select the release branch matching your Catalyst Center version. Note that it adds no authorization layer and does not enforce read-only access – the bundled catalog may include config-changing operations. |
| Cisco CML | stdio Python | Cisco Modeling Labs gets a full MCP wrapper. Lab lifecycle, topology management, node/link control, packet captures, and CLI exec. |
| Juniper JunOS | stdio Python | Official Juniper server using PyEZ and NETCONF. CLI execution, config management, Jinja2 template rendering, device facts, and batch operations across 10 tools. |
| Juniper Mist (Official) | Remote HTTP | Juniper’s hosted, official path into the Mist AI cloud — org and site status, client troubleshooting, no local install. Pairs with the JunOS server already listed to give Juniper full device-plus-cloud coverage. Juniper’s own docs warn it can surface PSKs, RADIUS secrets and SNMP credentials to the assistant, so token scoping is not optional. |
| Arista CVP | stdio Python | CloudVision Portal REST API access for Arista environments. Device inventory, events, connectivity monitoring, and tag management. Community-maintained. |
| ⭐ Protocol MCP | stdio Python | Live BGP and OSPF control-plane participation – an AI agent can peer with routers, inject or withdraw routes, and query the RIB and LSDB in real time. |
| ContainerLab | stdio Python | Full containerized network lab lifecycle via MCP. Deploy, inspect, exec, and destroy labs running SR Linux, cEOS, FRR, IOS-XR, or NX-OS. |
| Netmiko MCP | stdio Python | The broadest vendor reach on the list — Cisco IOS/IOS-XE/NX-OS/ASA, Junos, EOS, HP/Aruba and 50+ more. Where a vendor has no MCP server of its own, Netmiko is the fallback that still works. |
| HPE Aruba Central | uvx Python | Closes the biggest campus gap in the guide. 25 tools reaching 85+ Central API endpoints plus 12 pre-built investigation workflows, and it is architecturally read-only — it cannot change config or network state even if asked. Runs over stdio by default via uvx, with a streamable-HTTP mode for shared or remote use. A useful reference model for safe-by-construction design. |
| HPE Networking Unified | Docker | One container spanning Juniper Mist, Aruba Central and HPE GreenLake. For shops that inherited both HPE and Juniper wireless post-acquisition, this is a single connection instead of three. |
| Cisco Nexus Dashboard | Docker | 638+ operations across five Nexus Dashboard APIs, and the best-governed community server found — read-only by default, writes behind explicit enablement, plus RBAC, encrypted credentials, audit logging and LDAP. Deploys via Docker Compose and is reachable over SSE for remote clients. Community-built, enterprise-shaped. |
| Puppet Edge | — | Model-driven rather than CLI-driven. YANG/OpenConfig means the agent reasons about intent against a schema instead of scraping command output — and it validates before it writes. |
CAT 02
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| ⭐ Cisco ACI | stdio Python | APIC interaction, policy management, and fabric health for Cisco ACI data centers. Makes ACI’s notoriously deep policy model approachable via natural language. |
| ⭐ Cisco ISE | stdio Python | Identity Services Engine – the enforcement heart of Cisco’s Zero Trust architecture. Exposes identity policy, posture assessment, TrustSec, and endpoint control. |
| Cisco FMC | stdio Python | Firepower Management Center for Cisco’s Secure Firewall platform. Policy search, FTD device targeting, and multi-FMC support. |
| Cisco Meraki (Official) | Remote HTTP | Cisco shipped official hosted and open-source Meraki MCP servers in beta (Aug 2026), replacing the community build. Hosted at mcp.meraki.com/mcp, or self-host the open-source build – Cisco describes both as read-only. Coverage spans orgs, networks, wireless, switching, security, cameras, and diagnostics. Hosted deployment supports Meraki.com only (no Federal, GovCloud or localized environments) and does not currently enforce Dashboard API IP restrictions. |
| ThousandEyes (official) | Remote HTTP | The official, fuller version: alerts, outages, BGP routes, instant tests, endpoint agents, anomalies, and AI views across ~20 tools. Hosted. |
| Cisco SD-WAN | stdio Python | vManage read-only monitoring across 12 tools: fabric devices, WAN Edge inventory, templates, policies, alarms, BFD sessions, OMP routes, and control connections. |
| Catalyst SD-WAN (CiscoDevNet) | Docker Node | Triples the SD-WAN coverage currently in the guide — 39 tools spanning device management, live monitoring, templates, policies, CloudExpress and administration, versus 12 read-only tools. Routers are reached only through vManage, so the existing control plane stays the enforcement point. |
| DevNet Content Search | Remote HTTP | The grounding layer for the two official Cisco servers. Semantic search across Meraki and Catalyst Center API docs with full OpenAPI specs means the agent looks up the endpoint instead of inventing one. Cisco-hosted at devnet.cisco.com, no local install. |
| Network MCP Docker Suite | Docker | Ten servers — Meraki, NetBox, Catalyst Center, IOS XE, ThousandEyes, ISE, Splunk, Prometheus, ClickHouse, GitLab — in one docker compose up. The fastest way to stand up a realistic multi-domain agent lab. |
CAT 03
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| NetBox | stdio Python | Read-write access to the most widely deployed open-source DCIM/IPAM platform. AI agents can query and update your source of truth directly. |
| NetBox Platform MCP (Official) | Remote HTTP | NetBox Labs’ own managed server, and a genuine step up from the community build: GraphQL, bulk operations, cable tracing, Code Mode for multi-step workflows, and branching with change management. An agent can propose source-of-truth changes on a branch instead of writing straight to production. |
| netbox-mcp-rw | stdio Python | Full CRUD on NetBox for teams self-hosting rather than on NetBox Cloud. Device inventory, IP assignment, rack and site management, lifecycle status — the write path the official managed server gates behind plan tier. FastMCP-based, run via uv. |
| Nautobot | stdio Python | The Red Hat-backed NetBox evolution. Five tools covering IP addresses, prefixes, VRF, tenant, and site filtering. |
| Nautobot MCP (Official) | Streamable HTTP | Network to Code’s official v1.0, replacing the five-tool community server. Acts as an authenticated middleware layer rather than a thin API wrapper, so existing Nautobot permissions carry through. Defaults to streamable-HTTP on /mcp, with SSE available for older clients. |
| OpsMill Infrahub | stdio Python | Schema-driven SoT with versioned branches and GraphQL queries. The GitOps-for-infrastructure data model with ten tools covering the full lifecycle. |
| ServiceNow | stdio Python | Incidents, change requests, and CMDB. AI agents that can open tickets, query asset state, and act on ITSM data without a human copy-pasting between systems. |
| Infoblox (Official) | Remote HTTP | Exposes Infoblox’s DNS/DHCP/IPAM (DDI) data – the source-of-truth layer NetBox and Nautobot don’t cover. Infoblox’s pending acquisition of Kentik (announced July 2026) will fuse this with network flow and path data behind the same MCP layer. |
CAT 04
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| AWS Network | uvx Python | 27 tools covering VPC, Transit Gateway, Cloud WAN, VPN, Network Firewall, and flow logs. The deepest AWS networking MCP server available. |
| AWS CloudWatch | uvx Python | Metrics, alarms, and Logs Insights queries. Give your AI agent eyes on your AWS observability data. |
| AWS Cost Explorer | uvx Python | Spending analysis, forecasts, and anomaly detection. AI-driven FinOps without exporting CSVs. |
| AWS MCP Server | Remote HTTP | One managed remote server with access to 15,000+ AWS APIs, full documentation, and pre-built Agent SOPs for common multi-step tasks. |
| Azure MCP Server 2.0 | Remote HTTP | The single largest omission in the guide. 276 tools across 57 Azure services covering provisioning through operational diagnostics, and as of the April 2026 stable release it can be self-hosted as a remote server inside your own boundary. Entra ID auth and RBAC-scoped throughout. |
| Cloudflare (15 servers) | Remote HTTP | Fifteen official remote servers, several of them squarely network-operational: Radar for global traffic, BGP routing, ASN data and internet outages; DNS Analytics; Digital Experience Monitoring; Cloudflare One CASB. Radar in particular gives an agent internet-scale context no internal tool can. |
| Azure mcp-kubernetes | stdio Go | Cluster networking, not just cluster management — Cilium for policy and Hubble for flow observability alongside kubectl and Helm. Readonly mode and namespace allowlisting ship in the box. Distributed as a released binary the client runs as a stdio subprocess; container images are no longer published. |
| kubectl-mcp-server | stdio Python | In the CNCF Landscape, with 107 ecosystem tools reaching Cilium, Istio, cert-manager, KubeVirt and GitOps controllers. Non-destructive mode, secret masking and RBAC validation make it viable beyond a lab. Ships stdio, SSE and streamable-HTTP modes. |
| Terraform | Docker | The IaC standard gets an AI brain. Provider docs, modules, policies, and Stacks support from the Terraform Registry. |
| HashiCorp Vault | Docker | Natural language secrets operations. If your AI agent spots a hard-coded credential, Vault MCP can remediate it in the same conversation. |
CAT 05
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| Grafana | uvx Go | 75+ tools across Prometheus PromQL, Loki LogQL, alerting, incidents, OnCall, annotations, and panel rendering. |
| Prometheus | stdio Python | Direct PromQL without Grafana overhead. Instant and range queries, metric discovery, metadata, and scrape target health in 6 focused tools. |
| Datadog | Remote HTTP | Full-stack observability. Logs, metrics, traces, dashboards, network device monitoring, synthetics, LLM observability, and code security scanning. |
| Dynatrace | Remote HTTP | Davis AI-powered observability. Problems, root cause analysis, and security – all accessible via MCP. |
| New Relic | Remote HTTP | 35+ tools spanning APM, infrastructure, NRQL queries, alerts, and synthetics. Official. |
| Splunk (Official) | Remote HTTP | Splunk-supported and Cisco-owned, yet missing from the Cisco suite. generate_spl turns plain English into SPL — the single highest-leverage tool on this list, since SPL fluency is exactly the scarce skill the guide’s thesis is about. Served by Splunk itself on the management port, so it respects existing Splunk RBAC. |
| Kentik | stdio Go | Flow-level visibility to complement the metrics and traces already covered — plus DDoS alerting, BGP routing and synthetic monitoring. Strategically important: Infoblox announced its acquisition of Kentik in July 2026, so this data is headed behind the same MCP layer as the Infoblox DDI entry. |
| SuzieQ | uvx Python | Multi-vendor network state as queryable tables — interfaces, BGP, routes — normalized across platforms. Two tools, show and summarize, which is precisely the tight surface agents handle well. Talks to the SuzieQ REST API, so you need an endpoint and key. |
CAT 06
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| PagerDuty | stdio uvx | Official server. On-call schedules, escalation policies, event orchestration, incident workflows, and status pages. Read-only by default; write tools opt-in. |
| ServiceNow | stdio Python | ITSM lives at the intersection of both source of truth and incident management – incidents, change requests, and CMDB all in one server. |
CAT 07
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| NVD CVE | stdio Python | Direct access to the NIST National Vulnerability Database with CVSS scoring. Ask your agent whether a device has known critical CVEs before you touch it. |
| Vault Radar | Docker | AI-powered leaked secret discovery across GitHub, AWS, and Azure. |
| ⭐ Cisco ISE | stdio Python | Also listed in Cisco Suite – identity and posture are fundamentally security functions. Zero Trust enforcement through natural language. |
| ⭐ Palo Alto Prisma AIRS | stdio Python | An MCP security gateway for governing AI-agent and tool-call traffic – the control point that sits in front of every other server on this list. Centralized policy, inspection, and enforcement for what agents are allowed to call. |
| Zscaler (Official) | uvx Python | The reference implementation for the governance primitives this guide argues for. Read-only by default; unlocking any of the 148 write tools requires both a master switch and an explicit named allowlist, with the refusal logged at startup. Runs over stdio via uvx, with streamable-HTTP and SSE modes available. Also ships AWS Secrets Manager support so credentials never touch a manifest. |
| PAN-OS | stdio Python | Fills the gap between Prisma AIRS, which governs agent traffic, and the firewall policy an agent actually needs to reason about. Direct PAN-OS XML/REST access for rule audit and policy review. FastMCP-based, with an SSE mode for remote clients. |
| Fortinet FortiWeb / FortiManager | Embedded | The only entry where MCP is embedded in the product rather than bolted on beside it. FortiWeb 8.0 and FortiManager 8.0’s FortiAI framework point to where vendor MCP is heading — inside the platform, inheriting its auth model by default. |
CAT 08
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| GitHub | Docker Go | Issues, PRs, code search, Actions, and config-as-code workflows. Your network automation code lives here. Your AI agent should too. |
| GAIT | stdio Python | Git-based AI tracking and audit. Purpose-built for tracking AI-generated changes to infrastructure code – the governance layer VibeOps needs. |
| Red Hat Ansible Automation Platform | Remote HTTP | This guide opens by naming Ansible as the tool teams couldn’t staff — this is the answer to that. Deployed inside AAP itself as a pod on port 8448 over HTTPS, so agents trigger existing, already-approved job templates through established RBAC rather than reaching around it. A single mcp_allow_write_operations variable decides whether the AI tool gets read-only or read-write. Generally available and fully supported as of the June 2026 release, on AAP 2.6 and later. |
| Microsoft Graph | npx | OneDrive, SharePoint, Visio, Teams, and Exchange. Connects AI agents to the collaboration and document layer, including Visio network diagrams. |
CAT 09
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| ⭐ Wikipedia | stdio Python | The fastest path for an AI agent to ground itself in technology standards, protocol definitions, and vendor context. |
| RFC Lookup | npx | IETF RFC search and retrieval. When your agent needs to know exactly what an RFC says, it can look it up rather than hallucinate. |
| ⭐ Subnet Calculator | stdio Python | IPv4 and IPv6 CIDR subnet calculation. Simple, but the kind of precise utility that agents need to get right every single time. |
CAT 10
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| ⭐ Markmap | stdio Node | Hierarchical mind map generation from markdown. Feed it a complex multi-domain problem and watch the dependencies become visual. |
| Draw.io | npx | The ubiquitous enterprise diagramming tool gets MCP support. Network topology generation from natural language or live data. |
| UML MCP | stdio Python | 27+ diagram types via Kroki – nwdiag, rackdiag, packetdiag, C4, Mermaid, D2, Graphviz, ERD, BPMN, and more. Rack diagrams from AI? Yes. |
| Excalidraw | stdio Node | Streams hand-drawn-style architecture diagrams with smooth viewport control and interactive fullscreen editing. |
| Topolograph | — | Diagrams generated from live link-state data rather than from a prompt. OSPF/OSPFv3/IS-IS visualization with path calculation and failure prediction across Cisco, Juniper, Arista, Nokia, Mikrotik and Huawei — “what breaks if this link drops” answered visually. |
CAT 11
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| Packet Buddy | stdio Python | Deep pcap and pcapng analysis via tshark. AI-assisted packet capture analysis – describe what you’re seeing in the trace and let the agent find the anomaly. |
| Kubeshark | Remote HTTP Go | Kubernetes L4/L7 traffic analysis with eBPF-based TLS decryption. Capture, pcap export, snapshots, KFL filtering, and TCP/UDP flow stats. |
| Wireshark MCP | stdio Python | 51 tshark-backed tools, and unusually deep on the security side — credential scanning, port scans, DNS tunneling, beaconing, exfiltration and YARA. Turns a pcap from something only a specialist reads into something an agent can triage. Needs Wireshark with tshark on PATH. |
| SharkMCP | stdio Node | Live capture rather than file-only: start recording, execute the request, stop and analyze in one loop. Optional TLS decryption via SSLKEYLOGFILE closes the encrypted-traffic blind spot. |
CAT 12
| MCP Server | Transport | Why It’s Cool |
|---|---|---|
| IP Fabric (Official) | Embedded | Ships inside the appliance and is opt-in by default — an administrator has to deliberately turn it on. Queries run against a discovered snapshot, so answers are grounded in verified state rather than inferred. Compliance checks map to CIS, NIST, ISO 27001, PCI-DSS, HIPAA, NIS2 and DORA, and it ships a prompt library so teams don’t start from a blank page. |
| Forward Networks | — | 55+ tools for vendor-agnostic path tracing and semantic search across forwarding tables and ACLs, with every answer cited to the specific path, policy or config line that proves it. The citation model is what makes agent output auditable rather than merely plausible. |
| Batfish (Official) | stdio Python | Validation before deployment, with no device access required at all. 23 tools covering reachability, traceroute, ACL analysis, routing and BGP against a config snapshot — the safest possible place for an agent to test a change. FastMCP-based, run as python -m pybatfish.mcp. Marked beta. |
VibeOps emerged in early 2025, coined in the wake of Andrej Karpathy’s “vibe coding” – the practice of building software by describing intent to an AI in natural language and iterating in flow, rather than writing every line by hand. VibeOps extends that philosophy to the full operational lifecycle: infrastructure, deployment, monitoring, and incident response, all driven by intent rather than scripted procedure.
For network engineers, this framing names something that has been building for years. The shift from CLI to API was the first step. Ansible playbooks were another. What MCP enables is the final translation layer: from structured tool invocation to natural language intent, with AI handling the mapping between what you mean and what the toolchain needs to execute.
An engineer notices unusual traffic patterns and asks an AI agent to investigate. Here’s what happens; all in a single conversational exchange, without leaving the chat interface:
The agent inspects Kubernetes traffic at the packet level, identifying anomalous flows using eBPF-based TLS decryption.
Corroborates traffic anomalies with time-series data, running instant and range queries against the monitoring stack.
Validates external reachability and identifies exactly where in the path the issue originates.
Adds application-layer context to the network-layer investigation, correlating logs across the full stack.
Completes the loop – investigation and remediation documented automatically, no copy-pasting between systems.
The Itential team ran a FlowAI Hackathon where 17 AI agents tackled 167 missions based on real network and infrastructure problems – achieving a near 100% success rate. Every tool in that workflow has a production MCP server available today.
None of this works without trust, and trust in automation has always been earned incrementally. The right pattern for VibeOps adoption is the same as every prior automation wave: start read-only, build confidence, then extend to write operations within clearly governed policy boundaries. The MCP ecosystem supports this well.
The Itential MCP Server provides 65+ governed tools, connecting agent outputs to executable workflows with full auditability at enterprise scale.
GAIT – built specifically for this problem – tracks every AI-generated infrastructure change in Git, giving you a complete, reviewable audit trail.
Treat your AI agent like a junior engineer with root access – capable, but supervised. The governance primitives are here. Use them.
The network automation market is projected to reach $12.38 billion by 2030, growing at over 18% CAGR. The drivers are familiar: complexity, security requirements, multi-cloud proliferation, 5G edge expansion, and the persistent shortage of engineers who can manage all of it manually.
The industry spent the last decade building the automation primitives – APIs, SDKs, network orchestration platforms, source-of-truth systems. MCP is the universal adapter that makes those primitives accessible to AI agents operating in natural language. Anthropic has moved MCP into the Agentic AI Foundation under the Linux Foundation. Every major vendor has a server in development or production. The protocol has, by any reasonable measure, won.
The question for network and infrastructure teams in 2026 is not whether to engage with MCP and VibeOps, it’s how fast to move and with what governance model. The tools are here. The ecosystem is real. The vibes, as it turns out, are very good.
MCP (Model Context Protocol) servers are standardized interfaces that give AI agents governed access to real infrastructure tools, enabling natural language control over network devices, cloud platforms, observability stacks, and ITSM systems. As of September 2026, 78 production-ready MCP servers span every major layer of the network and infrastructure stack.
Most network MCP servers communicate via existing management interfaces – NETCONF, RESTCONF, REST APIs, or SSH-based CLI. The MCP server acts as a translation layer: it exposes structured tools to the AI agent, and underneath, it’s making the same API calls you’d make manually. If you can automate it with Python today, you can wrap it in an MCP server and give your AI agent access to it.
Ansible and Terraform require you to know what you want and write it out explicitly – playbooks, state files, variable definitions. VibeOps lets you describe intent in natural language and have the AI figure out the tool chain. It’s not a replacement for those tools; in many cases MCP servers sit on top of them. The difference is who does the translation between intent and execution – you, or the AI.
The two risks to think about most are blast radius and hallucination. An AI agent with write access to production can make changes at a speed and scale no human would attempt. Start read-only, gate write operations behind explicit flags, and use audit tools like GAIT to track every AI-generated change. Treat your AI agent like a junior engineer with root access – capable, but supervised.
See how Itential connects AI reasoning to governed execution across your entire infrastructure.