forti-code
A Claude Code plugin that manages FortiGate firewalls over SSH, with guardrails against mistakes.
Context
FortiGate firewalls are configured from the command line over SSH. It’s powerful but slippery: one wrong command can lock you out of the device or open a hole. forti-code is a plugin that makes that work safer, offering operations as controlled tools instead of raw commands.
The problem
Managing a firewall by hand has two risks. The first is technical: some commands can lock you out, like disabling admin SSH access, a factory reset or deleting the rules. The second is context: between sessions you lose track of what you’ve already done. I wanted a layer that handled both.
What I built
Operations are split into two groups. Read-only ones — status, interfaces, rules, logs, diagnostics, packet capture — can be run without fear, even across several devices. Changes — rules, address and service objects, firmware upgrades — all go through guardrails.
The guardrails are the heart of the project: dry run by default on every change, so you see what would happen before it happens; a configuration snapshot before every change, so you can roll back; and a filter on dangerous commands that blocks anything that would lock you out.
Technical choices
It’s written in TypeScript on Node.js and talks to FortiGates over SSH with
the ssh2 library. A registry keeps track of what each model can do —
hardware, firmware limits, supported features — so commands adapt to the device
instead of assuming they’re all the same. Session state is saved, so context
isn’t lost between uses.
Status
On hold for now, the code is on GitHub. Read-only operations and rule and object management work end to end.
Intended use
Meant for managing devices you own or are authorised to administer.