YueGuobin 0e6db9a7b6
fix: correct MCP transport security config to actually allow all hosts by default
The MCP library's TransportSecurityMiddleware only supports exact host
matches or "host:*" port wildcards. It does NOT support a standalone "*"
wildcard to mean "allow all hosts" — setting allowed_hosts=["*"] would
reject every connection because no Host header equals "*".

Worse, when transport_security=None was passed to FastMCP while its default
host is "127.0.0.1", FastMCP would auto-enable protection with strict
localhost-only rules, overriding GNS3's intent to allow all hosts.

Root cause analysis:
- FastMCP auto-enables DNS rebinding protection when host is localhost
  and no explicit TransportSecuritySettings is provided
- GNS3 was passing transport_security=None (indirectly via FastMCP's default)
  when protection was disabled, triggering the auto-enable
- The TransportSecuritySettings "allowed_hosts" list does NOT support "*"
  as a catch-all wildcard

This fix:
1. Always pass an explicit TransportSecuritySettings to FastMCP
   - Disabled: TransportSecuritySettings(enable_dns_rebinding_protection=False)
   - Enabled: TransportSecuritySettings(enable_dns_rebinding_protection=True, ...)
2. Restore mcp_allowed_hosts and mcp_allowed_origins config fields
3. Set mcp_enable_dns_rebinding_protection default to False (allow all hosts)

Behaviour:
- Default (no config change): all hosts can connect to MCP server
- With mcp_enable_dns_rebinding_protection=true: only configured hosts
- Aligns with GNS3 server's 0.0.0.0 binding policy
2026-06-05 23:20:57 +08:00
2022-10-02 23:25:58 -06:00
2015-06-18 16:33:24 +02:00
2026-05-25 18:07:50 +02:00
2026-05-13 00:34:05 +08:00
2025-03-08 14:08:42 +09:00
2016-06-15 19:11:26 +02:00
2022-12-20 21:28:46 +08:00

GNS3 server repository

Style GitHub Actions tests Latest PyPi version Snyk scanning

The GNS3 server manages emulators and other virtualization software such as Dynamips, Qemu/KVM, Docker, VPCS, VirtualBox and VMware Workstation. Clients like the GNS3 GUI and the GNS3 Web UI control the server using a HTTP REST API.

Installation

These instructions are for using GNS3, please see below for development.

Windows & macOS

Please use our Windows installer or DMG package to install the stable build along with the GNS3 VM. Note that as of GNS3 version above 3.0, you must run the server using the GNS3 VM or on a Linux system (remote, cloud or virtual machine).

Linux

Ubuntu based distributions

We build and test packages for actively supported Ubuntu versions. Other distros based on Ubuntu, like Mint, should also be supported.

Packages can be installed from our Personal Package Archives (PPA) repository:

sudo apt update
sudo apt install software-properties-common
sudo add-apt-repository ppa:gns3/ppa
sudo apt update                                
sudo apt install gns3-gui gns3-server

Other Linux distributions

GNS3 is often packaged for other distributions by third-parties:

PyPi

You may use PyPi in case no package is provided, or you would like to do a manual installation:

python3 -m pip install gns3-gui
python3 -m pip install gns3-server

Optional Features

GNS3 server supports optional features that can be installed as needed:

AI Copilot (Optional):

python3 -m pip install gns3-server[ai-copilot]

AI-powered assistant for network topology design and automation.

Development (For contributors):

python3 -m pip install gns3-server[dev]

Web Wireshark (Optional):

pip install gns3-server && gns3server-web-wireshark-setup

Browser-based packet capture analysis using Wireshark in a Docker container.

Combination Installation: You can install multiple optional features together:

python3 -m pip install gns3-server[ai-copilot,dev]

Why optional?

  • Reduces installation size for users who don't need specific features
  • Supports restricted environments (government, education, corporate) where certain libraries may not be allowed
  • Faster installation for basic GNS3 usage
  • Allows users to choose only the features they need

Note: If you install without optional extras, the server will work normally but optional features will be disabled. You can add features later by running the appropriate install command.

Uninstalling AI Copilot:

To remove AI Copilot dependencies:

gns3server-uninstall-ai-copilot

This will remove all AI Copilot dependencies while keeping the core functionality intact. The server will continue to work, but AI features will return a 501 (Not Implemented) status code.

The downside of this method is you will have to manually install all dependencies (see below).

Please see our documentation for more details.

Software dependencies

In addition to Python dependencies, other software may be required, recommended or optional.

  • uBridge is required, it interconnects the nodes.
  • Dynamips is required for running IOS routers (using real IOS images) as well as the internal switches and hubs.
  • VPCS is recommended, it is a builtin node simulating a very simple computer to perform connectivity tests using ping, traceroute etc.
  • Qemu is strongly recommended as most node types are based on Qemu, for example Cisco IOSv and Arista vEOS.
  • libvirt is recommended as it's needed for the NAT cloud.
  • Docker is optional, some nodes are based on Docker.
  • mtools is recommended to support data transfer to/from QEMU VMs using virtual disks.
  • i386-libraries of libc and libcrypto are optional, they are only needed to run IOU based nodes.

Note that Docker needs the script program (bsdutils or util-linux package), when running a Docker VM and a static busybox during installation (python3 setup.py install / pip3 install / package creation).

Development

Setting up

These commands will install the server with core Python dependencies:

git clone https://github.com/GNS3/gns3-server
cd gns3-server
git checkout 3.1
python3 -m venv venv-gns3server
source venv-gns3server/bin/activate
python3 -m pip install .
python3 -m gns3server

For AI Copilot development, install with additional dependencies:

python3 -m pip install .[ai-copilot,dev]

For development (tests and linting):

python3 -m pip install .[dev]

You will have to manually install other software dependencies (see above), for Dynamips, VPCS and uBridge the easiest is to install from our PPA.

Docker container

Alternatively, you can run the GNS3 server in a container

bash scripts/docker_dev_server.sh

use Docker Compose

docker compose up -d

Running tests

First, install the development dependencies:

python3 -m pip install -r dev-requirements.txt

Then run the tests using pytest:

python3 -m pytest -vv tests/

API documentation

The API documentation can be accessed when running the server locally:

  • On http://IP:PORT/docs to see with Swagger UI (i.e. http://localhost:3080/docs)
  • On http://IP:PORT/redoc to see with ReDoc (i.e. http://localhost:3080/redoc)

The documentation can also be viewed online however it may not be the most up-to-date version since it needs manually synchronization with the current code. Also, you cannot use this to interact with a GNS3 server.

Branches

master

master is the next stable release, you can test it in your day-to -day activities. Bug fixes or small improvements pull requests go here.

3.x development brand for the next major release.

Never use this branch for production. Pull requests for major new features go here.

Languages
JavaScript 54.9%
Python 44.4%
Shell 0.4%
HTML 0.3%