From BGP Threat Intel to Firewall Action with Cloudflare Radar + MCP

What happens when you combine Cloudflare Radar, MCP, firewall APIs, and a little bit of AI-assisted building?

I wanted to find out.

In this video, I walk through an application I built in roughly 20 minutes using Cloudflare Radar data, its MCP server, and Tines 3B.

The idea is simple: take rich Internet routing and security intelligence and make it operational.

Instead of finding a suspicious ASN and then manually researching every associated network, I can select the ASN, discover the networks behind it, review the security context, and move directly into a firewall workflow.

In one example, the application expands an ASN into 150 subnets and lets me select where I would want those networks blocked, including AWS WAF and Cisco Secure Firewall.

The firewall actions shown in this demo are mocked, but the underlying platforms expose APIs, which means this same workflow can be extended into real enforcement with the right approval and safety controls.

What You’ll See

:magnifying_glass_tilted_right: Cloudflare Radar data brought into a custom operational dashboard

:globe_with_meridians: ASN lookup and automatic network/subnet discovery

:shield: BGP hijack and route leak visibility

:bar_chart: Confidence-score filtering for security events

:fire: Turning an ASN into a potential firewall blocking workflow

:cloud: AWS WAF and Cisco Secure Firewall targets

:clipboard: Tracking and removing firewall rules

:eyes: Watching specific ASNs for new activity

:gear: Where alerting and automated response could fit next

:robot: Building the workflow with Tines 3B using plain English

Why This Matters

There is a lot of valuable network intelligence available to engineers, but intelligence by itself isn’t enough.

The interesting part is connecting:

Data → Context → Decision → Action

Cloudflare Radar can provide the visibility.

MCP gives us a way to expose that information to AI-assisted workflows.

Firewall APIs give us a potential enforcement point.

And platforms like Tines 3B make it possible to prototype the workflow around all of it surprisingly quickly.

The goal isn’t autonomous blocking without oversight. The opportunity is giving network and security engineers better context and a faster path from investigation to controlled action.

Technology Used

• Cloudflare Radar
• Cloudflare Radar MCP Server
• Tines 3B
• AWS WAF
• Cisco Secure Firewall
• APIs
• BGP / ASN routing intelligence

I’m going to keep building on this idea—adding more enrichment around ASNs and subnets, better context, alerting, and more controlled automation.

If you’re interested in practical AI, MCP, network automation, and what these tools actually look like when applied to NetOps and security operations, subscribe. There are more crazy ideas coming.

#NetworkAutomation #NetOps #Cloudflare #MCP #AIAgents #Tines #BGP #CyberSecurity #NetworkEngineering

4 Likes