Fortinet white logo
Fortinet white logo

online help

Supported vendors & configuration objects

Supported vendors & configuration objects

FortiConverter can translate configurations from the following vendors and models.

  • In some cases, FortiConverter can't translate some parts of the configuration because of dependencies or unsupported syntax and you must manually convert them.
  • If the number of objects exceeds the maximum valid length for FortiGate or FortiManager, FortiConverter trims them.

Unless noted as an exception below, conversions only support IPv4 unicast policy.

Vendor

Models

Versions

Convertible Objects

Alcatel-Lucent

Brick

ALSMS v9.x

  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set

Bluecoat

SGOS

6.5.10

6.7.4

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy

CheckPoint

SmartCenter

NGFP1 (4.0)

to NGX R80

  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • VPN communities (IPSec site-to-site)

Provider-1

NGX R65 to R80

Cisco

ASA

7.x/8.x/9.x

  • Interface
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • DNS Servers Interfaces
  • IPPools Local Users & Groups
  • NAT
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN
  • SSLVPN (ASA only)

FWSM

3.x/4.x

IOS

10.x to 12.x

15.x

PIX

5.x/6.x/7.x/8.x

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes

Nexus

5.2/6.x/7.x

FortiGate

FortiOS

FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device (We suggest to migrate to FortiOS 6.0 and above).

However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.

Huawei

USG Series

  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)

Juniper

SSG/ISG

ScreenOS 4.x, 5.x, 6.x

  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones

SRX

JunosOS 10.x to 18.x

  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)

MX

Juno OS 10.x to 12.x

  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes

McAfee

Sidewinder

7.x, 8.x

  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint

Stonesoft

5.7

  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT

Palo Alto Networks

PAN OS

PAN-OS 1.x

to 8.x

  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN
  • Panorama

Snort

  • IPS rules

SonicWall

TZ Series NSA Series

SonicOS 4.x, 5.x, 6.x

  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN

Sophos

XG Series

SFOS 17.0

  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy

Cyberoam

Cyberoam OS

10.6

Tipping Point

IPS

4.5

  • Addresses & Address Groups
  • Policies
  • Services & Service Groups

Vytta

VyOS

5.2 to 6.7

  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route

WatchGuard

Firebox Series

XTM Series

Fireware 11.3 to 12.1

  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.
  • Juniper (Junos only) can support converting the consolidated policy to FortiOS v6.2 configuration.

Supported vendors & configuration objects

Supported vendors & configuration objects

FortiConverter can translate configurations from the following vendors and models.

  • In some cases, FortiConverter can't translate some parts of the configuration because of dependencies or unsupported syntax and you must manually convert them.
  • If the number of objects exceeds the maximum valid length for FortiGate or FortiManager, FortiConverter trims them.

Unless noted as an exception below, conversions only support IPv4 unicast policy.

Vendor

Models

Versions

Convertible Objects

Alcatel-Lucent

Brick

ALSMS v9.x

  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set

Bluecoat

SGOS

6.5.10

6.7.4

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy

CheckPoint

SmartCenter

NGFP1 (4.0)

to NGX R80

  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • VPN communities (IPSec site-to-site)

Provider-1

NGX R65 to R80

Cisco

ASA

7.x/8.x/9.x

  • Interface
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • DNS Servers Interfaces
  • IPPools Local Users & Groups
  • NAT
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN
  • SSLVPN (ASA only)

FWSM

3.x/4.x

IOS

10.x to 12.x

15.x

PIX

5.x/6.x/7.x/8.x

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes

Nexus

5.2/6.x/7.x

FortiGate

FortiOS

FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device (We suggest to migrate to FortiOS 6.0 and above).

However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.

Huawei

USG Series

  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)

Juniper

SSG/ISG

ScreenOS 4.x, 5.x, 6.x

  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones

SRX

JunosOS 10.x to 18.x

  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)

MX

Juno OS 10.x to 12.x

  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes

McAfee

Sidewinder

7.x, 8.x

  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint

Stonesoft

5.7

  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT

Palo Alto Networks

PAN OS

PAN-OS 1.x

to 8.x

  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN
  • Panorama

Snort

  • IPS rules

SonicWall

TZ Series NSA Series

SonicOS 4.x, 5.x, 6.x

  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN

Sophos

XG Series

SFOS 17.0

  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy

Cyberoam

Cyberoam OS

10.6

Tipping Point

IPS

4.5

  • Addresses & Address Groups
  • Policies
  • Services & Service Groups

Vytta

VyOS

5.2 to 6.7

  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route

WatchGuard

Firebox Series

XTM Series

Fireware 11.3 to 12.1

  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.
  • Juniper (Junos only) can support converting the consolidated policy to FortiOS v6.2 configuration.