Fortinet white logo
Fortinet white logo

online help

Supported vendors & configuration objects

Supported vendors & configuration objects

FortiConverter can translate configurations from the following vendors and models.

  • In some cases, FortiConverter can't translate some parts of the configuration because of dependencies or unsupported syntax and you must manually convert them.
  • If the number of objects exceeds the maximum valid length for FortiGate or FortiManager, FortiConverter trims them.
  • FortiConverter comes with two different applications, each capable of a different set of conversions. The Converter Application column shows which FortiConverter application to use for each conversion.

Unless noted as an exception below, conversions only support IPv4 unicast policy.

Vendor Models Versions Convertible Objects
Alcatel-Lucent Brick ALSMS v9.x
  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set
Bluecoat SGOS

6.5.10

6.7.4

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy
CheckPoint SmartCenter NGFP1 (4.0) to NGX R80
  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • VPN communities (IPSec site-to-site)
Provider-1 NGX R65 to R80
Cisco ASA 7.x/8.x/9.x
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • Interface
  • IP Pools
  • Local Users & Groups
  • NAT (Central NAT)
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN

FWSM

3.x/4.x
IOS

10.x to 12.x

15.x

PIX

5.x/6.x/7.x/8.x

Firepower

6.x

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IPPools
  • Policies
  • Services & Service Groups
  • Static Routes
Nexus

5.2/6.x/7.x

FortiGate FortiOS FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device (We suggest to migrate to FortiOS 6.0 and above). However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.
  • For more details, please see "FortiGate configuration migration" and "Reviewing errors after FortiGate import "sections in admin guide.
Huawei USG Series
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)
IBM PAM IPS Sensor
Juniper SSG/ISG ScreenOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones
SRX JunosOS 10.x to 18.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)
MX Juno OS 10.x to 12.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
McAfee Sidewinder 7.x, 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint Stonesoft 5.7
  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT
Palo Alto Networks PAN OS PAN-OS 1.x to 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN
  • Panorama
Snort IPS rules
SonicWall TZ Series NSA Series SonicOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN
Sophos XG Series SFOS 17.0
  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy
Cyberoam Cyberoam OS 10.6
Tipping Point IPS 4.5
  • Addresses & Address Groups
  • Policies
  • Services & Service Groups
Vytta VyOS 5.2 to 6.7
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
WatchGuard Firebox Series XTM Series Fireware 11.3 to 12.1
  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes
  • IPSec VPN
  • NAT

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.
  • Juniper (Junos only) can support converting the consolidated policy to FortiOS v6.2 configuration.

Supported vendors & configuration objects

Supported vendors & configuration objects

FortiConverter can translate configurations from the following vendors and models.

  • In some cases, FortiConverter can't translate some parts of the configuration because of dependencies or unsupported syntax and you must manually convert them.
  • If the number of objects exceeds the maximum valid length for FortiGate or FortiManager, FortiConverter trims them.
  • FortiConverter comes with two different applications, each capable of a different set of conversions. The Converter Application column shows which FortiConverter application to use for each conversion.

Unless noted as an exception below, conversions only support IPv4 unicast policy.

Vendor Models Versions Convertible Objects
Alcatel-Lucent Brick ALSMS v9.x
  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set
Bluecoat SGOS

6.5.10

6.7.4

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy
CheckPoint SmartCenter NGFP1 (4.0) to NGX R80
  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • VPN communities (IPSec site-to-site)
Provider-1 NGX R65 to R80
Cisco ASA 7.x/8.x/9.x
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • Interface
  • IP Pools
  • Local Users & Groups
  • NAT (Central NAT)
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN

FWSM

3.x/4.x
IOS

10.x to 12.x

15.x

PIX

5.x/6.x/7.x/8.x

Firepower

6.x

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IPPools
  • Policies
  • Services & Service Groups
  • Static Routes
Nexus

5.2/6.x/7.x

FortiGate FortiOS FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device (We suggest to migrate to FortiOS 6.0 and above). However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.
  • For more details, please see "FortiGate configuration migration" and "Reviewing errors after FortiGate import "sections in admin guide.
Huawei USG Series
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)
IBM PAM IPS Sensor
Juniper SSG/ISG ScreenOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones
SRX JunosOS 10.x to 18.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)
MX Juno OS 10.x to 12.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
McAfee Sidewinder 7.x, 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint Stonesoft 5.7
  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT
Palo Alto Networks PAN OS PAN-OS 1.x to 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN
  • Panorama
Snort IPS rules
SonicWall TZ Series NSA Series SonicOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN
Sophos XG Series SFOS 17.0
  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy
Cyberoam Cyberoam OS 10.6
Tipping Point IPS 4.5
  • Addresses & Address Groups
  • Policies
  • Services & Service Groups
Vytta VyOS 5.2 to 6.7
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
WatchGuard Firebox Series XTM Series Fireware 11.3 to 12.1
  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes
  • IPSec VPN
  • NAT

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.
  • Juniper (Junos only) can support converting the consolidated policy to FortiOS v6.2 configuration.