Fortinet black logo

Online Help

Supported versions and conversions

Supported versions and conversions

FortiConverter can translate configurations from the following vendors and models. Unless noted as an exception below, conversions only support IPv4 unicast policy.

If FortiConverter cannot properly translate some of the supported configurations listed from below table, please kindly contact our product support email alias fconvert_feedback@fortinet.com

Vendor Models Versions Convertible Objects
Alcatel-Lucent Brick ALSMS v9.x
  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set
Bluecoat SGOS

6.5.10

6.6.4.2

6.7.4

7.0

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy
CheckPoint

SmartCenter

NGFP1 (4.0) to NGX R80

  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • VPN communities (IPSec site-to-site)

VSX

Provider-1 NGX R65 to R80
Cisco ASA 7.x/8.x/9.x
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • Interface
  • IP Pools
  • Local Users & Groups
  • NAT (Central NAT)
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN

FWSM

3.x/4.x
IOS

10.x to 12.x

15.x

PIX

5.x/6.x/7.x/8.x

Firepower

6.x

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IPPools
  • Policies
  • Services & Service Groups
  • Static Routes
Nexus

5.2/6.x/7.x

FortiGate FortiOS FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device (We suggest to migrate to FortiOS 6.0 and above). However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.
  • For more details, please see "FortiGate configuration migration" section in the admin guide.
Huawei USG Series
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)
IBM PAM IPS Sensor
Juniper SSG/ISG ScreenOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones
SRX JunosOS 10.x to 18.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)
MX Juno OS 10.x to 12.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
McAfee Sidewinder 7.x, 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint Stonesoft 5.7 - 6.7
  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT
Palo Alto Networks PAN OS PAN-OS 1.x to 10.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN
  • Panorama
Snort IPS rules
SonicWall TZ Series NSA Series SonicOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN
Sophos

XG Series SFOS 17.0 - 17.5 MR3
  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy
  • NAT (XG supports traditional NAT merge and SG model supports central NAT mode only)

Cyberoam Cyberoam OS 10.6.3 onward

SG Series

6.6 to 7.0

Tipping Point IPS 4.5
  • Addresses & Address Groups
  • Policies
  • Services & Service Groups
Vytta VyOS 5.2 to 6.7
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
WatchGuard

Firebox Series

XTM Series

Fireware 11.3 to 12.6
  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes
  • IPSec VPN
  • NAT

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.
  • Bluecoat conversion supports FortiProxy mode which the generated CLI would be slightly different to FortiGate mode.

Supported versions and conversions

FortiConverter can translate configurations from the following vendors and models. Unless noted as an exception below, conversions only support IPv4 unicast policy.

If FortiConverter cannot properly translate some of the supported configurations listed from below table, please kindly contact our product support email alias fconvert_feedback@fortinet.com

Vendor Models Versions Convertible Objects
Alcatel-Lucent Brick ALSMS v9.x
  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set
Bluecoat SGOS

6.5.10

6.6.4.2

6.7.4

7.0

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy
CheckPoint

SmartCenter

NGFP1 (4.0) to NGX R80

  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • VPN communities (IPSec site-to-site)

VSX

Provider-1 NGX R65 to R80
Cisco ASA 7.x/8.x/9.x
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • Interface
  • IP Pools
  • Local Users & Groups
  • NAT (Central NAT)
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN

FWSM

3.x/4.x
IOS

10.x to 12.x

15.x

PIX

5.x/6.x/7.x/8.x

Firepower

6.x

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IPPools
  • Policies
  • Services & Service Groups
  • Static Routes
Nexus

5.2/6.x/7.x

FortiGate FortiOS FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device (We suggest to migrate to FortiOS 6.0 and above). However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.
  • For more details, please see "FortiGate configuration migration" section in the admin guide.
Huawei USG Series
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)
IBM PAM IPS Sensor
Juniper SSG/ISG ScreenOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones
SRX JunosOS 10.x to 18.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)
MX Juno OS 10.x to 12.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
McAfee Sidewinder 7.x, 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint Stonesoft 5.7 - 6.7
  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT
Palo Alto Networks PAN OS PAN-OS 1.x to 10.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN
  • Panorama
Snort IPS rules
SonicWall TZ Series NSA Series SonicOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN
Sophos

XG Series SFOS 17.0 - 17.5 MR3
  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy
  • NAT (XG supports traditional NAT merge and SG model supports central NAT mode only)

Cyberoam Cyberoam OS 10.6.3 onward

SG Series

6.6 to 7.0

Tipping Point IPS 4.5
  • Addresses & Address Groups
  • Policies
  • Services & Service Groups
Vytta VyOS 5.2 to 6.7
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
WatchGuard

Firebox Series

XTM Series

Fireware 11.3 to 12.6
  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes
  • IPSec VPN
  • NAT

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.
  • Bluecoat conversion supports FortiProxy mode which the generated CLI would be slightly different to FortiGate mode.