Fortinet black logo

Online Help

Supported versions and conversions

Supported versions and conversions

FortiConverter can translate configurations from the following vendors and models. Unless noted as an exception below, conversions only support IPv4 unicast policy.

If FortiConverter cannot properly translate some of the supported configurations listed from below table, please kindly contact our product support email alias fconvert_feedback@fortinet.com

Vendor Models Versions Convertible Objects
Alcatel-Lucent Brick ALSMS v9.x
  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set
Bluecoat SGOS

6.5.10

6.6.4.2

6.7.4

7.0

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy
CheckPoint

SmartCenter

NGX R65 onward

  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Traditional IPSec sito-to-site VPN (Support only before R80.10)
  • Simplified IPSec sito-to-site VPN

VSX

Provider-1
Cisco ASA 7.x onward
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • Interface
  • IP Pools
  • Local Users & Groups
  • NAT (Central NAT)
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN

FWSM

3.x onward
IOS

10.x to 12.x

15.x

PIX

5.x onward

FTD (LINA)

6.x onward

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IPPools
  • Policies
  • Services & Service Groups
  • Static Routes
Nexus

5.2/6.x/7.x

FortiGate FortiOS FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device. However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.
  • For more details, please see "FortiGate configuration migration" section in the admin guide.
Huawei USG Series
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)
IBM PAM IPS Sensor
Juniper SSG/ISG ScreenOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones
SRX JunOS 10.x onward
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)
MX Juno OS 10.x to 12.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint Sidewinder 7.x onward
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
  • NAT (Policy NAT only)
Stonesoft 5.7 onward
  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT
Palo Alto Networks PAN OS PAN-OS 1.x onward
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN (GlobalProtect VPN not supported)
  • Panorama
Snort IPS rules
SonicWall TZ Series NSA Series SonicOS 4.x onward
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN
Sophos

XG Series SFOS 17.0 - 17.5 MR3
  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy
  • NAT (XG supports traditional NAT merge and SG model supports central NAT mode only)

Cyberoam Cyberoam OS 10.6.3 onward

SG Series

6.6 onward

Tipping Point IPS 4.5
  • Addresses & Address Groups
  • Policies
  • Services & Service Groups
Vytta VyOS 5.2 to 6.7
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
WatchGuard

Firebox Series

XTM Series

Fireware 11.3 onward
  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes
  • IPSec VPN
  • NAT

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.
  • Bluecoat conversion supports FortiProxy mode which the generated CLI would be slightly different to FortiGate mode.

Supported versions and conversions

FortiConverter can translate configurations from the following vendors and models. Unless noted as an exception below, conversions only support IPv4 unicast policy.

If FortiConverter cannot properly translate some of the supported configurations listed from below table, please kindly contact our product support email alias fconvert_feedback@fortinet.com

Vendor Models Versions Convertible Objects
Alcatel-Lucent Brick ALSMS v9.x
  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set
Bluecoat SGOS

6.5.10

6.6.4.2

6.7.4

7.0

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy
CheckPoint

SmartCenter

NGX R65 onward

  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Traditional IPSec sito-to-site VPN (Support only before R80.10)
  • Simplified IPSec sito-to-site VPN

VSX

Provider-1
Cisco ASA 7.x onward
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • Interface
  • IP Pools
  • Local Users & Groups
  • NAT (Central NAT)
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN

FWSM

3.x onward
IOS

10.x to 12.x

15.x

PIX

5.x onward

FTD (LINA)

6.x onward

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IPPools
  • Policies
  • Services & Service Groups
  • Static Routes
Nexus

5.2/6.x/7.x

FortiGate FortiOS FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device. However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.
  • For more details, please see "FortiGate configuration migration" section in the admin guide.
Huawei USG Series
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)
IBM PAM IPS Sensor
Juniper SSG/ISG ScreenOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones
SRX JunOS 10.x onward
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)
MX Juno OS 10.x to 12.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint Sidewinder 7.x onward
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
  • NAT (Policy NAT only)
Stonesoft 5.7 onward
  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT
Palo Alto Networks PAN OS PAN-OS 1.x onward
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN (GlobalProtect VPN not supported)
  • Panorama
Snort IPS rules
SonicWall TZ Series NSA Series SonicOS 4.x onward
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN
Sophos

XG Series SFOS 17.0 - 17.5 MR3
  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy
  • NAT (XG supports traditional NAT merge and SG model supports central NAT mode only)

Cyberoam Cyberoam OS 10.6.3 onward

SG Series

6.6 onward

Tipping Point IPS 4.5
  • Addresses & Address Groups
  • Policies
  • Services & Service Groups
Vytta VyOS 5.2 to 6.7
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
WatchGuard

Firebox Series

XTM Series

Fireware 11.3 onward
  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes
  • IPSec VPN
  • NAT

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.
  • Bluecoat conversion supports FortiProxy mode which the generated CLI would be slightly different to FortiGate mode.