Fortinet black logo

online help

Supported vendors and conversions

Supported vendors and conversions

FortiConverter can translate configurations from the following vendors and models. Unless noted as an exception below, conversions only support IPv4 unicast policy.

If FortiConverter cannot properly translate some of the supported configurations listed from below table, please kindly contact our product support email alias fconvert_feedback@fortinet.com.

Vendor Models Versions Convertible Objects
Alcatel-Lucent Brick ALSMS v9.x
  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set
Bluecoat SGOS

6.5.10

6.7.4

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy
CheckPoint SmartCenter NGFP1 (4.0) to NGX R80
  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • VPN communities (IPSec site-to-site)
Provider-1 NGX R65 to R80
Cisco ASA 7.x/8.x/9.x
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • Interface
  • IP Pools
  • Local Users & Groups
  • NAT (Central NAT)
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN

FWSM

3.x/4.x
IOS

10.x to 12.x

15.x

PIX

5.x/6.x/7.x/8.x

Firepower

6.x

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IPPools
  • Policies
  • Services & Service Groups
  • Static Routes
Nexus

5.2/6.x/7.x

FortiGate FortiOS FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device (We suggest to migrate to FortiOS 6.0 and above). However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.
  • For more details, please see "FortiGate configuration migration" and "Reviewing errors after FortiGate import "sections in admin guide.
Huawei USG Series
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)
IBM PAM IPS Sensor
Juniper SSG/ISG ScreenOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones
SRX JunosOS 10.x to 18.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)
MX Juno OS 10.x to 12.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
McAfee Sidewinder 7.x, 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint Stonesoft 5.7- 6.7
  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT
Palo Alto Networks PAN OS PAN-OS 1.x to 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN
  • Panorama
Snort IPS rules
SonicWall TZ Series NSA Series SonicOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN
Sophos XG Series SFOS 17.0 - 17.5 MR3
  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy
Cyberoam Cyberoam OS 10.6.3 onward
Tipping Point IPS 4.5
  • Addresses & Address Groups
  • Policies
  • Services & Service Groups
Vytta VyOS 5.2 to 6.7
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
WatchGuard

Firebox Series

XTM Series

Fireware

11.3 to 12.6

  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes
  • IPSec VPN
  • NAT

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.

Supported vendors and conversions

FortiConverter can translate configurations from the following vendors and models. Unless noted as an exception below, conversions only support IPv4 unicast policy.

If FortiConverter cannot properly translate some of the supported configurations listed from below table, please kindly contact our product support email alias fconvert_feedback@fortinet.com.

Vendor Models Versions Convertible Objects
Alcatel-Lucent Brick ALSMS v9.x
  • Interface (physical, logical, loopback, PPPoE)
  • Addresses & Address Books
  • Partitions
  • Services & Service Books
  • Static Routes
  • Zone rule set
Bluecoat SGOS

6.5.10

6.7.4

  • Addresses & Address Groups
  • Proxy Address (group)
  • Service
  • Proxy Policy
CheckPoint SmartCenter NGFP1 (4.0) to NGX R80
  • Interface
  • Addresses & Address Groups
  • Local Users & Groups
  • NAT
  • Negate Cell
  • Policies (rulebases.fws/*.csv)
  • RADIUS, TACACS+, LDAP
  • Rules (rulebases.fws/*.csv)
  • Schedules
  • Services & Service Groups
  • Static Routes
  • VPN communities (IPSec site-to-site)
Provider-1 NGX R65 to R80
Cisco ASA 7.x/8.x/9.x
  • ACLs
  • Addresses & Address Groups
  • DHCP Servers
  • DNS Servers
  • Interface
  • IP Pools
  • Local Users & Groups
  • NAT (Central NAT)
  • RADIUS, TACACS+, LDAP
  • Services & Service Groups
  • Static Routes
  • VPN

FWSM

3.x/4.x
IOS

10.x to 12.x

15.x

PIX

5.x/6.x/7.x/8.x

Firepower

6.x

IOS XR

4.x/5.x/6.x

  • Addresses & Address Groups & FQDNs
  • Interface
  • IPPools
  • Policies
  • Services & Service Groups
  • Static Routes
Nexus

5.2/6.x/7.x

FortiGate FortiOS FOS5.2 and above

FortiGate configuration can be converted based on the version of the target FortiGate device (We suggest to migrate to FortiOS 6.0 and above). However, note that

  • Older features might be deprecated and may not be fully converted over.
  • The review is necessary. After importing the converted configuration, any CLI commands that have not successfully imported can be reviewed on the page.
  • For more details, please see "FortiGate configuration migration" and "Reviewing errors after FortiGate import "sections in admin guide.
Huawei USG Series
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
  • Zone
  • IPSec Policy (VPN)
  • Security Context
  • Nat Policy (SNAT)
  • Nat Server (VIP)
IBM PAM IPS Sensor
Juniper SSG/ISG ScreenOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays Interfaces
  • Static Routes
  • Services & Service Groups
  • Policies
  • VIPs/MIPs
  • NAT
  • IP Pools
  • VPN
  • Local Users & Groups
  • RADIUS & LDAP
  • Zones
SRX JunosOS 10.x to 18.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Client & Relay
  • Interfaces
  • IP Pools
  • Local Users & Groups
  • NAT
  • Policies
  • RADIUS & LDAP
  • Services & Service Groups
  • Static Routes
  • VIPs/MIPs
  • VPN (IPSec site-to-site)
  • Zones
  • Routing-instances (virtual-router)
MX Juno OS 10.x to 12.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
McAfee Sidewinder 7.x, 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • IP Pools
  • Policies
  • Services & Service Groups
  • Static Routes
Forcepoint Stonesoft 5.7- 6.7
  • Addresses & Address Groups
  • Interfaces
  • Policies/ Sub-policy
  • Alias
  • Services & Service Groups
  • Static Routes
  • NAT
Palo Alto Networks PAN OS PAN-OS 1.x to 8.x
  • Addresses & Address Groups & FQDNs
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Static Routes
  • Services & Service Groups
  • Zones
  • VPN
  • Panorama
Snort IPS rules
SonicWall TZ Series NSA Series SonicOS 4.x, 5.x, 6.x
  • Addresses & Address Groups & FQDNs
  • DHCP Servers & Clients & Relays
  • Interfaces
  • Local Users & Groups
  • NAT
  • Policies
  • Schedules
  • Services & Service Groups
  • Static Routes
  • Zones
  • VPN (IPSEC site to site)
  • SSLVPN
Sophos XG Series SFOS 17.0 - 17.5 MR3
  • Interface
  • Zone
  • Addresses & Address Groups
  • Service & Service Groups
  • Users & User Groups
  • Policy
Cyberoam Cyberoam OS 10.6.3 onward
Tipping Point IPS 4.5
  • Addresses & Address Groups
  • Policies
  • Services & Service Groups
Vytta VyOS 5.2 to 6.7
  • Interface
  • Zone
  • Addresses & Address Groups
  • Services & Service Groups
  • Policy
  • Route
WatchGuard

Firebox Series

XTM Series

Fireware

11.3 to 12.6

  • Interfaces
  • Addresses & Address Groups
  • Services & Service Groups
  • Policies
  • Static Routes
  • IPSec VPN
  • NAT

Exception

  • Check Point to FGT conversion can support IPv4 multicast policy.
  • Check Point, Cisco, and Juniper (Junos only) to FGT conversion can support IPv6 unicast policy.