Convert a FortiGate (FortiOS) rulebase — address/service objects, groups, security policies, and NAT — into Palo Alto PAN-OS set-CLI commands or a candidate-config XML fragment. Runs entirely in your browser; your configuration never leaves this page.
Upload a full or partial show / config backup. Parsed in memory only.
Drop your FortiOS config here
or click to browse — .conf, .txt, or any text export
Step 2
Map interfaces & zones → PAN-OS zones
FortiOS policies reference interfaces directly; PAN-OS matches on zones. For each FortiOS interface, set the target PAN-OS zone (used for rule from/to) and, optionally, the exact PAN-OS interface it migrates to (used to complete hide-NAT source translation). For a subinterface, tick trunk and add the VLAN tag — e.g. base ethernet1/9 + tag 10 → ethernet1/9.10. Interface is only needed where a policy does interface (hide) NAT; leave it blank otherwise.
Step 3
PAN-OS output & conversion report
PAN-OS candidate-config fragment. Import with load config partial (merge into vsys1) — the exact xpath is in the header comment. Version-sensitive; validate on your target PAN-OS release.
Every item below is something a reviewer should verify against the source — approximations, unmapped references, and constructs PAN-OS models differently. Nothing here blocks the output; it tells you where to look.
Before you commit: This tool accelerates migration; it does not replace review. PAN-OS security rules match pre-NAT addresses but post-NAT zones — verify NAT-adjacent rules on a test device. Application-ID is set to any with the converted service; tighten to App-IDs where possible. Validated against a PA-850 test cluster is recommended before production push.