FortiGate → PAN-OS Converter

Convert a FortiGate (FortiOS) rulebase — address/service objects, groups, security policies, and NAT — into Palo Alto PAN-OS set-CLI commands or a candidate-config XML fragment. Runs entirely in your browser; your configuration never leaves this page.
v1.13 ← All Tools
Step 1

Load FortiOS configuration

Upload a full or partial show / config backup. Parsed in memory only.
Drop your FortiOS config here
or click to browse — .conf, .txt, or any text export
Step 2

Map interfaces & zones → PAN-OS zones

FortiOS policies reference interfaces directly; PAN-OS matches on zones. For each FortiOS interface, set the target PAN-OS zone (used for rule from/to) and, optionally, the exact PAN-OS interface it migrates to (used to complete hide-NAT source translation). For a subinterface, tick trunk and add the VLAN tag — e.g. base ethernet1/9 + tag 10ethernet1/9.10. Interface is only needed where a policy does interface (hide) NAT; leave it blank otherwise.
Step 3

PAN-OS output & conversion report


    
Before you commit: This tool accelerates migration; it does not replace review. PAN-OS security rules match pre-NAT addresses but post-NAT zones — verify NAT-adjacent rules on a test device. Application-ID is set to any with the converted service; tighten to App-IDs where possible. Validated against a PA-850 test cluster is recommended before production push.