FortiConverter - Best Choice
Pros
- Audit existing rulesets from CheckPoint, Cisco, Juniper and other platforms
- Build migration rulesets to FortiGate
- Stages migration before actual cutover
- Reduces or eliminates obsolete and shadow rules
- Simple logic
Cons
- Programming or scripting skills are not needed but highly recommended
- Requires excellent command of REGEX
- Interface Mapping from complex topologies requires a deep understanding of FortiGate interface capabilities and scripting
Most Important Features
- Multi-platform migration support to FortiGate
- Easy to use interface for simple topologies
- Support migration to multiple VDOMs (virtual FortiGate FWs)
- Advance routing support (e.g. Policy-based routing, BGP, etc.)
- Enterprise centralized management
- Easy to script changes
Return on Investment
- Streamlined migrations successful on the first try
- Simple and fast cutover maintenance window
- Audit and tune existing rule base
- Quickly identify shadow rules
- Quickly identify rules with elevated access
Alternatives Considered
Palo Alto Networks Next-Generation Firewalls - PA Series, Cisco Firepower 4100 Series and Tufin Orchestration Suite
Other Software Used
Palo Alto Networks Next-Generation Firewalls - PA Series, Cisco ASA
