Operator tool on your LAN. Licensed deployments run as a React/Vite portal (Docker typically http://host:7443). Authentication, workspace profiles, and configs stay in the browser. Do not expose it to the public internet without TLS and extra access control. This page does not convert uploaded files.
# FGT Custom Converter — dry-run (illustration) source: FortiGate-100F.conf target: FortiGate-200F map port1 -> wan1 port2 -> internal x1 -> agg1 [ok] interface map complete [ok] FGCP hbdev uses mapped members [warn] VLAN 40 parent remapped; review SD-WAN members config system interface edit "wan1" set vdom "root" set mode static next end # Output stays on your LAN. This marketing page does not convert files.
FortiGate converter
Paste or upload a FortiGate backup, pick the target hardware model, map interfaces, then run a dry-run checklist before convert. Output is FortiOS CLI you can copy, download, diff, or hand off to the conversion checker.
Profiles & hardware maps
Save, duplicate, export, and import full converter presets (.fgt-profile.json). Target models drive port lists, VLAN parents, and aggregate names.
FGCP dual output
Primary/secondary hostname and priority, correct multi-interface hbdev syntax, and Primary / Secondary / Combined tabs with per-unit copy, download, and diff.
SD-WAN & LAG
Member selection with mapping-aware badges, live SD-WAN preview, bulk LAG from selected ports, and VLAN subinterfaces with CIDR-to-netmask conversion.
Pre-conversion validation
Modal dry-run for port conflicts, LAG members, FGCP checks, and SD-WAN compatibility before you generate CLI. Ctrl+Enter runs convert.
Migration suite
VDOM splitter
Split multi-VDOM backups into global plus per-VDOM files, optional secret redaction, ZIP download, and join selected pieces back into one .conf.
Check Point tools
Object/rule visualizer, HA bootstrap scripts, Excel-to-CSV comment merge, and bulk export of mapped addresses, services, zones, routes, and policies to FortiGate CLI.
Cisco parser
Draft FortiOS CLI from IOS-style snippets (interfaces, routes, ACLs, NAT hints). Output is marked for review — secrets are redacted; it is not paste-ready without an engineer pass.
Conversion checker & diff
Automatic handoff from converter output. Policy/interface/route checks plus side-by-side FortiOS-aware diff of original vs converted config.
Cutover and utilities
Cut-doc & CHANGE DB
Step-by-step cutover checklists from templates, plus device/change inventory (CHG) isolated per workspace profile.
FortiCGtool CLI
Spreadsheet-driven FortiGate and FortiSwitch CLI generation, missing-object finder, and CLI regeneration from a reference backup.
Join, randomize, subnet
Merge config snippets, sanitize configs for sharing (consistent IP remaps), and a subnet/route calculator with CIDR expand/aggregate.
Workspace & MFA
Role-based access, local TOTP, workspace profiles so engineers do not overwrite each other, and JSON backup/restore of the local workspace.
Windows, Linux, and native setup zips are produced from the product repo. Pair it with FGT Config Visualizer for audit/hardening, or FGT Monitoring & Backup for live ops after cutover.