Supported Vendors
NetConverter AI supports translation between multiple network vendors and device types. Each platform has a defined role: some are supported as both source and target, some are source-only, and some are destination-only.
Apples to apples with Expedition
Palo Alto Expedition’s published matrix is objects → PAN-OS only. We score the same cells. Live / Preview / Missing / Wont. Full write-up on compare.html.
| Expedition cell | Expedition | NetConverter |
|---|---|---|
| Check Point R80+ objects, security, NAT, L3, routes | Live | Live (zones still any) |
| Check Point R75/R77 | Live | Wont — we are R80+ API |
| Check Point VPN | — | Missing |
| Cisco ASA objects, security, NAT, L3, routes | Live | Live |
| Cisco ASA VPN | Live | Preview — not claimed translated |
| FirePower (ASA syntax) | Live | Beat: real FMC REST ingest. Emit Preview |
| FortiGate 4/5/6 | Live | Beat: FortiManager ingest. Forti→PA Preview |
| Juniper ScreenOS / Junos 11–12 | Live | Wont |
| Remove unused objects + export XML | Live | Preview (detect only) |
| Bulk apply SPG | Live | Missing |
| Rules containing a subnet | Live | Preview |
Collectors: netconverter-ai/netconverter-tools. Local Docker public repo is not live yet — the private appliance tree vendors the engine and will not be flipped public.
Firewalls
Translate firewall configurations between these vendors:
Cisco ASA
Convert Cisco ASA firewall configurations to other firewall platforms — ASA is a source platform; NetConverter does not generate ASA configs. Supports security rules, NAT policies, interfaces, and object groups.
Format: CLI configuration
Palo Alto Networks
Translate Palo Alto firewall configurations in both XML and CLI (Set) formats. Supports security policies, NAT rules, address objects, and application-based rules.
Formats: PAN-OS XML, PAN-OS CLI
Fortinet FortiGate
Convert FortiOS firewall configurations including security policies, NAT rules, address objects, and service groups. Supports both CLI and configuration file formats.
Format: FortiOS configuration
Check Point
Check Point is supported as a source platform via the Handoff Bundle: a SmartConsole export from the appliance is ingested as a snapshot, parsed, and extracted into the intermediate representation. Targets are the Palo Alto family. NetConverter does not generate Check Point output. Technical reference: Check Point → Palo Alto.
Role: Source-only, via Handoff Bundle
Switches
Translate switch configurations between these vendors:
Cisco
Convert Cisco Catalyst switch configurations (IOS-XE). Supports VLANs, trunking, port channels, STP, and Layer 3 features.
Platform: IOS-XE (Catalyst)
Juniper
Translate Juniper switch configurations in both configuration mode and display set formats. Supports VLANs, trunking, aggregated Ethernet, and Layer 3 interfaces.
Formats: JUNOS (Config Mode), JUNOS (Display Set)
Aruba
Convert Aruba switch configurations including both traditional ArubaOS (source-only) and modern Aruba CX (full bidirectional) platforms. Supports VLANs, trunking, and Layer 3 features.
Platforms: ArubaOS (source-only), Aruba CX (full)
Routers
Translate router configurations between these vendors:
Cisco IOS-XE
Convert Cisco router configurations including interfaces, routing protocols (OSPF, BGP, EIGRP), route maps, ACLs, and VRF configurations.
Platform: IOS-XE
Juniper JunOS
Translate Juniper router configurations in both configuration mode and display set formats. Supports routing protocols, firewall filters, and routing instances.
Formats: JUNOS (Config Mode), JUNOS (Display Set)
Aruba CX
Convert Aruba CX router configurations including BGP, OSPF, VRF, static routes, and ACLs. Supports full bidirectional translation with Cisco IOS-XE and Juniper JunOS.
Platform: Aruba CX
Translation Capabilities
NetConverter AI translates configurations across 12 platform formats within the same device type. Eleven of those paths have a published migration guide. For example:
- Firewall: Cisco ASA → Palo Alto ↔ Fortinet; Check Point → Palo Alto (source-only Handoff Bundle)
- Switch: Cisco ↔ Juniper ↔ Aruba
- Router: Cisco IOS-XE ↔ Juniper JunOS ↔ Aruba CX
Platform Roles
Direction matters. A platform NetConverter can read is not necessarily one it can write:
- Source and target: Palo Alto PAN-OS (set and XML), Panorama, Fortinet FortiGate, Cisco IOS-XE, Juniper JunOS, Aruba CX
- Source only: Cisco ASA, ArubaOS, Check Point (Handoff Bundle)
- Destination only: Cisco FMC (REST and CLI), Palo Alto Strata Cloud Manager (REST and CLI)
- Not supported: Juniper SRX (removed February 2026), Arista EOS (planned), FortiManager (coming soon)
Cisco FTD is not a source format. An FTD-managed estate migrates as ASA to FMC, and FMC manages the FTD devices.
Supported Features
NetConverter AI translates a wide range of configuration features including:
- Interfaces & Zones - Physical interfaces, sub-interfaces, security zones
- Address Objects - Hosts, networks, ranges, FQDNs
- Service Objects - TCP, UDP, ICMP services and service groups
- Security Rules - Firewall policies, ACLs, security rules
- NAT Policies - Source NAT, destination NAT, static NAT
- Routing - Static routes, OSPF, BGP, route maps
- Switching - VLANs, trunking, port channels, STP
- Layer 3 - SVIs, IRB interfaces, VRF configurations
Getting Started
To translate a configuration:
- Select your device type (Firewall, Switch, or Router)
- Choose your source vendor and OS format
- Select your target vendor and OS format
- Paste or upload your configuration
- Click convert to get your translated configuration
Management Platforms
NetConverter AI also supports centralized management platforms for enterprise deployments:
Palo Alto Panorama
Analyze and translate Panorama-managed firewall configurations. Supports device groups, templates, and shared objects across multiple firewalls.
Tool: Panorama Analyzer
Palo Alto Strata Cloud Manager (SCM)
Cloud-native migration target for Palo Alto environments. Translate configurations directly into SCM-ready format via REST API and CLI integration.
Type: Target + REST API + CLI
Cisco FMC
Migrate to Cisco Firepower Management Center (FMC) with direct REST API push (tested on FMC 7.6.5+) or reviewable CLI output. Supports managed devices, access control policies, and object management.
Type: Target + REST API push + CLI
FortiManager
FortiManager support is coming soon — analysis and translation of FortiManager policy packages. It is not available today.
Status: Coming Soon
Additional Tools
NetConverter AI provides additional tools to help with configuration management:
Configuration Validator
Validate network configurations before deployment. Check for syntax errors, security issues, and best practice violations across all supported vendors.
Tool: Config Validator
Configuration Optimizer
Analyze configurations for optimization opportunities, security improvements, and best practice recommendations. Get detailed reports on potential issues and improvements.
Tool: Config Optimizer
Need Custom Support?
If you need support for additional vendors, formats, or features, please contact us. We offer custom development services for enterprise customers.