Sign in Get started

Supported Vendors

NetConverter AI supports translation between multiple network vendors and device types. Each platform has a defined role: some are supported as both source and target, some are source-only, and some are destination-only.

Apples to apples with Expedition

Palo Alto Expedition’s published matrix is objects → PAN-OS only. We score the same cells. Live / Preview / Missing / Wont. Full write-up on compare.html.

Expedition cell Expedition NetConverter
Check Point R80+ objects, security, NAT, L3, routesLiveLive (zones still any)
Check Point R75/R77LiveWont — we are R80+ API
Check Point VPNMissing
Cisco ASA objects, security, NAT, L3, routesLiveLive
Cisco ASA VPNLivePreview — not claimed translated
FirePower (ASA syntax)LiveBeat: real FMC REST ingest. Emit Preview
FortiGate 4/5/6LiveBeat: FortiManager ingest. Forti→PA Preview
Juniper ScreenOS / Junos 11–12LiveWont
Remove unused objects + export XMLLivePreview (detect only)
Bulk apply SPGLiveMissing
Rules containing a subnetLivePreview

Collectors: netconverter-ai/netconverter-tools. Local Docker public repo is not live yet — the private appliance tree vendors the engine and will not be flipped public.

Firewalls

Translate firewall configurations between these vendors:

Cisco ASA

Convert Cisco ASA firewall configurations to other firewall platforms — ASA is a source platform; NetConverter does not generate ASA configs. Supports security rules, NAT policies, interfaces, and object groups.

Format: CLI configuration

Palo Alto Networks

Translate Palo Alto firewall configurations in both XML and CLI (Set) formats. Supports security policies, NAT rules, address objects, and application-based rules.

Formats: PAN-OS XML, PAN-OS CLI

Fortinet FortiGate

Convert FortiOS firewall configurations including security policies, NAT rules, address objects, and service groups. Supports both CLI and configuration file formats.

Format: FortiOS configuration

Check Point

Check Point is supported as a source platform via the Handoff Bundle: a SmartConsole export from the appliance is ingested as a snapshot, parsed, and extracted into the intermediate representation. Targets are the Palo Alto family. NetConverter does not generate Check Point output. Technical reference: Check Point → Palo Alto.

Role: Source-only, via Handoff Bundle

Switches

Translate switch configurations between these vendors:

Cisco

Convert Cisco Catalyst switch configurations (IOS-XE). Supports VLANs, trunking, port channels, STP, and Layer 3 features.

Platform: IOS-XE (Catalyst)

Juniper

Translate Juniper switch configurations in both configuration mode and display set formats. Supports VLANs, trunking, aggregated Ethernet, and Layer 3 interfaces.

Formats: JUNOS (Config Mode), JUNOS (Display Set)

Aruba

Convert Aruba switch configurations including both traditional ArubaOS (source-only) and modern Aruba CX (full bidirectional) platforms. Supports VLANs, trunking, and Layer 3 features.

Platforms: ArubaOS (source-only), Aruba CX (full)

Routers

Translate router configurations between these vendors:

Cisco IOS-XE

Convert Cisco router configurations including interfaces, routing protocols (OSPF, BGP, EIGRP), route maps, ACLs, and VRF configurations.

Platform: IOS-XE

Juniper JunOS

Translate Juniper router configurations in both configuration mode and display set formats. Supports routing protocols, firewall filters, and routing instances.

Formats: JUNOS (Config Mode), JUNOS (Display Set)

Aruba CX

Convert Aruba CX router configurations including BGP, OSPF, VRF, static routes, and ACLs. Supports full bidirectional translation with Cisco IOS-XE and Juniper JunOS.

Platform: Aruba CX

Translation Capabilities

NetConverter AI translates configurations across 12 platform formats within the same device type. Eleven of those paths have a published migration guide. For example:

  • Firewall: Cisco ASA → Palo Alto ↔ Fortinet; Check Point → Palo Alto (source-only Handoff Bundle)
  • Switch: Cisco ↔ Juniper ↔ Aruba
  • Router: Cisco IOS-XE ↔ Juniper JunOS ↔ Aruba CX

Platform Roles

Direction matters. A platform NetConverter can read is not necessarily one it can write:

  • Source and target: Palo Alto PAN-OS (set and XML), Panorama, Fortinet FortiGate, Cisco IOS-XE, Juniper JunOS, Aruba CX
  • Source only: Cisco ASA, ArubaOS, Check Point (Handoff Bundle)
  • Destination only: Cisco FMC (REST and CLI), Palo Alto Strata Cloud Manager (REST and CLI)
  • Not supported: Juniper SRX (removed February 2026), Arista EOS (planned), FortiManager (coming soon)

Cisco FTD is not a source format. An FTD-managed estate migrates as ASA to FMC, and FMC manages the FTD devices.

Supported Features

NetConverter AI translates a wide range of configuration features including:

  • Interfaces & Zones - Physical interfaces, sub-interfaces, security zones
  • Address Objects - Hosts, networks, ranges, FQDNs
  • Service Objects - TCP, UDP, ICMP services and service groups
  • Security Rules - Firewall policies, ACLs, security rules
  • NAT Policies - Source NAT, destination NAT, static NAT
  • Routing - Static routes, OSPF, BGP, route maps
  • Switching - VLANs, trunking, port channels, STP
  • Layer 3 - SVIs, IRB interfaces, VRF configurations

Getting Started

To translate a configuration:

  1. Select your device type (Firewall, Switch, or Router)
  2. Choose your source vendor and OS format
  3. Select your target vendor and OS format
  4. Paste or upload your configuration
  5. Click convert to get your translated configuration
Try It Now: Use our Quick Convert tool to translate your first configuration.

Management Platforms

NetConverter AI also supports centralized management platforms for enterprise deployments:

Palo Alto Panorama

Analyze and translate Panorama-managed firewall configurations. Supports device groups, templates, and shared objects across multiple firewalls.

Tool: Panorama Analyzer

Palo Alto Strata Cloud Manager (SCM)

Cloud-native migration target for Palo Alto environments. Translate configurations directly into SCM-ready format via REST API and CLI integration.

Type: Target + REST API + CLI

Cisco FMC

Migrate to Cisco Firepower Management Center (FMC) with direct REST API push (tested on FMC 7.6.5+) or reviewable CLI output. Supports managed devices, access control policies, and object management.

Type: Target + REST API push + CLI

FortiManager

FortiManager support is coming soon — analysis and translation of FortiManager policy packages. It is not available today.

Status: Coming Soon

Additional Tools

NetConverter AI provides additional tools to help with configuration management:

Configuration Validator

Validate network configurations before deployment. Check for syntax errors, security issues, and best practice violations across all supported vendors.

Tool: Config Validator

Configuration Optimizer

Analyze configurations for optimization opportunities, security improvements, and best practice recommendations. Get detailed reports on potential issues and improvements.

Tool: Config Optimizer

Need Custom Support?

If you need support for additional vendors, formats, or features, please contact us. We offer custom development services for enterprise customers.