Sign in Get started

Firewall migration / Scope first

Palo Alto PAN-OS
to Fortinet FortiGate

Prepare the source, review the translated configuration and validate the behavior that matters to your network. Start with the device, software version and features in scope.

Discuss this migration →Open the platform →

Account approval and feature support apply. A listed migration path does not certify every model, version or configuration.

Define the handoff

What goes in.
What you review.

Source inputs

A PAN-OS export scoped to the intended firewall/VSYS, with source version and the target FortiGate/VDOM requirements.

Target output

FortiOS output for supported scope, with configuration and behavior findings for review.

Path-specific boundaries

Application-based policy and security services do not have universal one-to-one equivalents. Review dependencies and conditional behavior before relying on the output.

Scope the review

Check the behavior,
not just the syntax.

REVIEW 01

Firewall, VSYS and inherited policy scope

Confirm the intended behavior, supported scope and target-platform requirements.

REVIEW 02

Zones, interfaces and VDOM mapping

Confirm the intended behavior, supported scope and target-platform requirements.

REVIEW 03

Application-dependent rules and services

Confirm the intended behavior, supported scope and target-platform requirements.

REVIEW 04

NAT order, routing and security profiles

Confirm the intended behavior, supported scope and target-platform requirements.

These are review areas, not a guarantee that every construct in them is automated. Unsupported features, missing captures and conditional behavior remain part of the engineering review.

See the current product

Explore the workflow.

View dated product captures and a clearly labeled synthetic verification example. A screenshot of an interface does not establish acceptance of this migration path.

See the product tour →

Understand your result

Read the findings and their limits alongside the output. Address blockers, validate device acceptance and test affected traffic before seeking deployment approval.

Read the result guide →

Plan the next step

Bring the details
that make your migration different.

Source and target models, software versions, critical features and the change window help establish a realistic scope.

Discuss your scope →Compare migration paths →