product image

RuleForge — Firewall Migration

$99/ month
14 day trial

Convert firewall configs across ASA, FTD, Palo Alto, FortiGate & Check Point

Every vendor’s migration tool is a one-way funnel into its own product. RuleForge converts any direction — 20 of them. Cisco FMT only into FTD, FortiConverter into FortiGate, SmartMove into Check Point; Expedition was end-of-lifed Jan 2025.

Features

  • Sources/targets: Cisco ASA (incl. multi-context), Cisco FTD, Palo Alto PAN-OS (with/without Panorama), FortiGate (incl. VDOMs), Check Point
  • Deep Analysis: every feature inventoried — nothing silently dropped
  • Full Mapping: review and edit the source→target map before anything converts
  • Convert: objects, groups, rules, NAT in all four shapes, interfaces/VLANs/port-channels, zones, routes
  • Round-trip verification: the generated config is re-parsed and diffed against the model
  • Two documents per job: Conversion Process Report and Final Migration Report with cut-over checklist

Server requirements

  • Linux x86-64; single static binary, runs on a laptop or a jump host
  • Measured: ~10 MB binary, ~10 MB RAM idle, SQLite file — no database server
  • Minimum: 1 vCPU, 1 GB RAM, 500 MB disk; RAM scales with config size
  • Dashboard 127.0.0.1:8428; fully offline — configs never leave the machine

Pro $99/mo: unlimited rules, all 20 directions, multi-tenant conversion, both reports, round-trip verification. Team $299/mo: everything, unlimited jobs, team use. 14-day trial.

Offline Ed25519 licence, no phone-home.

Whop sells paid licences only. Free (same engine, 50 rules per job): github.com/nizartuanku/ruleforge