Skip to main content
FranFisc1
Visitor III
May 21, 2025
Solved

FortiConverter Cisco FTD Conversion - src / dst Interfaces missing in firewall policies

  • May 21, 2025
  • 3 replies
  • 914 views

Hello,

trying to convert a FTD policy to Fortigate using FC 7.2.0.

Some ACLs contain multiple source interfaces.
The converted policy imho seems to miss source interfaces.

This happens with FTD ACLs having multiple source interfaces as well.


example:

 

access-list CSM_FW_ACL_ remark rule-id 268444674: ACCESS POLICY: ACLFirePower - Mandatory access-list CSM_FW_ACL_ remark rule-id 268444674: L7 RULE: Inside_kms access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Verwaltung any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Bibo_Inside any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Inside any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc ServerNetz any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Netz_48 any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Netz_122_mgt any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Netz_64_streaming any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Netz_123_Drucker any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Netz57_Zeiterfassung any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Mobile_Prof60 any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc Mobil_Stud_61 any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc BiboKiosk any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674  access-list CSM_FW_ACL_ advanced permit tcp object-group-ifc BiboPC4 any object-group-ifc ServerNetz object rz-kms eq 1688 rule-id 268444674 

 is converted to:

 

config firewall policy  edit 10003   set name "Inside_kms"   set srcintf "Verwaltung"    set dstintf "ServerNetz"    set srcaddr "all"    set dstaddr "rz-kms"    set service "TCP-1688"    set schedule "always"   set logtraffic disable   set status enable   set action accept  next end

 

Is this a known bug or a restriction in FC 7.2.0 ?

Best answer by FranFisc1

Hello,

thanks for the answer and the link.
We had already reviewed the FC docs and pulled the LINA Config from the FTD system for conversion.
Meanwhile I have been in contact with Fortinet Engineers and it turned out as an FC issue.
The issue manifests in the resulting config if  "Combine policies generated by NAT merge" is enabled during conversion.

It will very likely be fixed in one of the next upcoming releases.

So my issue is solved.

Thanks

3 replies

Anthony_E
Staff
Staff
May 24, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
May 27, 2025

Hello,

 

To convert an FTD policy to FortiGate using FortiConverter 7.2.0, extract the LINA configuration from the FTD device using CLI commands and then use FortiConverter to convert the configuration. Note that only the LINA component is supported, not the SNORT IPS engine rules.

Could you please have a look at this document?: https://docs.fortinet.com/document/forticonverter/7.2.0/online-help/934353/cisco-conversions

 

 
Regards,
Anthony
Best Regards
FranFisc1
FranFisc1AuthorAnswer
Visitor III
May 27, 2025

Hello,

thanks for the answer and the link.
We had already reviewed the FC docs and pulled the LINA Config from the FTD system for conversion.
Meanwhile I have been in contact with Fortinet Engineers and it turned out as an FC issue.
The issue manifests in the resulting config if  "Combine policies generated by NAT merge" is enabled during conversion.

It will very likely be fixed in one of the next upcoming releases.

So my issue is solved.

Thanks

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.