Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
carlos_cosmo
New Contributor

Wildcard Cisco to Fortinet

Hello,

I'm new here on the forum and I need some help...

I would like to know if my Wildcard bellow converting to Fortinet is correct?

 

10.128.80.224/0.63.13.31 -> 00000000.00111111.00001101.00011111 - Wildcard Cisco 10.128.80.224/255.192.242.224 ->11111111.11000000.11110010.11100000 - Wildcard Fortigate

 

 

3 REPLIES 3
lobstercreed
Valued Contributor

While I have never used a wildcard object (Cisco or FortiGate), after doing a quick search it seems you've got it.

 

https://forum.fortinet.com/tm.aspx?m=92514

 

https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-firewall/Object%20Configuration/Addr...

carlos_cosmo

To you better understand our challenge, We are moving an ACL from our old Cisco switch to a new Fortinet firewall. This is an example of some lines we´re triyng to move:

 

ACLs Old Cisco:

10.128.80.224 0.63.13.31 10.206.5.0 0.0.0.31  10.128.80.224 0.63.13.31 10.206.11.0 0.0.0.15  10.192.80.224 0.7.13.31 10.206.11.0 0.0.0.15 Even after we check for Official Guide (the link you provide) how to configure wildcard mask, I still have doubt, cause I'm not found an example that matches the wildcard we are using. Basically lobstercreed, I want help to understand the Fortinet´s wild mask standard. I want to know if this ACL address using IP/wildmask 10.128.80.224/0.63.13.31, will reflect the same configuration on Fortinet´s policy if I´ll configure 10.128.80.224/255.192.242.224.

lobstercreed

You're going to have to prove it to yourself then.  The guide says it will work, but you still doubt it. 

 

I don't have a network designed the way you're describing and I'm not interested in spending the time setting up a test for something I will probably never use.

 

You already have a network where you can test this, so I'd recommend doing as you've described which follows the guide exactly. I see no reason why it wouldn't work.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors