How to Transfer all the rules and the configuration from Fortigate 200F to Meraki MX95

Momen-Kh
New here

How to Transfer all the rules and the configuration from Fortigate 200F to Meraki MX95

Hello, 

 

My upcoming project is to change all the company network from FortiGate Firewall and Aruba Switches/Aps to Cisco Meraki MX95 and MR36 APs.

 

Never worked on the Meraki so is there any way to transfer the full policies/rules/configuration from the Fortigate 200F to the new Meraki MX95? 

 

Thank you in advance.

3 REPLIES 3
alemabrahao
Kind of a big deal
Kind of a big deal

No, what you can do is analyze the Fortigate rules and create a Python script to apply the rules in MX.

 

https://developer.cisco.com/codeexchange/github/repo/CiscoSE/AddMerakiMXL3FirewallRuleToNetworks/

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Momen-Kh , I've undertaken this task previously and it was pretty labour intensive but gave us and the customer an opportunity to review their existing ruleset and perform a clean up operation.  Managed to reduce their ruleset significantly in the process and gave us a better understanding of their environment.

 

There are no toolsets available to ingest the Forti rules and output to the Meraki MX's.  API could be the way forward.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
PhilipDAth
Kind of a big deal
Kind of a big deal

What I tend to do for these ones (since they are so labour intensive), is go through all the rules to figure out which ones are no longer needed.  Disable them in advance.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.