Hot!Export Fortigate 300d Rules

Page: 12 > Showing page 1 of 2
Author
Azuriste
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/07/20 00:37:57
  • Status: offline
2018/07/20 05:51:05 (permalink)
0

Export Fortigate 300d Rules

Hello Guys ,
I need someone show me how can i do Export rules from Fortigate 300d to Excel Sheet  .We dont have a Fortimanager to do this export .
Any idea please ?
 
Regards
#1
ahmedsf
New Member
  • Total Posts : 20
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/12/24 03:00:02
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/22 01:46:31 (permalink)
0
Hi,
 
Use the CLI, run the configuration, copy the configuration and paste it in notepad. You can then take out the rules from the configuration and save it in Excel sheet.
 
Regards,
#2
Elthon Abreu
Bronze Member
  • Total Posts : 29
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/04/29 11:37:55
  • Location: Brazil
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/22 10:42:23 (permalink)

Elthon Abreu
FCNSA v5
#3
Nicholas Doropoulos
Silver Member
  • Total Posts : 72
  • Scores: 2
  • Reward points: 0
  • Joined: 2018/05/03 13:49:11
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/22 13:44:41 (permalink)
0
Hi,
 
Unfortunately, Fortinet has not made available a way to achieve the intended result seamlessly as of yet. What you can do is the following:
 
1) Open an ssh session to the Fortigate via Putty and enable logging of the session's output by following the kb article below:
 
http://kb.fortinet.com/kb/documentLink.do?externalID=FD36043
 
2) The, type the following commands:
 
config firewall policy 
show
 
3) Your firewall policies should now be included in the session's log you have created in step 1. Copy and paste the contents onto a spreadsheet.
 
Thanks.

NSE5, NSE 4, CCSA, CCNA R&S, CompTIA A+, CompTIA Network+, CompTIA Security+, MTA Security, ITIL v3
#4
Azuriste
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/07/20 00:37:57
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/25 01:36:08 (permalink)
0
Hello ,
Thanks to All .
I tried the Script http://firewallguru.blogs...-rules-to-csv.html?m=1 but it's not supporting  if i have a huge rules data  .it was working for the few entries but in my case i have more than 1500 rules .
 
Any Help please ?
 
Regards
#5
Elthon Abreu
Bronze Member
  • Total Posts : 29
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/04/29 11:37:55
  • Location: Brazil
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/25 07:19:59 (permalink)
0
Hi,
 
Have you thought about segmenting your rules in small blocks at a time?
 
Then you can export all rules to excel and merge all of them.
 
BR,

Elthon Abreu
FCNSA v5
#6
Azuriste
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/07/20 00:37:57
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/25 07:22:51 (permalink)
0
I can do this but i manage many firewalls .So i'm looking for an express procedure :)
 
Thanks
#7
Elthon Abreu
Bronze Member
  • Total Posts : 29
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/04/29 11:37:55
  • Location: Brazil
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/25 10:04:05 (permalink)
0
Express procedure = FortiManager  :)

Elthon Abreu
FCNSA v5
#8
Dave Hall
Expert Member
  • Total Posts : 1243
  • Scores: 116
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/25 10:41:49 (permalink)
0
If you plan to use that perl script - keep in mind that you can save an unencrypted fgt configuration file then open it in a text/word processor that understands unix/linux line feed only text files.  After this, just look for the firewall policy rule section and copy/paste that into smaller chucks that can be properly parsed by that perl script.
 
Edit: is there some grand design that you need to have the firewall rules parsed/converted?
post edited by Dave Hall - 2018/07/25 10:43:17

FMG-VM64/FortiAnalyzer-VM/4.0/5.0/5.2/5.4 (FWF40C/FW92D/FGT200B/FGT200D) / FAP220B/221C
#9
emnoc
Expert Member
  • Total Posts : 4942
  • Scores: 306
  • Reward points: 0
  • Joined: 2008/03/20 13:30:33
  • Location: AUSTIN TX AREA
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/25 11:31:15 (permalink)
0
It would be nice to export the rule set via xml or csv format directly from the firewall.
Ken

PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
#10
Azuriste
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/07/20 00:37:57
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/26 00:26:27 (permalink)
0
Hi ,
Could i use Fortimanager to export rules with trial version ?
 
Regards
#11
brudy
New Member
  • Total Posts : 9
  • Scores: 2
  • Reward points: 0
  • Joined: 2011/12/03 11:26:16
  • Location: Switzerland
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/26 22:26:04 (permalink)
4 (2)
I wrote a perl script for my customers which need it do document the firewall policies.
 
Maybe it helps: 
 
https://www.brg.ch/dump-fortigate-config-into-csv/
 
Just use the saved config as input. 
 
#12
TuncayBAS
Gold Member
  • Total Posts : 205
  • Scores: 14
  • Reward points: 0
  • Joined: 2005/07/01 03:17:46
  • Location: Ankara / Turkey
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/27 00:10:49 (permalink)
0
Full Config Export. One or multi device export
 
http://www.tuncaybas.com/...ortigate-policy-export

Tuncay BAS
RZK Muhendislik Turkey
NSE 4 5 6
FCESP v5
#13
Azuriste
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/07/20 00:37:57
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/27 00:42:41 (permalink)
0
@brudy : i tried your script but it's not working :(
when i execute the script i show just an appeared window showing the content of the script !
 
Regards ,
#14
Azuriste
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/07/20 00:37:57
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/27 00:44:12 (permalink)
0
@Tuncay : the Tools not working form me also !
 
TuncayBAS
New
Gold Member 

Total Posts : 205Scores: 14Reward points: 0Joined: 7/1/2005Location: Ankara / TurkeyStatus: online

Re: Export Fortigate 300d Rules 32 minutes ago (permalink)

 
 
0
Full Config Export. One or multi device export
 
http://www.tuncaybas.com/...ortigate-policy-export

 
Tuncay BAS
RZK Muhendislik Turkey
NSE 4 5 6
FCESP v5
Answer Helpful Report AbuseForward  Quote   #13

AzuristeNew
New Member 

Total Posts : 5Scores: 0Reward points: 0Joined: 1 week agoStatus: online

Re: Export Fortigate 300d Rules seconds ago (permalink)

 
 
0
@brudy : i tried your script but it's not working :(
when i execute the script i show just an appeared window showing the content of the script !
 
Regards ,

 
Forward  Managei  Edit   #14




 
Azuriste
Quick Reply: (Open Full Version)        Paragraph Font Family Font Size                 
Path: p
 
 
Submit Post

 
 

Home » All Forums » [Other FortiGate and FortiOS Topics] » Firewall » Export Fortigate 300d Rules
Jump to:  Jump to - - - - - - - - - -  [FortiGate / FortiOS UTM features] - - - - AntiVirus - - - - Application Control - - - - Data Leak Prevention (DLP) - - - - Email filtering (AntiSPAM) - - - - Former Content Management Forum - - - - Intrusion Detection & Prevention - - - - Web Filtering [Fortinet Beta Programs] - - - - Beta Message Board [Fortinet Services] - - - - FortiCloud IOC [Other FortiGate and FortiOS Topics] - - - - Firewall  - - - - Log & Report - - - - Miscellaneous -- FortiOS and FortiGate - - - - New Features -- FortiOS - - - - Routing and Transparent Mode - - - - System settings - - - - User and Authentication - - - - VPN [Other Fortinet Products] - - - - AscenLink - - - - Coyote Point - - - - FortiADC - - - - FortiAnalyzer - - - - FortiAP - - - - FortiAuthenticator - - - - FortiBalancer - - - - FortiBridge - - - - FortiCache - - - - FortiCamera & FortiRecorder - - - - FortiCarrier  - - - - FortiCASB - - - - FortiClient - - - - FortiCloud - - - - FortiConnect - - - - FortiController - - - - FortiConverter - - - - FortiCore - - - - FortiDB - - - - FortiDDOS - - - - FortiDirector - - - - FortiDNS - - - - FortiExplorer - - - - FortiExtender - - - - FortiFone - - - - FortiGuard - - - - FortiHypervisor - - - - FortiMail - - - - FortiManager - - - - FortiMonitor - - - -  Fortinet Security Fabric - - - - FortiPlanner - - - - FortiPortal - - - - FortiPresence - - - - FortiProxy - - - - FortiRPS - - - - FortiSandbox - - - - FortiScan - - - - FortiSIEM - - - - FortiSwitch - - - - FortiTester - - - - FortiToken - - - - FortiTap - - - - FortiVoice - - - - FortiWAN - - - - FortiWeb - - - - FortiWiFi - - - - Wireless Infrastructure (FortiWLC, FortiWLM, Meru) [Forum Information & Miscellaneous Topics] - - - - Forum News - - - - Ideas for Forum Site - - - - Fortinet Cookbook - - - - Knowledge Base - - - - Technical -- non-FortiOS - - - - Miscellaneous -- non-technical 


 
 
© 2018 APG vNext Commercial Version 5.5
 


Latest Posts   
Re: Block mails from special domain Re: fortinet authentication page Re: Export Fortigate 300d Rules Re: How to assign a fixed ip address from gui Re: FortiAP FAP-221E FortiAnalyser Traffic Shaping Report Re: FortiOS 6.0.2 is out! Re: Export Fortigate 300d Rules FortiOS 6.0.2 is out! Setup IPSec VPN with other brand firewall 

Active Posts   
fortinet authentication page Export Fortigate 300d Rules How to assign a fixed ip address from gui Change public IP for IPSec connection FortiSwitch 124E-POE Stability and Function ssl vpn portal login with Error:Permission denied Tunnel Failover Question Juniper to Fortigate BGP FortiGate 1000D -Reboots after 5 s Help with error "...may be caused by a mismatch in the TLS version. ..." 

All FAQs   
There is no record available at this moment



TuncayBAS
#15
brudy
New Member
  • Total Posts : 9
  • Scores: 2
  • Reward points: 0
  • Joined: 2011/12/03 11:26:16
  • Location: Switzerland
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/27 02:20:34 (permalink)
0
Hi Azuriste
 
If you are running it on Windows, you have to install Perl first to make it work. I recommend ActivePerl https://www.activestate.com/activeperl/downloads
#16
Aigarz
Bronze Member
  • Total Posts : 22
  • Scores: 0
  • Reward points: 0
  • Joined: 2012/06/13 12:23:53
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/27 04:42:48 (permalink)
0
brudy - you are a legend, 'give this man a cookie' 
best thing you get all the object details within the same output.
 
 
#17
Azuriste
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/07/20 00:37:57
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/27 06:04:17 (permalink)
0
Hi , 
 
I have Perl on Windows and i tested for some scripts and its working .the problem i got the output file without any data !
 
Should i do the test in Linux Env ?
 
Regards,
#18
Azuriste
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/07/20 00:37:57
  • Status: offline
Re: Export Fortigate 300d Rules 2018/07/27 08:05:58 (permalink)
0
Finally it's working .
the brudy Script it's verry goood script .i advice eveery one  to use it.
 
Thank's a lot brudy
#19
rwpatterson
Expert Member
  • Total Posts : 8259
  • Scores: 177
  • Reward points: 0
  • Joined: 2006/08/08 10:08:18
  • Location: Long Island, New York, USA
  • Status: online
Re: Export Fortigate 300d Rules 2018/08/06 12:51:36 (permalink)
0
With Peter's blessing, I have created an online version of his script. So far it only converts the policy list into a text format. More to come.
 
Bob
 
fortinet.camerabob.com/config.cgi

-Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

-4.3.19-b0694
FWF60B
FWF80CM (4)
FWF81CM (2)
 
#20
Page: 12 > Showing page 1 of 2
Jump to:
© 2018 APG vNext Commercial Version 5.5