Audit firewall matrices.
Generate clean FortiGate CLI.
Validate XLSX or CSV firewall rules, detect risky mistakes, compare an existing configuration, and generate review-ready FortiGate CLI locally in your browser.
Compare with an existing FortiGate configuration
Load a FortiOS .conf backup to reuse matching address/service objects and flag name conflicts. The file is parsed locally in your browser.
FortiGate inventory
Imported rules
| Status | Row | Name | Source | Destination | Protocol | Port | Src Intf | Dst Intf | Action |
|---|
Findings
Configuration summary
FortiGate CLI preview
Deployment safety: DeepCodeAgent does not connect to or modify your FortiGate. Review object names, interfaces, policy IDs, policy order, NAT, security profiles and all generated commands before deployment. A configuration can change after a backup is exported, so re-check the target firewall before applying a delta or rollback.
From Excel firewall matrix to review-ready FortiGate CLI
DeepCodeAgent is a browser-based firewall matrix auditor and FortiGate policy generator. Import a CSV or Excel matrix containing source, destination, protocol, port, source interface, destination interface and action. The tool validates each row before generating address objects, custom services and IPv4 firewall policies.
If you also load a plain-text FortiOS configuration backup, DeepCodeAgent can reuse matching address and service objects, identify generated-name collisions, detect a limited set of equivalent existing policies and create a smaller delta configuration. A rollback file is generated from the objects and policy IDs created by that delta.
What the auditor checks
Current checks include IPv4 and CIDR syntax, port ranges, supported protocols, missing interfaces, invalid actions, duplicate rules, broad ANY destinations, ANY ports, CIDRs with host bits and selected remote-management exposure patterns.
What the generator creates
The current beta generates FortiGate IPv4 address objects, TCP/UDP/SCTP custom services, firewall policies, a delta configuration and a rollback configuration. Matching objects from an imported configuration are referenced instead of recreated.
What still requires manual review
NAT, policy order, UTM and security profiles, VDOM context, zones, address groups, service groups, FQDN objects, VIPs, IPv6 and advanced FortiGate features are outside the current equivalence engine. Do not deploy generated CLI without an administrator review.
Frequently asked questions
Does DeepCodeAgent upload my firewall matrix?
The selected matrix and FortiGate configuration are parsed by JavaScript in your browser. The beta does not send those selected files to a DeepCodeAgent application backend.
Can I convert an Excel firewall matrix to FortiGate CLI?
Yes. The current beta accepts XLSX, XLS and CSV files with common column names for source, destination, protocol, port, source interface, destination interface and action.
Can it compare with my current FortiGate configuration?
Yes, for supported plain-text FortiOS configuration sections. It currently inventories IPv4 address objects, custom services and firewall policies used by the MVP comparison engine.
Is the generated FortiGate CLI safe to deploy automatically?
No. DeepCodeAgent is a review and generation aid, not an automatic deployment system. Always validate the CLI on the intended FortiOS version and target configuration before applying it.
FortiGate and FortiOS are trademarks of Fortinet, Inc. DeepCodeAgent is an independent tool and is not affiliated with or endorsed by Fortinet.