mechub sovereign network-security automation ← all projects
browser tool early MIT

firewallintentconverter

Multi-vendor config migration to SRX

Browser-based conversion of firewall and cloud configs, from PAN-OS to AWS security groups, into reviewable Juniper SRX output. Always a migration draft.

About

A browser-based tool that converts firewall configurations into an intermediate format for review, editing and conversion to Juniper SRX. Paste or upload a config, review the parsed rules in an interactive UI, optionally get AI-powered best-practice suggestions, then export as SRX set commands or XML.

The output is always a migration draft requiring review, never production-ready.

Features

  • Sources: PAN-OS XML, Junos SRX, FortiGate, Cisco ASA/FTD, Check Point R80+, SonicWall, Huawei USG, AWS, Azure and GCP
  • Greenfield mode builds an SRX configuration from scratch via an LLM-guided interview
  • Six-step workflow from source import through review, conversion and export
  • Rules are auto-triaged into Safe, Decision, Unsupported and Blocked buckets
  • The LLM API key is kept only in sessionStorage for the current tab session and is never sent to the project server; the built app is a static SPA with no server required

Quick start

Development mode

git clone https://github.com/mechubsec/firewallintentconverter
cd firewallintentconverter
npm install && npm run dev

Static build

npm run build
# then open dist/index.html

Full instructions in the README ↗