Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.95
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Fortigate Parameter Explanation and Conversion Suggestions")}}

Fortigate Parameter Explanation and Conversion Suggestions

{{ $t('productDocDetail.updateTime') }}: 2026-01-04

This section only covers the security policy portion, including IPS, WAF, URL filtering, and antivirus. For application control, please use tools to automate the conversion.

FortiGate Parameter

FortiGate Parameter Description

Corresponding Sangfor NGAF Module/Parameter

Migration Notes

name

Policy name

Policies > Network Security > Policies

Can be migrated directly; name length/character set must comply with NGAF rules

srcintf

Source interface

Policies > Network Security > Policies

NGAF security policies do not support interfaces directly; select the corresponding zone for the interface in the policy

dstintf

Destination interface

Policies > Network Security > Policies

NGAF security policies do not support interfaces directly; select the corresponding zone for the interface in the policy

srcaddr

Source address object

Policies > Network Security > Policies

Must select the corresponding address object in the policy

dstaddr

Destination address object

Policies > Network Security > Policies

Must select the corresponding address object in the policy

service

Service object (port/protocol)

Policies > Network Security > Policies

Must select the corresponding service object in the policy

action

Policy action

Policies > Network Security > Policies

Must select the policy action in the NGAF policy

schedule

Policy schedule

Policies > Network Security > Policies / Objects > Schedule

The same schedule object can be recreated in NGAF

logtraffic

Log events

Policies > Network Security > Policies

Enable Log Events

ips-sensor

IPS policy name

Policies > Network Security > Policies

Corresponds to an IPS template in NGAF; must be manually specified

ssl-ssh-profile

SSL decryption policy

Policies > Decryption

Create decryption policy under Policies > Decryption