Skip to content
Next2IT
← Next2IT tools

Free FortiGate configuration reviewer

Turn firewall findings
into a clear plan.

Understand the settings worth checking. Decide what needs attention. Get Next2IT’s help taking the next step for your business.

No upload. No email required. Your configuration stays yours.

Neatly organised network patch cables connected to switches in an equipment rack.
SUPPORT FOR YOUR BUSINESS NETWORKClear findings.
Practical next steps.
How we can help
Private, browser-only review Risk score + PDF + Excel UK team · UK-wide support

See what needs a closer look

An explained risk score and prioritised findings, with missing information clearly flagged.

Leave with practical next steps

A readable PDF for the conversation. An Excel action list for the people doing the work.

Get the right people involved

Bring your IT team into the review, or ask Next2IT to help assess and plan the changes.

START WITH YOUR CONFIGURATION

Your private review starts here.

Five guided steps.
Try the example before choosing your own file.

Step 01 / 05 Browser-only processing

Start with a clearer picture.

Get an explained risk score, settings worth checking and a report to work through with your IT team. We’ll guide you through making a masked export first.

No configuration upload

Your browser reads the file locally. It is never sent to Next2IT, an AI provider or a review server.

No session recording

Analytics and session replay are disabled here. Your configuration and results are not saved in cookies or browser storage.

You control the report

Download a PDF report or an Excel action list. Keep references anonymous, or choose to include identifiers for your engineer.

A starting point for an engineer, not a security certificate.

We check a defined set of configuration patterns. Traffic, policy order, firmware vulnerabilities and the controls around your firewall need a wider review.

No sign-up. No changes to your firewall. Use an export you are authorised to review.

Exactly what happens to my data?

The site and its code download normally, so our hosting provider receives the page request. Choosing a configuration does not upload it. The file is read in a separate browser worker; fixed finding descriptions and anonymous references reach the page by default. If you explicitly select identifiers, policy IDs, object names and VDOM names also appear locally in the results and can be included in your reports. Address fields, secret fields and the raw configuration are excluded.

The page blocks background network connections and third-party scripts. It does not retain the review in cookies, local storage or a database. “Clear & start again” releases the working data; your original file and any report you download remain on your device.

External guidance and contact links open other pages. They receive no configuration or report. Keep using a trusted, up-to-date browser: this tool cannot protect against a compromised device or browser extension.

Your configuration stays on your device.Ruleset 2026.09 · Independent Next2IT tool

FROM FINDINGS TO ACTION

You have a report.
Let’s agree the next steps.

A broad rule may keep a critical application running. A management setting may be protected by another control. We help put the findings in context, so you can make informed changes.

  1. Understand the finding

    We can check the live settings, the surrounding controls and what the rule needs to do for your business.

  2. Agree what matters first

    Work through the likely impact, business dependencies and unanswered questions with an engineer.

  3. Plan changes with confidence

    Agree the scope, testing, change window and recovery plan before making changes to a working firewall.

BEFORE YOU START

A few useful
answers.

Clear about what we check.
Clear about what stays private.

What does the free reviewer check?

It looks for broad allow rules, explicit logging and inspection settings, management protocols, WAN-role management access, administrator MFA and trusted-host settings, strong-crypto settings, and selected IPsec proposals. It reads supported FortiOS text and Fortinet YAML structures, including VDOMs. Every finding explains the evidence and what still needs context.

Will it tell me whether my firewall is secure?

No. A configuration is only part of the picture. This tool does not test live traffic, simulate rule order, expand address groups, assess firmware vulnerabilities or prove internet exposure. It never changes your firewall. Use the findings as a starting point for an engineer’s review.

Do I need to share my configuration or email address?

No. The free tool and both report downloads work without an account, email address or upload. Password masking does not remove every identifying detail, so keep the original export private. Reports use anonymous references by default; including policy IDs, object names and VDOM names is optional.

How does the risk score work?

It is a Next2IT configuration indicator out of 100: higher means more observed settings need attention. Each finding type starts at 25 points for high priority, 10 for medium or 3 for low, with up to five repeat points. The breakdown shows every point. Missing information makes it provisional; a zero is withheld when information is incomplete. It covers all findings regardless of report selection and is not a probability of a breach or a security certificate.

What can I download?

A PDF with the score breakdown, selected evidence, actions and grouped unanswered checks, or an Excel workbook with filterable findings and Owner, Status and Notes columns. PDF supports up to 250 selected findings; Excel retains every pending entry location. Both are created locally. Updating Excel statuses tracks progress; a fresh review is needed to calculate a new score.

What happens if I ask Next2IT for help?

You choose whether to book a conversation or contact us. We’ll discuss your environment, concerns and the scope of any work before proceeding. Opening a booking or contact page does not send your score, findings, report or configuration. We can agree what information is needed and how to share it securely.

Is this an official Fortinet tool?

No. This is an independent tool built by Next2IT. FortiGate and FortiOS are Fortinet trademarks. The export guide links to Fortinet’s own documentation. Findings need to be interpreted against your device, software version and business requirements.