Built at 2 a.m., for 2 a.m.

FortiTools started as a folder of snippets — the debug flow block one of us pasted into every incident bridge, the IKE config we kept re-deriving, the transceiver part numbers nobody can remember. Turning them into forms took an afternoon. Not having to remember them again has saved considerably more.

It's maintained by working network engineers, not a content team. Every tool here is one somebody on the team reached for during a real incident, which is also why the list is short: if it isn't useful under pressure, it doesn't ship.

Nothing is hosted server-side beyond the pages themselves. The generators, the parsers and the lookups all run in your tab, which means the site works on an air-gapped laptop and your client's config never touches our infrastructure — because there isn't any.

28
tools live
0
accounts required
2026
started

What's next

More parsers, mostly. The generators were the easy half — the genuinely useful work is turning a pasted config into a list of things that are wrong with it. The shadowed-rule finder and the policy diff are the first two; there will be more.

Found a bug in the output?

Send the firmware version, the fields you entered, and what the box actually said. That's enough to reproduce it, and it usually gets fixed the same week.

hello@fortitools.com

FortiTools is an independent project. It is not affiliated with, endorsed by, or supported by any vendor. FortiGate and FortiOS are trademarks of their respective owner, used here only to describe what the tools are for.