NetCrosswalk: Cross-Vendor Network Task Translator

You know how to do it on one box. Here's how it's done on the other — GUI or CLI, plus the gotchas.

30 tasks

Pick a task on the left

Set the two vendors in the bar above, then choose the task you already know how to do. Each task shows the method (GUI, CLI, or either), the concrete steps, and the gotchas — which is where most of the value is.

Currently translating MikroTik RouterOSFortinet FortiGate (FortiOS).

30 tasks

Across 8 categories, from ping to IPsec.

8 vendors

Compared side by side, with honest gaps where a platform genuinely cannot do something.

Search the gotchas

The search box covers step text and notes too — try masquerade, trusthost, or hairpin.

Vendors covered

MikroTik RouterOS RouterOS 7.x
Everything is reachable from both WinBox and CLI, and the two use the same object tree — a GUI path translates almost 1:1 into a CLI path.
Fortinet FortiGate (FortiOS) FortiOS 7.2 – 7.6
The GUI covers configuration well but almost none of the troubleshooting tools. Anything diagnostic (ping, traceroute, sniffer, session list) lives in the CLI Console.
Ubiquiti UniFi Network UniFi Network 8.x – 9.x (UDM / UDM-Pro / UXG)
Controller-driven: you configure the site, not the device. The controller pushes provisioning, so on-device CLI changes get overwritten on the next provision. Menu paths move between minor versions more than any other vendor here.
Cisco IOS / IOS-XE IOS-XE 17.x (Catalyst 9000, ISR 1000/4000)
CLI-first. The IOS-XE WebUI exists but most shops never enable it, so assume CLI. Nothing you type is persistent until you copy running-config to startup-config.
Palo Alto Networks PAN-OS PAN-OS 10.2 / 11.x
Candidate-config model: nothing you change takes effect until you Commit. The GUI is strong, including a real packet-capture UI, but ping and traceroute are CLI-only.
Netgate pfSense CE pfSense CE 2.7 / Plus 24.x
The GUI is the source of truth and includes a full Diagnostics menu, so almost nothing here requires a shell. Editing FreeBSD config files by hand gets clobbered by the GUI.
SonicWall (SonicOS) SonicOS 7.3.x (Gen7 TZ/NSa/NSsp; current General Release line is 7.3.2/7.3.3 — note Gen8 TZ80/TZ280+/NSa 2800+ hardware instead runs the separate SonicOS 8.x line)
Unlike MikroTik or Cisco, where the CLI is a first-class, complete configuration surface, SonicOS's CLI covers only a subset of what the GUI can do — almost all security policy, VPN, and security-services (content filtering, IPS, etc.) configuration is done in the web GUI, with the CLI reserved for bootstrap setup, scripting repetitive changes, and troubleshooting.
NETGEAR Insight (Cloud Management Platform) Insight Cloud Portal/App 10.0.x (cloud mgmt); switch-side CLI varies by line — Smart Switch "Lite CLI" firmware 6.0.10.5+/7.0.9.5+, fully-managed M4200/M4300 CLI 12.0.11.x
Unlike a single-OS vendor, "NETGEAR" here is really three separate management surfaces stitched together by Insight: routers and Orbi Pro APs are cloud/app-managed with zero local CLI, Smart Switches get a locked-down Lite CLI, and only the fully-managed M4200/M4300 switch line has a proper IOS-style CLI — so whether a GUI step even has a CLI equivalent depends entirely on which box you're touching.

/ search  ·  s swap vendors  ·  move through tasks  ·  Esc clear search