Course menu

Module 1: Getting StartedLesson 1.2 (2 of 5 in this module)2 of 18 in the FortiGate Administrator course

First login and basic setup

Reaching a new FortiGate, the first admin password, hostname, DNS, NTP, the default route and management access.

Beginner · 11 min read

What you will learn

After this lesson, you can log in to a new FortiGate, give it a hostname, address its WAN and LAN interfaces, add a default route, set DNS and NTP, and verify it can reach the Internet.

  • GUI and console
  • Admin password
  • DNS and NTP
  • Default route

Initial setup is the minimum configuration that makes a FortiGate manageable and connected: a strong admin password, a hostname, IP addresses and administrative access on the interfaces, a default route to the ISP, DNS servers so it can resolve names (including FortiGuard), and time synchronisation for logs and certificates.

In simple terms: Before a FortiGate can protect anything, it needs a password, a name, addresses on its ports, a way to the Internet and the correct time.

A real-life situation

FGT1 has just been unboxed. The ISP has given the address 203.0.113.2/30 with gateway 203.0.113.1, and the LAN is to be 10.0.1.0/24 with the FortiGate as its gateway, 10.0.1.1. By the end of this lesson FGT1 will be reachable from the LAN for management and able to reach the Internet itself. (LAN users still can't browse: that needs a firewall policy, in module 2.)

Step 1: get in

  • Console: connect the console cable, open a terminal at 9600 baud (8-N-1) and log in as admin with an empty password. This always works, whatever the IP settings.
  • Browser: connect a laptop to the model's management or internal port, give it an address in the same subnet (often 192.168.1.0/24), and browse to https://192.168.1.99. Accept the self-signed certificate warning.
  • VM: use the hypervisor's console to set port1's address first, then the browser.

At the first login FortiOS asks for a new admin password. Choose a long one: this account can change everything.

Step 2: hostname, interfaces and the default route

config system global set hostname FGT1 end config system interface edit port1 set mode static set ip 203.0.113.2 255.255.255.252 set role wan set allowaccess ping next edit port2 set ip 10.0.1.1 255.255.255.0 set role lan set allowaccess ping https ssh next end config router static edit 1 set gateway 203.0.113.1 set device port1 next end

port1 (WAN) answers only ping: management from the Internet is a common attack target. port2 (LAN) allows HTTPS and SSH for administrators. A static route with no destination set is the default route, 0.0.0.0/0.

Step 3: DNS and time

config system dns set primary 96.45.45.45 set secondary 96.45.46.46 end config system ntp set ntpsync enable set type fortiguard end

The FortiGate itself needs DNS to reach FortiGuard and to resolve FQDN objects. 96.45.45.45 and 96.45.46.46 are FortiGuard's DNS servers; any reliable resolver works. Correct time matters for logs, certificates and schedules.

Step 4: verify

Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # get system status
Version: FortiGate-VM64 v7.4.x,buildxxxx (GA)
...
Hostname: FGT1
Operation Mode: NAT
Current virtual domain: root
...
System time: ...
Example output, trimmed. Check the version, the hostname and the operation mode (NAT).
Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # get router info routing-table all
Codes: K - kernel, C - connected, S - static, R - RIP, B - BGP
       O - OSPF, IA - OSPF inter area
       ...

Routing table for VRF=0
S*      0.0.0.0/0 [10/0] via 203.0.113.1, port1, [1/0]
C       10.0.1.0/24 is directly connected, port2
C       203.0.113.0/30 is directly connected, port1
Two connected networks and the default route, with distance 10 (the FortiGate default for static routes).
Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # execute ping www.fortiguard.com
PING www.fortiguard.com (…): 56 data bytes
64 bytes from …: icmp_seq=0 ttl=55 time=12.4 ms
64 bytes from …: icmp_seq=1 ttl=55 time=12.1 ms
...
A reply proves three things at once: the route, the WAN link and DNS all work.

Why it works this way

The FortiGate's own traffic (to DNS, NTP, FortiGuard) is local traffic: it needs a route but no firewall policy. Traffic through the FortiGate, such as PC1 browsing, always needs a policy. That is why FGT1 can ping the Internet now while PC1 can't yet.

allowaccess controls only management access to the FortiGate on that interface. Removing HTTPS from the WAN doesn't stop users browsing through it; it stops strangers reaching the login page.

Common mistakes

  • Allowing HTTPS, SSH or HTTP on the WAN interface "temporarily" and forgetting it.
  • Removing HTTPS from the interface you are connected through, and locking yourself out (use the console to recover).
  • Forgetting DNS: FortiGuard updates and FQDN addresses fail although ping to an IP address works.
  • Expecting LAN users to browse once the default route exists. They also need a firewall policy.

💡 Tip: keep a console cable or out-of-band access to every FortiGate. Most lockouts are fixed in a minute from the console.

Key takeaways

✅ Key takeaways
  • First login: admin, empty password, forced change; console works without any IP settings.
  • Address each interface, set its role, and allow only the management protocols it needs.
  • A static route without a destination is the default route; static routes have distance 10.
  • Set DNS and NTP; verify with get system status, the routing table and execute ping.

Check yourself

Predict · scenario 1

FGT1 can ping 8.8.8.8 but not www.fortiguard.com. What is most likely missing?

Predict · scenario 2

Which setting stops people on the Internet reaching FGT1's login page?

Predict · scenario 3

In `config router static`, an entry has a gateway and device but no dst. What does it route?

FAQ

What are the default login details?
On a new or factory-reset FortiGate the user is admin with an empty password, and FortiOS forces you to set a new password at the first login. The default management address depends on the model (often 192.168.1.99 on the management or internal port); the model's QuickStart guide lists it.
Should I use the setup wizard or the CLI?
Either. The GUI walks you through the same settings. Learning the CLI pays off: it is faster, it can be pasted in bulk, and it shows exactly what is configured.