A real-life situation
FGT1 has just been unboxed. The ISP has given the address 203.0.113.2/30 with gateway 203.0.113.1, and the LAN is to be 10.0.1.0/24 with the FortiGate as its gateway, 10.0.1.1. By the end of this lesson FGT1 will be reachable from the LAN for management and able to reach the Internet itself. (LAN users still can't browse: that needs a firewall policy, in module 2.)
Step 1: get in
- Console: connect the console cable, open a terminal at 9600 baud (8-N-1) and log in as
adminwith an empty password. This always works, whatever the IP settings. - Browser: connect a laptop to the model's management or internal port, give it an address in the same subnet (often 192.168.1.0/24), and browse to
https://192.168.1.99. Accept the self-signed certificate warning. - VM: use the hypervisor's console to set port1's address first, then the browser.
At the first login FortiOS asks for a new admin password. Choose a long one: this account can change everything.
Step 2: hostname, interfaces and the default route
config system global
set hostname FGT1
end
config system interface
edit port1
set mode static
set ip 203.0.113.2 255.255.255.252
set role wan
set allowaccess ping
next
edit port2
set ip 10.0.1.1 255.255.255.0
set role lan
set allowaccess ping https ssh
next
end
config router static
edit 1
set gateway 203.0.113.1
set device port1
next
endport1 (WAN) answers only ping: management from the Internet is a common attack target. port2 (LAN) allows HTTPS and SSH for administrators. A static route with no destination set is the default route, 0.0.0.0/0.
Step 3: DNS and time
config system dns
set primary 96.45.45.45
set secondary 96.45.46.46
end
config system ntp
set ntpsync enable
set type fortiguard
endThe FortiGate itself needs DNS to reach FortiGuard and to resolve FQDN objects. 96.45.45.45 and 96.45.46.46 are FortiGuard's DNS servers; any reliable resolver works. Correct time matters for logs, certificates and schedules.
Step 4: verify
FGT1 # get system status Version: FortiGate-VM64 v7.4.x,buildxxxx (GA) ... Hostname: FGT1 Operation Mode: NAT Current virtual domain: root ... System time: ...
FGT1 # get router info routing-table all Codes: K - kernel, C - connected, S - static, R - RIP, B - BGP O - OSPF, IA - OSPF inter area ... Routing table for VRF=0 S* 0.0.0.0/0 [10/0] via 203.0.113.1, port1, [1/0] C 10.0.1.0/24 is directly connected, port2 C 203.0.113.0/30 is directly connected, port1
FGT1 # execute ping www.fortiguard.com PING www.fortiguard.com (…): 56 data bytes 64 bytes from …: icmp_seq=0 ttl=55 time=12.4 ms 64 bytes from …: icmp_seq=1 ttl=55 time=12.1 ms ...
Why it works this way
The FortiGate's own traffic (to DNS, NTP, FortiGuard) is local traffic: it needs a route but no firewall policy. Traffic through the FortiGate, such as PC1 browsing, always needs a policy. That is why FGT1 can ping the Internet now while PC1 can't yet.
allowaccess controls only management access to the FortiGate on that interface. Removing HTTPS from the WAN doesn't stop users browsing through it; it stops strangers reaching the login page.
Common mistakes
- Allowing HTTPS, SSH or HTTP on the WAN interface "temporarily" and forgetting it.
- Removing HTTPS from the interface you are connected through, and locking yourself out (use the console to recover).
- Forgetting DNS: FortiGuard updates and FQDN addresses fail although ping to an IP address works.
- Expecting LAN users to browse once the default route exists. They also need a firewall policy.
💡 Tip: keep a console cable or out-of-band access to every FortiGate. Most lockouts are fixed in a minute from the console.
Key takeaways
- First login: admin, empty password, forced change; console works without any IP settings.
- Address each interface, set its role, and allow only the management protocols it needs.
- A static route without a destination is the default route; static routes have distance 10.
- Set DNS and NTP; verify with get system status, the routing table and execute ping.
Check yourself
FGT1 can ping 8.8.8.8 but not www.fortiguard.com. What is most likely missing?
Which setting stops people on the Internet reaching FGT1's login page?
In `config router static`, an entry has a gateway and device but no dst. What does it route?