StudyToCert

All certifications / FortiGate Admin / Lessons

Fortinet NSE 4 - FortiOS 7.6 Administrator NSE4_FGT_AD-7.6 · Domain 1: Deployment and system configuration

Initial setup: default management IP 192.168.1.99, admin account, forced password change, interface roles and access (HTTPS, SSH, ping)

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Every FortiGate you unbox starts from the same known state, and the exam expects you to know that state cold. A hardware FortiGate ships with the address 192.168.1.99 on its management interface (often labelled MGMT, or internal/port1 on smaller models). You cable a laptop to that interface, give the laptop an address in the same subnet, and browse over HTTPS to 192.168.1.99 in a web browser. HTTPS is the default GUI protocol, so a plain HTTP request redirects to it.

The default administrator account is named admin and has a blank (empty) password. FortiOS does not leave it that way: the first time you log in, the unit forces you to set a new password before it lets you do anything else. There is no root account and no serial-number login, which is a favourite distractor on the exam. Registration in FortiCloud is optional for local management and is not required just to log in.

Once you are in, interfaces carry a role that describes their place in the network. The three built-in roles are LAN, WAN and DMZ, plus Undefined. The role is mostly a convenience that hides irrelevant fields (a WAN interface, for example, exposes settings you would not put on a LAN port), and it does not by itself change how traffic is filtered. Firewall policies still decide what passes.

Each interface also has an Administrative Access setting that lists the management services allowed to reach the FortiGate on that interface: HTTPS and SSH for management, PING so the interface answers ICMP echo, plus options such as HTTP, SNMP, FMG-Access and Security Fabric Connection (formerly called FortiTelemetry). This is a common source of lockouts: if you remove HTTPS from the interface you are managing over, you lose the GUI. On a WAN interface facing the Internet you normally allow little or nothing, and you rely on trusted hosts and a VPN for remote management.

In a lab you will set a static IP on port1 in the GUI or with the CLI. The equivalent CLI is short: enter config system interface, edit port1, set ip 10.0.0.1/24, set allowaccess ping https ssh, then end. Knowing both the GUI path and the allowaccess keyword helps you answer questions phrased either way.

Key terms

Management IP (192.168.1.99)
The default address on a factory FortiGate's management/internal interface, reached over HTTPS for first login.
Administrative access
The per-interface list of management services (HTTPS, SSH, PING, SNMP, and so on) that the FortiGate will answer on that interface.
Interface role
A label (LAN, WAN, DMZ or Undefined) that tailors which configuration fields are shown for an interface; it does not filter traffic on its own.
allowaccess
The CLI keyword under a system interface that sets which management protocols the interface accepts.
Real-world example

A technician cables a laptop to a new FortiGate's MGMT port, sets the laptop to 192.168.1.50/24, browses over HTTPS to 192.168.1.99, logs in as admin with a blank password, and is immediately forced to create a new admin password.

Exam tip: Losing GUI access after an interface change is almost always a missing HTTPS entry in that interface's Administrative Access. Confirm allowaccess before you disconnect.

Check yourself

What URL and credentials do you use for the very first login to a factory-default hardware FortiGate?

Browse over HTTPS to 192.168.1.99 and log in as admin with a blank password; FortiOS then forces you to set a new password.

You removed HTTPS from the interface you manage over and lost the GUI. What setting caused it?

The interface's Administrative Access (allowaccess) list no longer includes HTTPS, so the FortiGate stops answering GUI requests there.

Does an interface role of WAN block traffic by itself?

No. The role only tailors the shown settings; firewall policies decide what traffic passes.

Study FortiGate Admin for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the FortiGate Admin study plan