Every FortiGate you unbox starts from the same known state, and the exam expects you to know that state cold. A hardware FortiGate ships with the address 192.168.1.99 on its management interface (often labelled MGMT, or internal/port1 on smaller models). You cable a laptop to that interface, give the laptop an address in the same subnet, and browse over HTTPS to 192.168.1.99 in a web browser. HTTPS is the default GUI protocol, so a plain HTTP request redirects to it.
The default administrator account is named admin and has a blank (empty) password. FortiOS does not leave it that way: the first time you log in, the unit forces you to set a new password before it lets you do anything else. There is no root account and no serial-number login, which is a favourite distractor on the exam. Registration in FortiCloud is optional for local management and is not required just to log in.
Once you are in, interfaces carry a role that describes their place in the network. The three built-in roles are LAN, WAN and DMZ, plus Undefined. The role is mostly a convenience that hides irrelevant fields (a WAN interface, for example, exposes settings you would not put on a LAN port), and it does not by itself change how traffic is filtered. Firewall policies still decide what passes.
Each interface also has an Administrative Access setting that lists the management services allowed to reach the FortiGate on that interface: HTTPS and SSH for management, PING so the interface answers ICMP echo, plus options such as HTTP, SNMP, FMG-Access and Security Fabric Connection (formerly called FortiTelemetry). This is a common source of lockouts: if you remove HTTPS from the interface you are managing over, you lose the GUI. On a WAN interface facing the Internet you normally allow little or nothing, and you rely on trusted hosts and a VPN for remote management.
In a lab you will set a static IP on port1 in the GUI or with the CLI. The equivalent CLI is short: enter config system interface, edit port1, set ip 10.0.0.1/24, set allowaccess ping https ssh, then end. Knowing both the GUI path and the allowaccess keyword helps you answer questions phrased either way.
Key terms
- Management IP (192.168.1.99)
- The default address on a factory FortiGate's management/internal interface, reached over HTTPS for first login.
- Administrative access
- The per-interface list of management services (HTTPS, SSH, PING, SNMP, and so on) that the FortiGate will answer on that interface.
- Interface role
- A label (LAN, WAN, DMZ or Undefined) that tailors which configuration fields are shown for an interface; it does not filter traffic on its own.
- allowaccess
- The CLI keyword under a system interface that sets which management protocols the interface accepts.
A technician cables a laptop to a new FortiGate's MGMT port, sets the laptop to 192.168.1.50/24, browses over HTTPS to 192.168.1.99, logs in as admin with a blank password, and is immediately forced to create a new admin password.
Check yourself
What URL and credentials do you use for the very first login to a factory-default hardware FortiGate?
Browse over HTTPS to 192.168.1.99 and log in as admin with a blank password; FortiOS then forces you to set a new password.
You removed HTTPS from the interface you manage over and lost the GUI. What setting caused it?
The interface's Administrative Access (allowaccess) list no longer includes HTTPS, so the FortiGate stops answering GUI requests there.
Does an interface role of WAN block traffic by itself?
No. The role only tailors the shown settings; firewall policies decide what traffic passes.