FortiGate 40F — login, gateway address and status lights
Open a browser on a device connected to your FortiGate 40F and go to 192.168.1.99.
The FortiGate 40F is a firewall router from Fortinet, in UK use 2020-present. This page covers the four things people actually come looking for: its settings address, how its login works, what its lights mean and how to reset it safely.
What is the FortiGate 40F gateway address?
The FortiGate 40F settings page is at 192.168.1.99. Type that into the address bar of a browser — not into a search box, which will just search for the number instead of opening the page.
Your device has to be connected to the FortiGate 40F itself for this to work — over its Wi-Fi or by cable. On mobile data, or connected to a different network, the address goes nowhere.
HTTPS only, and on port1 rather than a dedicated management port — the 40F does not have one. Plain http:// will not give you a login page, so browse to https://192.168.1.99. Fortinet expects your laptop to be on 192.168.1.0/24, and its own guide suggests giving it 192.168.1.1, which is the address most UK ISP routers already use. Unplug the WAN while you set the unit up if you want to avoid a subnet clash.
What is the default username and password for the FortiGate 40F?
Documented default username, no password
The FortiGate 40F does not ship with a password. The admin account is already there with a documented username, and the password field is genuinely empty until somebody sets one:
- Username
admin
Leave the password box empty. There is no value to type and no value to look up. If a site offers you a password for this model, it has guessed.
Fortinet states it directly: "By default, your FortiGate has an administrator account set up with the username admin and no password." That empty state is real, not a gap in our research — it is what an out-of-box or freshly reset unit is in. FortiOS then forces the issue: "Adding a password to the admin administrator is mandatory. You will be prompted to configured it the first time you log in to the FortiGate using that account, after a factory reset, and after a new image installation." So a blank password gets you in exactly once.
What do the lights on the FortiGate 40F mean?
Here is what each light on the FortiGate 40F is telling you, and what to do about it.
| Light | What it means | What to do |
|---|---|---|
| PWRsolid green | Power is on. | |
| PWRoff | Power is off. | Check the socket and that you are using the power supply that came with the unit rather than a substitute. |
| STATUSsolid green | Operating normally. | |
| STATUSflashing green | Booting up. | Wait for it to settle before deciding anything is wrong. |
| HAsolid green | Operating in a high-availability cluster. | |
| HAsolid amber | HA failover. | The cluster has moved traffic to the other unit. Find out why before you fail it back. |
| HAoff | Not in an HA cluster. Normal on a single-firewall site. | |
| WIFIsolid green | Wi-Fi is connected. FortiWiFi models only — a plain FortiGate has no WIFI light. | |
| WIFIflashing green | Wi-Fi activity. FortiWiFi models only. | |
| WIFIoff | Wi-Fi is off, or this is a non-wireless FortiGate. | |
| Port LINK/ACTsolid green | The port has a link. | |
| Port LINK/ACTflashing green | Transmitting data. | |
| Port LINK/ACToff | No link on that port. | Check the cable and that the device at the other end is powered. |
| Port SPEEDsolid green | Connected at 1Gbps. | |
| Port SPEEDsolid amber | Connected at 100Mbps. | If you expected a gigabit link, suspect the cable or a speed setting at the far end. |
| Port SPEEDoff | Not connected, or connected at 10Mbps. |
The 40F-3G4G variant adds SVC and 3G/4G lights that the plain FG-40F does not have.
How do you reset a FortiGate 40F?
What you lose. Everything goes: firewall policies, IPsec and SSL VPN tunnels along with their pre-shared keys, VDOMs, VLANs, interface addressing, SD-WAN rules, static routes, admin accounts and local certificates. The unit comes back on 192.168.1.99 with admin and no password. On a live site that means no internet until the policy set is rebuilt or a configuration backup is restored.
- There is no reset button. Fortinet does not fit one to the 40F — the QuickStart Guide panel diagrams list antennas, power, USB, console, WAN, FortiLink and Ethernet ports 1 to 3, and nothing else. A factory reset is a command: execute factoryreset, run either over SSH, from the GUI console, or over the RJ45 console port at 9600 8-N-1 with no flow control.
- Hold it for No hold time, because there is no button to hold..
- Release, and give the unit a few minutes to restart before trying to connect.
If you have lost the password, the command route is closed to you and the console port is the only way in. That is the practical reason the missing button matters.
A reboot is not a reset. A reboot from the GUI or a power cycle keeps every setting. Only execute factoryreset clears them.
What if you cannot get into the FortiGate 40F at all?
Yes, over a physical console cable. Fortinet documents a special maintainer account for exactly this, and says plainly that "as long as someone with physical access to the device has the serial number of the device, which is labeled on the device, they can change the admin administrator account password". Once in you can set a new admin password or run execute factoryreset. The account can be switched off with set admin-maintainer disable, and Fortinet warns that if you do that and then lose the password, the only way back in is a fresh firmware installation.
If that does not work, a factory reset will always get you in, at the cost of every setting on the unit.
Where this comes from
- Connecting to the FortiGate using a web browser — Source of the 192.168.1.99 management address.
- FortiOS administration guide — administrators — States the empty default admin password and that setting one is mandatory at first login.
- FortiGate/FortiWiFi 40F and 60F Series QuickStart Guide — Front-panel light table, port list and console settings.
- Disable the maintainer admin account — The documented console recovery route, and the consequence of disabling it.
- Setting up FortiGate for management access — Confirms port1 is the management interface on units with no dedicated MGMT port.
- Fortinet hardware document library — Used as the evidence that both models are still actively documented, since Fortinet keeps its lifecycle dates behind a FortiCare login.