Skip to content

FortiGate 60F — login, gateway address and status lights

Open a browser on a device connected to your FortiGate 60F and go to 192.168.1.99.

The FortiGate 60F is a firewall router from Fortinet, in UK use 2019-present. This page covers the four things people actually come looking for: its settings address, how its login works, what its lights mean and how to reset it safely.

What is the FortiGate 60F gateway address?

The FortiGate 60F settings page is at 192.168.1.99. Type that into the address bar of a browser — not into a search box, which will just search for the number instead of opening the page.

Your device has to be connected to the FortiGate 60F itself for this to work — over its Wi-Fi or by cable. On mobile data, or connected to a different network, the address goes nowhere.

HTTPS only, on port1. The 60F has no dedicated management port either, so port1 is where you start. As on the 40F, Fortinet expects your laptop on 192.168.1.0/24 — which collides with the default range of most UK ISP routers, so unplug the WAN while you commission it.

What is the default username and password for the FortiGate 60F?

Documented default username, no password

The FortiGate 60F does not ship with a password. The admin account is already there with a documented username, and the password field is genuinely empty until somebody sets one:

Username
admin

Leave the password box empty. There is no value to type and no value to look up. If a site offers you a password for this model, it has guessed.

Same FortiOS behaviour as the 40F. The admin account exists with no password at all, and FortiOS makes you set one the first time you use it, after a factory reset, and after a firmware re-image. Fortinet's wording is that adding a password to the admin account is "mandatory".

What do the lights on the FortiGate 60F mean?

Here is what each light on the FortiGate 60F is telling you, and what to do about it.

LightWhat it meansWhat to do
LOGOsolid greenThe device is on. This is the illuminated Fortinet logo, which the 40F does not have. It glows blue rather than green on FortiWiFi models.
PWRsolid greenPower is on.
PWRoffPower is off.Check the socket and that you are using the power supply that came with the unit rather than a substitute.
STATUSsolid greenOperating normally.
STATUSflashing greenBooting up.Wait for it to settle before deciding anything is wrong.
HAsolid greenOperating in a high-availability cluster.
HAsolid amberHA failover.The cluster has moved traffic to the other unit. Find out why before you fail it back.
HAoffNot in an HA cluster. Normal on a single-firewall site.
WIFIsolid greenWi-Fi is connected. FortiWiFi models only — a plain FortiGate has no WIFI light.
WIFIflashing greenWi-Fi activity. FortiWiFi models only.
WIFIoffWi-Fi is off, or this is a non-wireless FortiGate.
Port LINK/ACTsolid greenThe port has a link.
Port LINK/ACTflashing greenTransmitting data.
Port LINK/ACToffNo link on that port.Check the cable and that the device at the other end is powered.
Port SPEEDsolid greenConnected at 1Gbps.
Port SPEEDsolid amberConnected at 100Mbps.If you expected a gigabit link, suspect the cable or a speed setting at the far end.
Port SPEEDoffNot connected, or connected at 10Mbps.
FortiLinksolidMarks the two FortiLink ports, which are meant for managing FortiSwitches rather than for general LAN use.If you have plugged a client or an ordinary switch into FortiLink A or B, move it to one of the numbered Ethernet ports.

How do you reset a FortiGate 60F?

What you lose. Identical in scope to the 40F — policies, VPN tunnels and pre-shared keys, VDOMs, VLANs, addressing, SD-WAN, routing, admin accounts and certificates all go, and the unit returns to 192.168.1.99 with admin and no password. It usually hurts more here, because a 60F is typically the site edge with two WANs and site-to-site tunnels, so a reset drops the internet and every branch VPN at once.

  1. No reset button, same as the 40F. The 60F rear panel carries antennas, power, USB, console, WAN1 and WAN2, DMZ, FortiLink A and B, and Ethernet ports 1 to 5. Factory reset is execute factoryreset from the CLI, over SSH or over the RJ45 console port at 9600 8-N-1.
  2. Hold it for No hold time, because there is no button to hold..
  3. Release, and give the unit a few minutes to restart before trying to connect.

Take a configuration backup you can actually restore — meaning one whose admin password you know — before you go anywhere near this.

A reboot is not a reset. A GUI reboot or a power cycle keeps every setting. Only execute factoryreset clears them.

What if you cannot get into the FortiGate 60F at all?

Yes, over a physical console cable. Fortinet documents a special maintainer account for exactly this, and says plainly that "as long as someone with physical access to the device has the serial number of the device, which is labeled on the device, they can change the admin administrator account password". Once in you can set a new admin password or run execute factoryreset. The account can be switched off with set admin-maintainer disable, and Fortinet warns that if you do that and then lose the password, the only way back in is a fresh firmware installation.

If that does not work, a factory reset will always get you in, at the cost of every setting on the unit.

Where this comes from

Sitemap