FortiGate 60F — login, gateway address and status lights
Open a browser on a device connected to your FortiGate 60F and go to 192.168.1.99.
The FortiGate 60F is a firewall router from Fortinet, in UK use 2019-present. This page covers the four things people actually come looking for: its settings address, how its login works, what its lights mean and how to reset it safely.
What is the FortiGate 60F gateway address?
The FortiGate 60F settings page is at 192.168.1.99. Type that into the address bar of a browser — not into a search box, which will just search for the number instead of opening the page.
Your device has to be connected to the FortiGate 60F itself for this to work — over its Wi-Fi or by cable. On mobile data, or connected to a different network, the address goes nowhere.
HTTPS only, on port1. The 60F has no dedicated management port either, so port1 is where you start. As on the 40F, Fortinet expects your laptop on 192.168.1.0/24 — which collides with the default range of most UK ISP routers, so unplug the WAN while you commission it.
What is the default username and password for the FortiGate 60F?
Documented default username, no password
The FortiGate 60F does not ship with a password. The admin account is already there with a documented username, and the password field is genuinely empty until somebody sets one:
- Username
admin
Leave the password box empty. There is no value to type and no value to look up. If a site offers you a password for this model, it has guessed.
Same FortiOS behaviour as the 40F. The admin account exists with no password at all, and FortiOS makes you set one the first time you use it, after a factory reset, and after a firmware re-image. Fortinet's wording is that adding a password to the admin account is "mandatory".
What do the lights on the FortiGate 60F mean?
Here is what each light on the FortiGate 60F is telling you, and what to do about it.
| Light | What it means | What to do |
|---|---|---|
| LOGOsolid green | The device is on. This is the illuminated Fortinet logo, which the 40F does not have. It glows blue rather than green on FortiWiFi models. | |
| PWRsolid green | Power is on. | |
| PWRoff | Power is off. | Check the socket and that you are using the power supply that came with the unit rather than a substitute. |
| STATUSsolid green | Operating normally. | |
| STATUSflashing green | Booting up. | Wait for it to settle before deciding anything is wrong. |
| HAsolid green | Operating in a high-availability cluster. | |
| HAsolid amber | HA failover. | The cluster has moved traffic to the other unit. Find out why before you fail it back. |
| HAoff | Not in an HA cluster. Normal on a single-firewall site. | |
| WIFIsolid green | Wi-Fi is connected. FortiWiFi models only — a plain FortiGate has no WIFI light. | |
| WIFIflashing green | Wi-Fi activity. FortiWiFi models only. | |
| WIFIoff | Wi-Fi is off, or this is a non-wireless FortiGate. | |
| Port LINK/ACTsolid green | The port has a link. | |
| Port LINK/ACTflashing green | Transmitting data. | |
| Port LINK/ACToff | No link on that port. | Check the cable and that the device at the other end is powered. |
| Port SPEEDsolid green | Connected at 1Gbps. | |
| Port SPEEDsolid amber | Connected at 100Mbps. | If you expected a gigabit link, suspect the cable or a speed setting at the far end. |
| Port SPEEDoff | Not connected, or connected at 10Mbps. | |
| FortiLinksolid | Marks the two FortiLink ports, which are meant for managing FortiSwitches rather than for general LAN use. | If you have plugged a client or an ordinary switch into FortiLink A or B, move it to one of the numbered Ethernet ports. |
How do you reset a FortiGate 60F?
What you lose. Identical in scope to the 40F — policies, VPN tunnels and pre-shared keys, VDOMs, VLANs, addressing, SD-WAN, routing, admin accounts and certificates all go, and the unit returns to 192.168.1.99 with admin and no password. It usually hurts more here, because a 60F is typically the site edge with two WANs and site-to-site tunnels, so a reset drops the internet and every branch VPN at once.
- No reset button, same as the 40F. The 60F rear panel carries antennas, power, USB, console, WAN1 and WAN2, DMZ, FortiLink A and B, and Ethernet ports 1 to 5. Factory reset is execute factoryreset from the CLI, over SSH or over the RJ45 console port at 9600 8-N-1.
- Hold it for No hold time, because there is no button to hold..
- Release, and give the unit a few minutes to restart before trying to connect.
Take a configuration backup you can actually restore — meaning one whose admin password you know — before you go anywhere near this.
A reboot is not a reset. A GUI reboot or a power cycle keeps every setting. Only execute factoryreset clears them.
What if you cannot get into the FortiGate 60F at all?
Yes, over a physical console cable. Fortinet documents a special maintainer account for exactly this, and says plainly that "as long as someone with physical access to the device has the serial number of the device, which is labeled on the device, they can change the admin administrator account password". Once in you can set a new admin password or run execute factoryreset. The account can be switched off with set admin-maintainer disable, and Fortinet warns that if you do that and then lose the password, the only way back in is a fresh firmware installation.
If that does not work, a factory reset will always get you in, at the cost of every setting on the unit.
Where this comes from
- Connecting to the FortiGate using a web browser — Source of the 192.168.1.99 management address.
- FortiOS administration guide — administrators — States the empty default admin password and that setting one is mandatory at first login.
- FortiGate/FortiWiFi 40F and 60F Series QuickStart Guide — Front-panel light table, port list and console settings.
- Disable the maintainer admin account — The documented console recovery route, and the consequence of disabling it.
- Setting up FortiGate for management access — Confirms port1 is the management interface on units with no dedicated MGMT port.
- Fortinet hardware document library — Used as the evidence that both models are still actively documented, since Fortinet keeps its lifecycle dates behind a FortiCare login.