FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dbabic
Staff
Staff
Article Id 196896

Description

 

This article explains how to restart a FortiGate to factory defaults.

This procedure clears all changes made to the FortiGate configuration and resets the system to its original configuration with the default factory settings.

It does not change the firmware version or the antivirus or IPS  attack definitions.
 
There is also an option to reset FortiGate to factory settings without losing management access.


Scope

 

This command works on FortiGates and FortiProxys.


Solution

 

A FortiGate Device can be reset to Factory defaults by using either the GUI or the CLI interface. This reset will remove all configurations. It will be out of the box condition. Direct access to FortiGate will be needed to access it.

GUI

Note: The reset to factory settings using the GUI is not available in v5.4.

1) Access the system using a web browser.

2) In the navigation tree, go to System -> Dashboard -> Status, and select the Revisions link for the System Information Widget.
 
tana_0-1665105019181.jpeg

3) Select Restore Factory Default or Revert.
 
tana_2-1665105141165.jpeg

 

Note.
If there is no revision available, create one first.

4) A warning will appear, proceed to select 'OK' and system will reboot and load the basic configuration.

tana_1-1665105104490.jpeg
From CLI:

1) Open a SSH to the system and execute the following command:
 
# exec factoryreset
 
2) A warning will appear.
 
This operation will reset the system to factory default!
Do you want to continue? (y/n)
 
3) System will reboot and will load a basic configuration.
 
Factory reset without losing management access:
 
This option will reset the device to factory settings except for VDOM, interface, and static route settings.
This means that after resetting, FortiGate will not have any firewall policies, IPsec settings, but it will be possible to access the FortiGate remotely on its IP address.
This option is available only in CLI:
 
1)    Open a SSH to the system and execute the following command:
 
# execute factoryreset2
 
2)    Warning will appear:
 
FGT50E-3 # exec factoryreset2
This operation will reset the system to factory default except system.global.vdom-admin/system.global.long-vdom-name/VDOMs/system.interface/system.settings/router.static/router.static6!
Do you want to continue? (y/n)
 
After reboot, FortiGate will be in factory settings but with management access.
All administrators will be removed and FortiGate can be accessed with the default username.