What model of FGT? Sounds like a small one like 40F since you said "lan" for the hard-switch. Are you realizing "lan" includes all internal ports? Then, did you separated the lan1(port1) port from the hard-switch?
Also as any FW appliances, by default, nothing is allowed unless you configure something with policies.
Then you wan to set up a lan network/subnet to allow out(internet)-to-in access? Unless you have a web-server, FTP server, or whatever other internet service servers, that shouldn't be configured. That generally require VIPs to make holes on the wall to let them come inside.
If you want to make the lan1 as your management port, you just needed to separate the interface from the lan hard-switch then the rest of lan ports stay in "lan" hard-switch so that you can use it as regular user ports. So that you can set in-to-out internet access policy. That should be already there by default for those smaller models.