Description | This article describes how to verify and confirm the status of the devices in the Security Fabric. The root (FortiGates) and downstream nodes sometimes appear to be present when they are not connected to each other. |
Scope | FortiGate. |
Solution |
If a downstream FortiGate is not authorized, it stays visible but isolated— the device is then listed as Pending/Discovered but it is possible that the csfd handshake never completes. When the cfsd handshake fails to complete no Security Fabric sessions, trust, or telemetry/policy sync will be established. The downstream devices with show Pending or Discovered but not Authorized. Also, Fabric Connector object exists but does not establish sessions with the root and the csf states can differ between root and downstream. Use the following cli commands to verify status and trouble shoot node to node and node to fabric (downstream devices).
On the FortiGate Device:
diagnose sys csf authorization pending-list
On the Downstream Devices:
diagnose sys csf upstream
On the FortiGate and Downstream Devices:
diagnose debug reset
To complete the output collection, wait for the full handshake to appear before disabling the debug. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.