Security Fabric Downstream Authorization Pending
A company has deployed a Security Fabric with a root FortiGate 600E and two downstream FortiGate 200E devices. The network also includes a FortiAnalyzer and a FortiManager. The administrator notices that the Security Fabric topology in FortiGate is not showing the downstream devices. The root FortiGate can ping the management IPs of the downstream devices. Additionally, the administrator has configured the downstream devices with the correct root IP and authorization mode is set to 'none'. However, when running 'diagnose sys fabric list' on the root, it shows the downstream devices with status 'Pending'. The root FortiGate's firewall policy allows all traffic from the downstream subnets. What is the most likely cause of the issue?
Quick Answer
The answer is that the downstream devices are missing the root FortiGate's serial number in the downstream-authorization configuration. Even when the authorization mode is set to 'none', each downstream FortiGate must explicitly list the root FortiGate's serial number to complete the Security Fabric handshake; without it, the root sees the devices as discovered but cannot finalize the adjacency, leaving them in a 'Pending' status. This scenario tests your understanding of the Security Fabric authorization process on the Fortinet NSE 7 Advanced Security NSE7 exam, where a common trap is assuming 'none' mode bypasses all authorization requirements—it only disables password-based approval, not the serial-number trust. Remember the memory tip: "Pending means missing the serial; even 'none' needs the root's ID to be done."
⚠ Common exam trap
Test-takers frequently assume setting authorization mode to 'none' removes all authorization requirements, but in reality, the downstream device must still explicitly list the root's serial number to complete the Fabric handshake.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The downstream devices are missing the root FortiGate's serial number in the 'downstream-authorization' configuration.
The 'Pending' status in the output of 'diagnose sys fabric list' indicates that the root FortiGate has discovered the downstream devices but they have not completed the authorization handshake. Even though the authorization mode is set to 'none', each downstream FortiGate must still have the root FortiGate's serial number explicitly listed in its 'downstream-authorization' configuration to be accepted into the Security Fabric. Without this entry, the root will not finalize the adjacency, leaving the downstream devices in a pending state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The downstream devices are missing the root FortiGate's serial number in the 'downstream-authorization' configuration.
Why this is correct
When authorization mode is 'none', the root does not automatically authorize; the downstream must have the root's serial in the configuration.
- ✗
The FortiAnalyzer is not configured to receive logs from the downstream devices.
Why it's wrong here
FortiAnalyzer is not required for fabric formation.
- ✗
The downstream devices are using a different management port than the root.
Why it's wrong here
Ping works, so the port is reachable.
- ✗
The root FortiGate's firewall policy is blocking the downstream devices' Fabric traffic.
Why it's wrong here
The policy allows all traffic from downstream subnets.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on NSE7
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO statements about Security Fabric deployment are correct? (Choose two.)
medium- A.A Security Fabric can contain a maximum of 50 FortiGate devices.
- ✓ B.The root FortiGate must have a management IP address that is reachable from all downstream devices.
- ✓ C.Each FortiGate device in the Fabric must have a unique FortiGate serial number.
- D.All FortiGate devices in the Fabric must be managed by the same FortiManager.
- E.A FortiGate can only belong to one Security Fabric at a time.
Why B: Options B and C are correct. Option B is correct because the root FortiGate acts as the central coordination point for the Security Fabric; all downstream devices must be able to reach its management IP to establish and maintain communication, which uses TCP port 8013 (HTTPS) for the initial handshake and keepalive messages. Option C is correct because each FortiGate device in the Fabric must have a unique serial number to ensure proper identification and avoid conflicts within the Fabric topology.
Variation 2. Which TWO statements about the Security Fabric and FortiManager are correct? (Choose two.)
medium- ✓ A.FortiManager can manage multiple Security Fabrics.
- B.FortiGate devices must be in transparent mode to join the fabric.
- C.FortiAnalyzer must be deployed to use the Security Fabric.
- ✓ D.The first FortiGate added to the Security Fabric becomes the root FortiGate.
- E.A FortiGate can be part of multiple Security Fabrics simultaneously.
Why A: FortiManager can manage multiple Security Fabrics because it is designed as a centralized management platform that can oversee multiple independent FortiGate clusters or fabric topologies. Each Security Fabric is a logical grouping of FortiGate devices that share a common root FortiGate, and FortiManager can be configured to manage several such fabrics simultaneously, each with its own root and member devices, without requiring separate management servers. Additionally, when a Security Fabric is formed, the first FortiGate added to the fabric automatically becomes the root FortiGate, which serves as the central point for fabric communication and policy enforcement. This root FortiGate is responsible for coordinating fabric-wide operations and sharing information with other member devices.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.