In a Fortinet Security Fabric spanning the control-center FortiGate and several substation FortiGates, what role does the control-center device play as the fabric root?
Select an answer to reveal the explanation.
Short Explanation
Being the root just means the control-center box sits at the top of the fabric's family tree: everything else connects up to it, and that's where the consolidated view comes together. It doesn't make it a traffic cop or the only device allowed to run updates.
Full Explanation
The root device in a Security Fabric is the anchor that downstream devices join and report into, forming the top of the fabric's topology structure and the point where fabric-wide visibility and rating information consolidate, an organizational role within the fabric relationship rather than a special traffic-handling or licensing privilege. Claiming only the root can run FortiGuard-updated signatures confuses fabric membership with FortiGuard licensing, which each device manages on its own regardless of fabric role. HA cluster primary and secondary election is a separate mechanism entirely, governed by HA configuration like device priority, not by which device happens to be the fabric root, and a fabric can span multiple independent HA pairs, none of which take their primary status from fabric root status. Claiming the root is the only device that may pass inter-substation traffic misreads a topology and visibility role as a data-plane gatekeeping role, which the fabric root is not. The operational caveat: fabric root status is about topology anchoring, not traffic policy or HA behavior, so a good check when troubleshooting is confirming those two areas separately rather than assuming fabric role explains an HA or traffic issue.