Security Fabric (CSF) roles
a tree of FortiGates (and other Fortinet devices) sharing topology and telemetry; one root, the rest downstream, connected on TCP 8013
The root FortiGate is where you enable the Fabric and (usually) attach FortiAnalyzer; downstream units join by pointing upstream. The CSF control connection is TCP 8013. Fabric gives you the topology views, fabric-wide policy/object push (from the root), automation stitches, and a combined security rating. Device authorization is manual by default — a downstream device shows up pending until the root authorizes it.