Discovery response lockdown
By default, FortiGate automatically generate a FortiExtender entry if a newly added FortiExtender discovers it, that is to say when the FortiExtender is sending a discovery request.
In order to prevent rogue devices from detecting or scanning the FortiGate, you can enable "fortiextender-discovery-lockdown"
to ensure that the discovery response is sent to a pre-authorized device only.
Once enabled, the FortiGate will not automatically generate an extender entry when a newly discovered FortiExtender joins the network. Instead, it will only accept discovery request from a pre-authorized extender entry. By default, "fortiextender-discovery-lockdown"
is disabled. You can enable it using the following command:
config system global set fortiextender-discovery-lockdown enable end