"In addition to monitoring rogue APs, you can actively prevent your users from connecting to them. When suppression is activated against an AP, the FortiGate WiFi controller sends deauthentication messages to the rogue AP’s clients, posing as the rogue AP, and also sends deauthentication messages to the rogue AP, posing as its clients."
Rogue APs are generally defined as APs that you don't manage but have been connected to your wired network. Obviously this could be a significant security risk. I don't think they're sending deauth messages to every client/AP they see.
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortig...
"In addition to monitoring rogue APs, you can actively prevent your users from connecting to them. When suppression is activated against an AP, the FortiGate WiFi controller sends deauthentication messages to the rogue AP’s clients, posing as the rogue AP, and also sends deauthentication messages to the rogue AP, posing as its clients."