Addresses and groups
A room policy's source (srcaddr) names address groups; their members
are the room's computers, IPv4 address objects of a single host
(ipmask with mask 255.255.255.255, "/32"). Addresses and groups
shows them and lets tenant admins change a computer's IP or add a
computer to a room.
Changes here edit address objects on the FortiGate only. They do not configure DHCP, DNS or the computer itself.
The page
- Firewall, Building and Room filter the list of Groups on the left. Each group shows its room and number of computers; a group that cannot be edited is marked view only.
- Choose a group to see its computers: Computer, IPv4 address and Management. Search by name or IP searches in the selected group.
- Groups are found by their real names in the room policies, not guessed from the room number. The connector reads them every 5 minutes, on Refresh, and after every address change.
- With stale data (Data not current — editing is blocked) or address changes switched off for the firewall (Address changes are switched off for this firewall), the buttons are disabled.
Viewers see every group here, teachers only the groups of the rooms granted to them; only tenant admins change addresses.
What can be edited
Matrix edits only what it can change without touching anything outside the room:
| Object | Editable when |
|---|---|
| A group | It is a standard group (no exclusions, no nested groups, no unsupported member types) used only by the room's own policy. |
| A computer | It is a /32 IPv4 (ipmask) object and a member of this group only: not of another group, not named in the source or destination of any IPv4 policy the connector read. |
Everything else is shown as View only with the reason, for example The group is also used outside the selected room., The object is also used in another group or policy., Only the IPv4 address of a single computer (/32) can be edited., or The group has nested groups or uses an unsupported type or exclusions.
There is no deleting, renaming or moving of computers and no creating of groups.
Change a computer's IP
- In the group, choose Change IP on the computer.
- Enter the New IPv4 address (a single computer's address; not
0.0.0.0, loopback, multicast, link-local or reserved) and choose Review the change: pc-102-01.coding.local · SB1-102-Students address · old IP → new IP. - Confirm the change.
The request carries the IP you saw and the version of the group you loaded. The connector reads the policy, the group, the object and every use of it again; if anything changed in the meantime the change is refused: The group changed since you loaded it. Refresh, check the computers and try again. A duplicate IP among the managed computers is refused. Only the object's IP changes; its comment and other fields stay.
Add a computer
- In the group, choose Add computer.
- Enter the Computer name: one DNS label followed by the firewall's
Computer name suffix, for example
pc-102-01.coding.local. An IPv4 object is created, not an FQDN object. - Enter the New IPv4 address, Review the change and Confirm the change.
A name that already exists (in any letter case) and an IP already used by
a managed computer are refused. The connector first creates the address
object, with the comment <marker> <operation id> (by default
Entrosity Matrix operation 3f…), reads it back, and then appends it to
the group's current members, keeping every other member and field, and
reads the group back.
Results and unfinished operations
| Message | Meaning |
|---|---|
| The IP address and the group membership are confirmed. | Done. |
| The change is not confirmed. Refresh and use "Check / retry" on the unfinished operation. | A write was sent but its confirmation did not arrive. |
| The change was refused. + reason | Nothing was written (Troubleshooting). |
| The change failed. + reason | Nothing was written (Troubleshooting). |
Each write step is recorded (journaled) by the connector before it is sent, and reported to Matrix. When an operation is interrupted, its author sees it in the group as Unfinished operation: pc-… with how far it got:
| Stage | Shown as |
|---|---|
update_sent | The IP change was not confirmed. |
create_sent | Creating the address was not confirmed. |
created | The address was created; its group membership is not confirmed. |
member_sent | The address was created; adding it to the group is not confirmed. |
Check / retry (after a refresh and a new confirmation) repeats the operation for the same computer, IP and group against the group as it is now: a created object is recognised by its comment, IP and UUID and not created again, and nothing is overwritten or deleted. Only the operation's author can retry it, and only once it had started writing (an operation refused before any write needs a new request). Nothing is ever retried automatically.
Limits and cautions
- One address change at a time per firewall (
busy). - The operation's checks read the FortiGate again between steps, but the FortiGate's API has no transaction across them. Avoid editing the same objects on the FortiGate (or in another tool) while Matrix changes them.
- The firewall's API administrator needs read and write access to
addresses and address groups (Setting up the FortiGate),
and the connector's guard must allow address writes
(
guard set <id> --address-writes on).