Skip to main content

Getting started

This walk-through takes an organization from nothing to the first room switched off and on. Step 1 is for a platform admin of the Hub, step 2 for the FortiGate's administrator, step 7 for a local administrator of the connector computer; the rest needs the Tenant admin role in Matrix (Roles and permissions).

No FortiGate at hand? Follow the same steps with a simulated firewall: Trying Matrix with the simulator adds what is different.

While Matrix is in beta

Only platform admins can open Matrix during the beta (Products in beta). They are global admins in every Matrix tenant, so they can follow every step below themselves.

Before you start​

  • The FortiGate's management address and HTTPS port as the connector computer reaches it, its VDOM (usually root), and its FortiOS version.
  • The direction of the room policies: their source interface or zone (for example Students) and destination interface or zone (for example the SD-WAN zone INTERNET).
  • How the room policies are named, for example Internet Access for SB1-102, Internet Access for FB-102.
  • The host name suffix of the computers' address objects (for example .coding.local), if you will add computers from Matrix.
  • An always-on Windows computer on the administration network that reaches the FortiGate's management port, with outbound TCP 443 to hub.entrosity.com (Connectors → Requirements).

1. Enable Matrix for the organization​

A platform admin opens Administration → Organizations on the Hub, opens the organization and ticks Entrosity Matrix under Products (Products per organization), then gives members a Matrix role: Tenant admin for the IT administrators, Teacher for teachers who switch rooms, Viewer for people who only look.

Within about a minute the organization appears in Matrix as a tenant with the same ID.

2. Prepare the FortiGate​

The FortiGate's administrator creates a REST API administrator for Matrix with a minimal access profile, the connector computer as its only trusted host and access to the rooms' VDOM only, and generates its API token: Setting up the FortiGate. Keep the token for step 5; it is shown only once on the FortiGate.

3. Install a connector​

  1. In Matrix, open Connectors and choose Install a connector.

  2. Give it a Label (for example Server room PC), pick the Site, keep Maximum uses at 1 and Expires after (days) at 7, and choose Create token.

  3. Copy the command under Windows: install the MSI (elevated prompt) and run it in an elevated command prompt on the Windows computer, in the folder of the installer (Download connector on the Connectors page downloads the newest one; rename it to matrix-connector.msi or use its name in the command):

    msiexec /i matrix-connector.msi /qn ENROLLMENT_TOKEN=<token> SERVER_URL=https://hub.entrosity.com/matrix
  4. Within a minute the connector appears under Connectors as online.

Details and the other ways to install: Connectors.

4. Add the firewall​

  1. Open Firewalls and choose Add firewall.
  2. Fill in the form (Firewalls → Settings):
    • General: a Name (for example Main building FortiGate), the Site, the Connector from step 3, Driver FortiGate (REST API).
    • Connection: Address and Port of the FortiGate's HTTPS management, VDOM, Verify the FortiGate's TLS certificate with its CA certificate (PEM) (or leave the CA empty to use the connector computer's trusted roots), and optionally the Expected FortiOS version (for example 7.4.11).
    • Rooms: the Source interface or zone and Destination interface or zone, the Policy name pattern (for example Internet Access for (?P<room>(?:SB[0-9]+|FB|HAC)-[0-9]{3})) and the Building names (for example FB → Фирма, HAC → ЦВП).
    • Computers: the Computer name suffix (for example .coding.local).
    • Changes: leave both switches off for now.
  3. Choose Create firewall.

5. Store the API token​

On the firewall's page, under API token, paste the token from step 2 into New token and choose Store token. It is stored encrypted and never shown again; the connector picks it up within a minute.

6. Check the firewall​

  1. Choose Check. The connector reads the FortiGate (GET requests only) and shows the FortiOS version, whether the Direction was found, the numbers of Room policies, Address groups and Computers, the Connector guard, and Warnings (Firewalls → Check).
  2. Open the Pattern tester and choose Use names from the last check: every policy with the configured direction is listed, and you see which are rooms and with which room and building. Adjust the pattern until exactly the room policies match.
  3. Read every warning. A later_accept_policy warning means that a room switched off still has internet through a later policy (What switching a room off means). Resolve it on the FortiGate before relying on Matrix in lessons.

Within the report interval the rooms appear under Rooms, marked Connection active.

7. Accept the local guard​

The connector writes nothing until a local administrator of the connector computer accepts the firewall. The firewall's page shows the command under Connector guard. On the connector computer, in an elevated command prompt:

cd "C:\Program Files\Entrosity\Matrix Connector"
matrix-connector guard show
matrix-connector guard accept <firewall id>

guard accept prints what Matrix may change on this firewall (host, VDOM, direction, pattern, …) and asks you to type yes. It allows policy writes; address writes stay off until matrix-connector guard set <firewall id> --address-writes on (Connectors → The local guard). Connector guard on the firewall's page turns Accepted.

8. Switch changes on​

On the firewall's page, under Changes, tick Allow turning room policies on and off (and, when you are ready for it, Allow changing and adding computers) and choose Save.

9. Switch a room​

  1. Open Rooms. Pick a room the FortiGate's administrator agreed to use for testing.
  2. Choose Disable the rule, confirm, and watch the card: the change was sent to the firewall…, then the rule is disabled.
  3. Test from a computer of that room: new connections and established ones (see What switching a room off means).
  4. Choose Enable the rule and confirm.

Both changes are in History with their steps.

10. Give teachers their rooms​

Open Room rights, choose the Firewall and, for each teacher, tick the rooms they may switch, then Save (Room rights). Teachers see and switch only their rooms; tenant admins switch all.

Next steps​