Skip to main content

Rooms

Rooms (the start page of a tenant) shows every room of every firewall as a card, grouped by building. Everyone with a Matrix role sees all rooms; who may switch which room: Roles and permissions.

The page​

  • Search by room filters the cards by room code; Building and Firewall filter by building and by firewall.
  • Buildings are shown with their names from the firewall's Building names (for example FB → Фирма, HAC → ЦВП); codes SB1, SB2, … without a name are shown as Building 1, Building 2, ….
  • Refresh asks the connector to read the firewall now (otherwise every report interval, 30 seconds by default). The page also updates live when a report arrives.
  • Under the title, each firewall shows Connection active with Last update: …, or No confirmed connection (Stale data). A simulated firewall shows Test data · simulator.

The notice at the top is meant literally: the state shows whether the rule is enabled; a disabled rule alone does not confirm that the internet is off (What switching a room off means).

Room states​

On the cardMeaning
The rule is enabledThe room's policy is enabled on the FortiGate: the room has internet (as far as this policy is concerned).
The rule is disabledThe policy is disabled.
State not currentThe firewall's data is stale: the card shows the last reported state, and switching is blocked.
No longer on the firewallThe policy was not in the last successful report (deleted, renamed, moved to another direction).
Back on at …A pending automatic re-enable (Disable until).
Unconfirmed, Refused, FailedThe result of the last change of this room, when it was not a success (Results).
Processing…A change of this room is running.
View onlyYou are a viewer (teachers only see the rooms granted to them: Room rights).
3 allowed sitesThe domains this room reaches while its internet is off: the list for all rooms plus the room's own list (the tooltip: This room: 1 · all rooms: 2). Opens Allowed sites at the room's list. Hidden while the connector does not support allowed sites and no list has domains.

Switch a room​

  1. Choose Disable the rule (or Enable the rule) on the card.
  2. The dialog asks Do you confirm disabling the rule for room SB1-102? and reminds you that the change will be recorded in the history. When disabling, choose under Turn back on automatically whether and when the room comes back on (Disable until).
  3. Confirm. The card shows SB1-102: the change was sent to the firewall… and then the result.

What happens meanwhile: Matrix records the change, sends it to the connector, the connector reads the policy again, checks that it is still the room's manageable policy, asks Matrix whether the change is still allowed, writes only the policy's status when it differs, and reads it back to confirm. When the policy already has the desired status, nothing is written and the change is a success.

Disable until​

When disabling, Turn back on automatically offers:

OptionRe-enable at
No — keep it disabledNever; the room stays off until someone enables it.
In 45 minutes45 minutes from now.
At the end of the school day (17:00)Today at 17:00 local time (not offered after 16:55: The school day is already over).
At a chosen time…Turn back on at a date and time between 5 minutes and 7 days from now.

The card then shows Back on at …, and the re-enable is listed under Schedules. Rules:

  • Enabling the room by hand cancels its pending re-enable.
  • A new disable-until replaces the previous one; a new disable without a time keeps the room off and cancels the re-enable.
  • Cancel automatic re-enable on the card (or on Schedules) keeps the room off until someone enables it.
  • At the time, Matrix switches the room on as the System, with the same checks as any change: the firewall must be current and allow changes, and the connector's guard must be accepted. If the connector is offline Matrix retries (from every 30 seconds up to every 15 minutes) for 24 hours; a re-enable that does not succeed shows as Failed on Schedules: enable the room by hand.

Bulk changes​

  1. Choose Select rooms. Tick rooms, or Select building to tick every room of a building.
  2. Choose Disable selected or Enable selected; the dialog lists the rooms. When disabling, Turn back on automatically applies to all of them.
  3. Confirm. The change was sent for 5 rooms. Each room then gets its own result, as for a single change.
  • Rooms of one firewall at a time (Select rooms of one firewall at a time).
  • A teacher sees and selects only their own rooms; a hand-made request with another room sends nothing (unknown_room).
  • A room with a change already running is skipped: Not sent for SB1-102: another change of this room or firewall is still running.
  • Each room counts against the rate limits.

Done leaves the selection mode.

Results​

MessageMeaningWhat to do
SB1-102: the rule is disabled. / enabled.Written and confirmed.Nothing.
Unconfirmed: the change is not confirmed. Refresh and check the history before trying again.The write may have happened, but its confirmation did not arrive.Refresh. If the card shows the desired state, it worked. Check History. Never click repeatedly.
Refused: the change was refused. + reasonNothing was written: no right, changes switched off, the guard not accepted, the policy changed on the firewall, too many changes, …Read the reason (Troubleshooting).
Failed: the change failed. + reasonNothing was written: the firewall is unreachable, refused the token, has another FortiOS version, …Troubleshooting.

Every attempt, including refused ones (also a hand-made API call for a room you have no right to), is in the History.

Stale data​

A firewall's rooms are stale when its connector is offline, the firewall's status is not online (unreachable, token refused, …), or its last report is older than 2.5 times its report interval (at least 90 seconds). Then:

  • the firewall shows No confirmed connection, and a banner says why (the last report is too old, no report yet, the connector is offline, …);
  • the cards show the last reported state as State not current;
  • switching is blocked (snapshot_stale) until a fresh report arrives.

Banners for administrators​

Tenant admins also see, per firewall:

  • Changes are switched off for …: the firewall's switches are off (Firewalls → Changes).
  • The connector has not accepted … yet or The configuration of … differs from what the connector accepted, with the command to run on the connector computer (Connectors → The local guard).

Limits​

  • 10 changes per minute per user and 30 per minute per tenant (each room of a bulk change counts); beyond, rate_limited (too many changes; wait a minute). The server's teachers can change them (Running Entrosity Matrix).
  • One change at a time per room (busy).
  • The connector writes at most 60 times per minute per firewall (its local guard's cap).