Skip to main content

Trying Matrix with the simulator

Every Matrix connector contains a simulator: an in-memory FortiGate behind the same driver interface as the real one, with the same objects and write rules (policies in sequence order, /32 address objects, address groups). Rooms, bulk changes, disable-until, addresses and the history work end to end with it, which makes it the way to try, demonstrate and train on Matrix before touching a real firewall.

What you get​

Each simulated firewall reports FortiOS v7.4.11 and is seeded like the pilot school:

RoomsInternet Access for SB1-102, SB1-108, SB1-208, SB2-216, SB2-315, SB2-316, FB-102 and HAC-401 (SB1-108 and SB2-315 disabled)
Groups<room>-Students address for each room, with three computers pc-<room>-1<suffix> … pc-<room>-3<suffix>
Other policiesA disabled general Internet Access for Students after the rooms, a lookalike Test-Internet-SB1-102 (not a room: the name does not match) and a Guest WiFi policy of another direction

The direction, VDOM and computer name suffix follow the firewall's settings in Matrix; any host and port will do. Each firewall of driver simulator is its own simulated FortiGate, kept in memory while the connector runs (a restart starts from the seed again).

Set up a trial​

The simulator runs only when the connector is started with --dev, which the Windows service is not. On the connector computer:

  1. Install and enroll a connector on any Windows computer, following Connectors. It does not need to reach a FortiGate.

  2. Stop the service and run the connector in the foreground with the simulator, in an elevated command prompt:

    sc stop EntrosityMatrixConnector
    "C:\Program Files\Entrosity\Matrix Connector\matrix-connector.exe" run --dev

    The console logs simulated firewalls available (driver "simulator"). Keep the window open for the trial; Ctrl+C stops it, and sc start EntrosityMatrixConnector brings the service back.

  3. In Matrix, add a firewall on that connector (Getting started) with Driver Simulator (test data, no real firewall), any Address and Port (for example sim1 and 443), Source interface or zone Students, Destination interface or zone INTERNET, the Policy name pattern Internet Access for (?P<room>(?:SB[0-9]+|FB|HAC)-[0-9]{3}) and the Computer name suffix .coding.local. No token is needed.

  4. Accept the guard as for a real firewall (Getting started), and switch changes on.

  5. Within a report interval the eight rooms appear, marked Test data · simulator.

Developers run the same with make dev in entrosity-matrix-connector (data directory ~/.matrix-connector outside Windows) (Matrix connector → Development).

Limits​

  • The simulator only exists in a connector run with --dev: a firewall of driver simulator on a normal service fails with unknown_driver.
  • It simulates the FortiGate's configuration, not traffic: nothing is actually blocked.
  • Allowed sites are not set up in the simulator of --dev (the setup CLI cannot be pasted into it), so its lists show as not set up. Developers can run the HTTPS simulator fortigate-sim instead, whose control API applies the setup CLI Matrix shows (and the cleanup of the old Entrosity services group, unselect and delete): curl -X POST --data-binary @setup.txt localhost:18444/cli (Matrix connector → Development).