Trying Matrix with the simulator
Every Matrix connector contains a simulator: an in-memory FortiGate behind the same driver interface as the real one, with the same objects and write rules (policies in sequence order, /32 address objects, address groups). Rooms, bulk changes, disable-until, addresses and the history work end to end with it, which makes it the way to try, demonstrate and train on Matrix before touching a real firewall.
What you get
Each simulated firewall reports FortiOS v7.4.11 and is seeded like the
pilot school:
| Rooms | Internet Access for SB1-102, SB1-108, SB1-208, SB2-216, SB2-315, SB2-316, FB-102 and HAC-401 (SB1-108 and SB2-315 disabled) |
| Groups | <room>-Students address for each room, with three computers pc-<room>-1<suffix> … pc-<room>-3<suffix> |
| Other policies | A disabled general Internet Access for Students after the rooms, a lookalike Test-Internet-SB1-102 (not a room: the name does not match) and a Guest WiFi policy of another direction |
The direction, VDOM and computer name suffix follow the firewall's
settings in Matrix; any host and port will do. Each firewall of driver
simulator is its own simulated FortiGate, kept in memory while the
connector runs (a restart starts from the seed again).
Set up a trial
The simulator runs only when the connector is started with --dev, which
the Windows service is not. On the connector computer:
-
Install and enroll a connector on any Windows computer, following Connectors. It does not need to reach a FortiGate.
-
Stop the service and run the connector in the foreground with the simulator, in an elevated command prompt:
sc stop EntrosityMatrixConnector"C:\Program Files\Entrosity\Matrix Connector\matrix-connector.exe" run --devThe console logs
simulated firewalls available (driver "simulator"). Keep the window open for the trial;Ctrl+Cstops it, andsc start EntrosityMatrixConnectorbrings the service back. -
In Matrix, add a firewall on that connector (Getting started) with Driver Simulator (test data, no real firewall), any Address and Port (for example
sim1and443), Source interface or zoneStudents, Destination interface or zoneINTERNET, the Policy name patternInternet Access for (?P<room>(?:SB[0-9]+|FB|HAC)-[0-9]{3})and the Computer name suffix.coding.local. No token is needed. -
Accept the guard as for a real firewall (Getting started), and switch changes on.
-
Within a report interval the eight rooms appear, marked Test data · simulator.
Developers run the same with make dev in entrosity-matrix-connector
(data directory ~/.matrix-connector outside Windows)
(Matrix connector → Development).
Limits
- The simulator only exists in a connector run with
--dev: a firewall of driversimulatoron a normal service fails withunknown_driver. - It simulates the FortiGate's configuration, not traffic: nothing is actually blocked.
- Allowed sites are not set up in the simulator of
--dev(the setup CLI cannot be pasted into it), so its lists show as not set up. Developers can run the HTTPS simulatorfortigate-siminstead, whose control API applies the setup CLI Matrix shows (and the cleanup of the old Entrosity services group,unselectanddelete):curl -X POST --data-binary @setup.txt localhost:18444/cli(Matrix connector → Development).