Professional Services AMA – March 2026
Thank you to everyone who joined our March AMA session! Below is a clean, easy‑to‑scan recap of every question asked, along with brief summaries of the answers shared during the call. If you’d like the full context, you can view the recording below.
Cato uses active‑passive by default. Active‑active is available with EA enablement.
Your IPSec configuration labels them directly:
- Primary=active
- Secondary=standby
No. Secondary tunnels do not participate in load‑sharing.
Yes, but only via Early Access. This enables multiple tunnels on primary/secondary POPs.
You can see traffic hitting WAN firewall policies, but tunnel‑level packet breakdown is not available.
Not in CMA. Support can perform captures on the backend.
Yes, via the API or MCP Server integrations.
Not today. Current alerts may trigger on QoS discards. Recommended to submit an Idea Hub request.
Not currently. Alerts must be disabled per area (BGP, XOps, link health).
Suggested as an idea via the Idea Hub.
Hostname resolution should work in normal circumstances. Re‑testing and a support ticket is recommended if it persists.
No timeline yet; currently only possible on the backend through Support.
Robin gave a walkthrough of our AI Security offering during this event. He starts discussing capturing user prompts around the 18th minute and continues discussing how to secure and monitor AI for several minutes.
Not with AWS public IPs. Cato can only inspect inbound traffic terminated on Cato public IPs via Remote Port Forwarding.
Cato is a SaaS platform and cannot locally inspect traffic inside your AWS VPC.
Not natively. Consider:
- Cato API
- CatoCLI
- Terraform provider
Fully adopting identity‑based policies (ZTNA) instead of legacy IP‑based access controls.
It depends:
- Windows + SCIM + Azure AD Join/Hybrid = no license needed
- macOS = license currently required
- On‑prem AD join = SCIM not supported (use LDAP)
SCIM does not support on‑prem AD joined devices. These must use LDAP provisioning.
Common causes include:
- Internet Recovery option not enabled
- Device posture checks failing
If issues persist, Support should investigate.
Yes, use the “contains” filter for domain‑based event searching.
- User connects to the Cato Portal
- Portal creates a policy
- Cato initiates a connection to your internal resource
Without Source NAT, the internal server sees a Cato public IP. Source NAT forces it to appear from a private IP instead.
Not today, traffic uses the default QoS queue. Idea Hub submissions encouraged.
Yes. The list is expanding, and domain/FQDN bypass is available in EA via your account team.
These topics require SME confirmation and will be answered on the community once available:
Pending SME validation.
Pending SME validation.
Drop them in the community anytime or join our next AMA.