Forum Discussion

DScott's avatar
DScott
Icon for Joining the Conversation rankJoining the Conversation
1 month ago

AWS - OpenVPN routing clash for Cato SDP

Hi,

We have been a Cato customer for just over a year now and we have a hybrid network Infra, of some onprem servers and new workloads been hosted in both AWS & GCP.

My question is around the use of existing OpenVPN for accessing our AWS trusted VPCs and users having issues with Cato SDP and OpenVPN clashing for DNS/routes etc.. when trying to access the AWS vs. Onprem server environments.

We need staff to be on Cato SDP all the time for montioring, audting and best security practices.. however it clashes with some users who need OpenVPN AWS access. What do other companies do to get around this issue (if they have a similar routing issue at all?). Split tunnel vs. AWS marketplace Cato virtual socket (EC2 instance needed per account?).

I would be very interested to see if others have seen or have a good work around to this dilemia. 

1 Reply

  • andy's avatar
    andy
    Icon for Making Connections rankMaking Connections

    Hi

    I would suggest to integrate your whole AWS & GPC environment into your Cato enviornment as a site.

    You can connect them via IPSec for Google or in AWS you have in AWS marketplace a Cato appliance available to deploy.

    But this needs then for each AWS & GPC environment also licenses on Cato side.

    Keep both VPNs running in parallel is definitly not the best idea.

    Best regards,

    Andreas