Forum Discussion

FlowBeer's avatar
FlowBeer
Icon for Making Connections rankMaking Connections
3 months ago

Cato Client - manual PoP addressing

Has anyone tried scripting to change the manual pop location so the user can run the script and it will change their client manual pop address to a specific location.

Not sure where this detail is stored on windows for the client, regkey or config file?

Even a cato cli client with a switch to set it?

I tried using fqdns as the pop name and having it resolve to a PoP IP in the hosts file, then using a script to change the hosts file entry to the desired PoP IP.... but the client cant use fqdns as the PoP to connect to :D

12 Replies

  • michaelsaw's avatar
    michaelsaw
    Icon for Cato Professional Services rankCato Professional Services

    Hi FlowBeer, 

    Interesting point! Usually Cato Client would connect to the PoP that is most optimal.

    Just to understand better, is there a reason when you mentioned: "change the manual pop location so the user can run the script and it will change their client manual pop address to a specific location"? ___

    Cheers

     

    • FlowBeer's avatar
      FlowBeer
      Icon for Making Connections rankMaking Connections

      Hi Michael, delayed response sorry.

      Yes the reasoning is the chinese firewall still impacts traffic when a user connects to a chinese PoP and egresses, via Cato internal backbone, on another "out of country/non-China" PoP (eg HK or Tokyo). The only way to avoid being impacted by the chinese gov FW rules is to have the client tunnel built, end to end, directly to the HK/Tokyo PoP.

  • Nath's avatar
    Nath
    Icon for Staying Involved rankStaying Involved

    What's the context, why do you want to do that?

    • FlowBeer's avatar
      FlowBeer
      Icon for Making Connections rankMaking Connections

      I need a simple way for users to adjust and specify the PoP they are connecting to.

      • Nath's avatar
        Nath
        Icon for Staying Involved rankStaying Involved

        The client normally determines the closest (in terms of latency) PoP to connect to.  Once they are connected, can you not use Network Rules to determine where the user traffic egresses from?  We use a lot of NAT egress rules, and also ROUTE rules and BACKHAUL rules.

        For example, my laptop could connect to a PoP in Ireland, but all the internet traffic could egress via China if you wanted.