The most recent content from our members.
We had been under the impression that by enabling a Geoblock rule in the Client Connectivity Policy for Hong Kong, that would prevent any of our travelling users from connecting to a Hong Kong PoP. I have been informed by Cato support that this is not the case. "Regarding Hong Kong specifically, Hong Kong is not a Chinese…
We currently have an on-premises Active Directory and have Pre-Login enabled with connect at boot enabled. We defined internal destinations (domain domain controllers) as allowed destinations, so the devices can reach the domain controllers before the user has logged in. This worked fine so far. However, now we want to…
Searching in new KB for roadmap reveals no roadmap, but lots of product updates that are in the KB that link to the roadmap document. All the links are either bit.ly (which gives the user an error) or the old KB (which gives the user an error). Could it be addressed that the roadmap is reinstated, and I would highly…
It takes about 40 minutes once the user is deleted from from the IDP. Are there any other options for disabling a SCIM user? My thought was to create a WAN firewall rule to deny the user access until the scim update happens. Currently user are setup for split tunneling so I wouldnt need an Internet FW rule but if split…
We are planning to migrate from Cato Directory Services LDAP & User Awareness to Cato SCIM user provisioning and looking to get some feedback if anyone has performed this migration and if they encountered any issues during the migrations. We currently have a few domains, over 3500 users and not everyone has an SDP lic, a…
Hi, We have been a Cato customer for just over a year now and we have a hybrid network Infra, of some onprem servers and new workloads been hosted in both AWS & GCP. My question is around the use of existing OpenVPN for accessing our AWS trusted VPCs and users having issues with Cato SDP and OpenVPN clashing for DNS/routes…
We would like to request CATO Team to consider adding Cisco DUO to the SSO identity provider list.
HTTP Version Not Supported Your client is using HTTP version 1.1, which is not supported. This service requires HTTP/2. Please update your client or contact support Reply from Cato Support : I have confirmed internally that HTTP/2 is not supported yet.
I’m looking for guidance on configuring a Windows CA to issue and validate RSA certificates for device posture verification in Cato. Has anyone implemented this integration?What’s the best approach for certificate management? Should we use self-signed certificates or purchase individual device certificates from DigiCert or…
📣 Cato Rapid Recap | June 2025 Staying current on the latest features, best practices, and platform improvements isn’t always easy. That’s why I’m kicking off a new 2-minute monthly recap — designed to help you: * ✅ Quickly catch up on what’s new * ✅ Share relevant updates with prospects, POCs, and customers * ✅ Stay…
It looks like you're new here. Sign in or register to get started.