Endpoint Device DNS Resolution
When Cato is handling DHCP and DNS for all devices within an account across multiple vlans, across multiple sites, is it possible for a device to resolve the IP of a hostname outside of the local subnet that the device is on, using Cato DNS to resolve the hostname? We historically have had on-prem Windows AD providing DHCP/DNS which reliably provided name resolution from hostname to IP, but also reverse DNS for IP back to hostname. We are moving to Entra ID/Intune+Auto Pilot managed devices with the outlook to retire our on-prem servers entirely. We have various use cases where we need to resolve a hostname to have the IP returned, but also for the IP to resolve back to hostname via reverse DNS. This has become difficult for Entra ID managed devices unless the device is on the same local subnet where the site switch manages the resolution via the local mac table. Is mDNS the right approach and where I should focus my attention or is there an alternative I should consider? As is looks like mDNS is restricted to vlans within the same site, it may not work in our scenario where we need to resolve across sites. Any advice or recommendations are greatly appreciated.54Views1like5CommentsIdentifying the Cause of LDAP Synchronization Failure
Hello, We have been synchronizing accounts with an on-premises LDAP server. The synchronization worked normally until July 2nd, but it stopped working from July 3rd. We want to identify the cause, but it is difficult to investigate because the source IP shown in the web UI is different. Does anyone have any ideas on how to perform something like a traceroute from the source IP used for LDAP synchronization? Thank you for your assistance.17Views0likes3CommentsPolicy Rule Not Hitting When Destination is Set to 'Any' – Expected Behavior?
Hi all, I ran into a situation with a security policy in Cato and would like to hear if anyone else has experienced something similar. Here is the scenario: I created a policy where the source site is set to "Site A", the destination is set to "Any", and the application is defined as a specific IP address, for example 192.168.1.1. In this setup, the rule does not match and traffic is not allowed as expected. However, when I change the destination from "Any" to the specific site where 192.168.1.1 is located, the rule starts working correctly and the traffic is matched. My questions: Is this expected behavior in Cato? Does using "Any" as the destination somehow prevent matching traffic to a specific internal IP? Is there something else I might be missing? Appreciate any insights or experiences. Thanks!78Views0likes2CommentsIs there a way to restrict access to the WebUI?
Hi all, Some of our customers want to restrict access to the Web UI from the local networks of the socket. However, even though I write LAN FW rules, the local IPs will respond to the HTTPs request from every network on the LAN port, even if that is a guest network. Is there any way to restrict access to the WebUI? If not, isn't such a configuration necessary? Thank you,Solved94Views1like4CommentsLAN NGFW and Segmentation
Hi all, This is probably a dumb question but I was looking at the recent news about Cato supporting LAN NGFW and checking EAST-WEST traffic. My question is, does this mean the Cato Sockets act as the Gateway for each VLAN? I'm just wondering how the sockets would cope with the amount of traffic going through them and getting inspected. But maybe I'm off base entirely.Solved65Views0likes2CommentsCATO socket intermittent disconnection.
Hi everyone, i have experienced loss of connection from my ISP to CATO socket.. upon checking no any issues from ISP side no downtime. i already replaced LAN patch cable from ISP modem to CATO socket. and i restarted both devices. but still keep experiencing disconnection. how can i check or where can i download logs so i can see what is the root cause of CATO disconnection???98Views0likes3CommentsContainers and Network Rules
Hi! We use an IP container for storing large amounts of IP ranges and reference the container in Internet firewall rules. We have a problem we could overcome by referencing the IP Container in a Network Rule, but apparently, the container can only be used with firewall rules, not network rules. Does anyone have any suggestions on how to work around this? In simple terms, the requirement is to define specific IP ranges, to which traffic would then be routed through a NAT rule and a static IP.130Views0likes3Comments