Recent Discussions
Wireless Traffic Identified as DSCP18
This is driving me up the wall and I don't see a lot of good options, aside from pester support. We're an Aruba wireless shop and we have some WMM/QoS configured. This ends up with a bunch of events where the Application/Service detected is dscp18 because Cato is picking up on the QoS value from the access point. It makes my life difficult when we try to create WAN Firewall rules based on a service on a given destination(s). Aside from de-allocating that DSCP value on my production SSID's, what can I do? Has anyone else encountered this before?MichaelQ9 days agoComet31Views0likes4CommentsAzure Virtual Desktop Session Host Routing
Hi, has anyone ever set up a route table on Azure so that the route to Microsoft Login subnets goes out through Cato? When we tried doing this, to make sure our AVD users are protected by Cato, users stopped being able to connect to session hosts through the AVD FQDN (broker). I suspect that its either TLS Inspection being enabled for Microsoft Login app (has never been an issue for our laptop users), or that AVD brokering system needs Microsoft Login traffic to go through the internet instead of a private route for some reason.59Views0likes2CommentsNetwork routing
Need some confirmation with the routing configuration. Under the Network routing, I can only see the UI says Subnet but I am pretty sure we should be able to route a host say 1.1.1.1/32 as well. The UI does not allow you to put 1.1.1.1/32. Can I just put 1.1.1.1 without the mask and be OKAY?SolvedAbn2 months agoMeteor56Views0likes2CommentsConnectivity Alert Email - Interface Names
Hello, By default, the notification emails regarding a disconnected or degraded socket interface include the public IP address of the interface under "Interface Name". This does not match the port name in the socket configuration panel. Is it possible to modify this email template to include the descriptive name instead of, or ideally in addition to, the public IP address? This would be extremely helpful for quickly identifying which ISP is impacted. Not all network engineers have every single public IP in the company committed to memory! (Pictures have been redacted/edited to remove or alter sensitive information)aekcmi3 months agoMeteor145Views2likes10CommentsCATO Client still connected in a trusted network
Hello! Is it normal that my CATO client stay connected event if i'm in a trusted network? The Alway on status is Enforced (Suspend) I can disconnect my client, but i was wondering if it's not disconnecting itself. Thanks a lot!Steph3 months agoComet59Views0likes1CommentDirected Broadcast?
Short & sweet: can CATO do Directed Broadcast? Yes, it's for WoL between sites.SolvedBrad3 months agoComet51Views0likes1CommentDHCP option to assign Cisco Wireless Controller
Hi Community, We have some sites that I'm trying to set a DHCP option to assign the controller IP to cisco 9105. I have a vendor rule on the AP's that get DHCP from our Microsoft DHCP servers. Was just curious if anyone has configured an option that works through Cato DHCP? Thank you.59Views0likes1CommentX1700 Sockets running 22.0.19219 breaks HA
More of a caution, over the weekend we upgraded our sockets to 22.0.19219. No issues with our X1500's but sites running X1700's in an HA pair caused us some trouble. The HA keepalive no longer works, which was causing traffic to switch between Primary and Secondary sockets. Both sockets are showing as master. Engineering has discovered the root cause and are working on new version of the firmware, but wanted to let you all know in cause you plan to upgrade soon. Sockets can't reach each other via IP, but both sockets are pingable from other devices on the network.Chris_OT4 months agoComet71Views3likes0Comments