"cato is a solid product"
Its unified approach, ease of management, and strong security features are key. Specifically, the centralized management interface and the combined SD-WAN and network security on a single platform are often highlighted as benefits. Cato SASE Cloud is a popular cloud-native networking and security platform. Despite its strengths—like easy deployment, centralized management, and solid security integration—users and analysts may point out some common criticisms or drawbacks. Cato addresses several critical issues in modern enterprise networking and security. Here's a breakdown of the problems it solves and how that benefits organizations and users:
"Use Cato for VPN"
It's easy to handle from the console and user-friendly. However, it sometimes drops connection frequently and then reconnects. Previously, we used OpenVPN; we believe Cato is more secure than OpenVPN.
I
Information Security Manager
"CATO Networks: Feature-Rich Product with Significant Business Impact"
The console is easier to manage. The product is user-friendly because the deployment was custom-tailored to require no intervention, and the configuration exceeded all customer expectations. Implementing it has also been a great experience since migrating existing policies was quite easy. We use the product daily, and it has helped us address previous challenges while simplifying administration. Integration with several compatible OEMs was effective and substantial. Although the product meets use cases well, customer support is a key highlight, offering excellent technical assistance and ease of use. There are no dislikes as of now. We need more evaluation to find any drawbacks. POP selection is based on region. It's effective for events and offers a variety of customization options to delve into event details. Adding more features increases the product's effectiveness.
"Cato SASE"
Cato unifies Next-Generation Firewall (FWaaS), Secure Web Gateway (SWG), Intrusion Prevention System (IPS), Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA) on a single platform, guaranteeing uniform security policies for all users and locations. Feature Gaps: Pricing can be complicated or expensive for smaller orgs or certain use cases. Limited Customization: Since it's a managed service, it may provide less flexibility than traditional on-prem solutions. ZTN and SD-WAN are included.
"Exceptional Connectivity and Security Across Latin America"
I want to emphasize its outstanding network connectivity and the extensive coverage it provides across Latin America. I also appreciate its security level, which works much like a SIEM. So far, I haven't encountered any flaws—all its features are superb. It helps resolve security issues effectively.
"CrowdStrike + JumpCloud Integration"
The combination of CrowdStrike Falcon, a top cloud-native endpoint protection platform, with JumpCloud's open directory platform offers a unified security approach that merges identity, device, and threat intelligence. This strong pairing helps organizations implement Zero Trust by linking endpoint health with identity-based access controls. The integration provides strong endpoint-identity correlation: CrowdStrike supplies real-time endpoint telemetry (e.g., threat detection, vulnerability status), while JumpCloud manages identity and access. When combined, policies can be enforced based on both device security state and user identity. Benefits include blocking access from compromised or non-compliant devices, supporting Zero Trust access models, and reducing lateral movement and insider threats. However, while both platforms have APIs and third-party connectors, the native integration isn't as plug-and-play as some vendor bundles (like Microsoft Defender + Entra). Some organizations may need custom scripts or middleware. Additionally, for small businesses, the combined cost of EDR (CrowdStrike) and identity/security tools (JumpCloud) could be prohibitive. Problem 1: Traditional Antivirus Can't Handle Modern Threats. CrowdStrike Falcon uses AI-driven behavioral analysis and threat intelligence to detect and stop advanced threats like ransomware, fileless attacks, and zero-day exploits in real time. Slow detection and response times are also an issue.
"Cato SASE Cloud: User-Friendly, Secure, and Comprehensive"
I love how easy it is to use and implement Cato—it deploys quickly and is simple to administer daily. The intuitive interface and centralized management streamline operations across multiple locations. Their support team is quick to respond and knowledgeable, resolving issues promptly. We rely on it regularly because it's reliable and feature-rich, covering secure access, threat prevention, and traffic optimization. Plus, it integrates seamlessly with our existing tools and identity providers, making the switch smooth and boosting productivity and security. On the downside, advanced customization and granular control are more limited than with traditional firewalls. Reporting and analytics could be more robust and flexible, and policy changes sometimes take a few minutes to take effect. While stable and improving, it's still maturing in some enterprise features. Managing diverse technologies (like different firewall types and MPLS) and integrations across various devices is tough. Cato's CMA helps streamline configuration across all sites in one step, reducing workload for network engineers and the security team.
S
System AdminiAdministrator
"Intuitive SASE with Outstanding Network Segmentation"
I'm most impressed with the all-in-one central platform that merges SD-WAN, firewall, SWG, CASB, and ZTNA in a single dashboard. It's quick to set up and onboard—spinning up a new site takes less than an hour—and everyday management is much simpler than handling multiple tools with separate interfaces and licenses. However, Cato doesn't offer certain advanced features like remote browser isolation, network sandboxing, or full DLP. It also doesn't come with a web application firewall, and its IDS/IPS capabilities could be stronger. Users often find it feature-limited compared to bigger vendor suites. Performance might be slower depending on connection quality or proximity to a PoP, causing bottlenecks. The licensing, based on bandwidth tiers, can be confusing or costly, especially for smaller businesses. Moving from legacy point solutions, such as on-prem firewalls, requires careful planning and operational changes. Traditional setups involve separate tools for SD-WAN, VPNs, firewalls, and SWGs, each managed individually. Cato consolidates them into one cloud-native platform, eliminating the need for 'swivel-chair troubleshooting' and easing overall infrastructure management. Legacy WANs often suffer from latency and packet loss, and MPLS is expensive. Cato's global private backbone ensures low latency, dependable performance, and redundancy, allowing fast site-to-site and internet connectivity. Disparate security appliances often lack deep inspection and consistent policy enforcement. Cato incorporates NGFW, IPS, SWG, CASB, anti-malware, and ransomware protection in a single-pass inspection model, ensuring uniform enforcement everywhere.
"Highly Effective, Fully Cloud-Based Solution"
It brings together SD-WAN, firewall-as-a-service, secure web gateway, and zero trust network access into one cloud-native package. This doesn't just make management easier but also cuts down on the number of vendors and point solutions. Even though the platform is streamlined and user-friendly, it may appear constrained when you need to enforce very niche or intricate security policies compared to more granular enterprise firewalls or separate tools. Cato tackles the issue of having a disjointed network and security setup. Many companies rely on a patchwork of solutions—firewalls, VPNs, SD-WAN, and CASBs from different vendors. That leads to overhead, security loopholes, and performance problems.
"Single Console for Network and Security: SD-WAN, NGFW, and ZTA Made Simple"
The best part is having both network and security in one place. Handling SD-WAN, NGFW, and remote access through a single interface cuts down on complexity and eliminates the hassle of dealing with multiple vendors. However, because it's a cloud service, you don't get the same level of fine-grained control as with on-prem gear, like custom routing rules or deep firewall tweaks. It saved me from the nightmare of juggling countless devices. Previously, troubleshooting a remote login issue or a slow branch connection meant checking the firewall, VPN, and router separately. Now it's all in one spot. This saves me a ton of time—tasks that took hours now take just a couple of clicks. In short, I sleep better at night because the network is much more reliable.