Enforcement modes
Native enforcement minimizes added latency and does not send decrypted traffic
to Forge. Content-aware routing is reserved for protocols where Forge can
reconstruct and govern the interaction.
Content routing
Forge provisions the inspection CA and a bounded TLS-inspection and routing configuration for the selected AI destinations. Managed clients must trust the inspection CA through the organization’s existing certificate-management process. The Forge rerouter classifies the decrypted protocol and directs model and browser traffic to the LLM Gateway and MCP traffic to the MCP Gateway. The gateway applies identity, access, and content controls before calling the original upstream. Forge previews inspection scope, route targets, excluded traffic, provider changes, verification, and rollback before apply. Certificate pinning, TLS bypass, QUIC, ECH, and routes outside the configured Cato scope remain explicit coverage gaps.Native policies
Forge compiles broad Access policies into the applicable Cato Internet Firewall or Application Control rule. The compiled rule retains subject, destination, application/category, action, logging, and ordering semantics supported by Cato. Policy read access supports provider-state comparison and change preview. Publishing requires a separate write credential, explicit confirmation, provider readback, and rollback verification. The policy executes in Cato’s network path. Forge receives its decision later through the Events feed and uses that evidence for inventory, attribution, and analytics.Sources
Collection preserves Cato markers and advances them only after the bounded
batch is persisted. Records that cannot be safely correlated remain unresolved
with their provider entity references.
Connection
Setup
- Connect the Cato account and test event, audit, entity, policy, TLS, routing, and source-health capabilities independently.
- Enable content-aware routing for the supported AI destinations in scope.
- Review and confirm the CA, TLS-inspection scope, Forge routing target, exclusions, provider readback, and rollback plan.
- Compile broad Access policies into Cato for the remaining AI catalog.
- Verify a routed gateway session and a separate native Cato policy event in Forge.