Skip to main content
The Cato Networks integration combines content-aware gateway routing with native network enforcement. Supported AI protocols can be decrypted and rerouted to Forge. The larger Forge AI catalog is governed directly through Cato policy and observed through the Events feed.

Enforcement modes

Native enforcement minimizes added latency and does not send decrypted traffic to Forge. Content-aware routing is reserved for protocols where Forge can reconstruct and govern the interaction.

Content routing

Forge provisions the inspection CA and a bounded TLS-inspection and routing configuration for the selected AI destinations. Managed clients must trust the inspection CA through the organization’s existing certificate-management process. The Forge rerouter classifies the decrypted protocol and directs model and browser traffic to the LLM Gateway and MCP traffic to the MCP Gateway. The gateway applies identity, access, and content controls before calling the original upstream. Forge previews inspection scope, route targets, excluded traffic, provider changes, verification, and rollback before apply. Certificate pinning, TLS bypass, QUIC, ECH, and routes outside the configured Cato scope remain explicit coverage gaps.

Native policies

Forge compiles broad Access policies into the applicable Cato Internet Firewall or Application Control rule. The compiled rule retains subject, destination, application/category, action, logging, and ordering semantics supported by Cato. Policy read access supports provider-state comparison and change preview. Publishing requires a separate write credential, explicit confirmation, provider readback, and rollback verification. The policy executes in Cato’s network path. Forge receives its decision later through the Events feed and uses that evidence for inventory, attribution, and analytics.

Sources

Collection preserves Cato markers and advances them only after the bounded batch is persisted. Records that cannot be safely correlated remain unresolved with their provider entity references.

Connection

Setup

  1. Connect the Cato account and test event, audit, entity, policy, TLS, routing, and source-health capabilities independently.
  2. Enable content-aware routing for the supported AI destinations in scope.
  3. Review and confirm the CA, TLS-inspection scope, Forge routing target, exclusions, provider readback, and rollback plan.
  4. Compile broad Access policies into Cato for the remaining AI catalog.
  5. Verify a routed gateway session and a separate native Cato policy event in Forge.
Cato events alone do not prove prompt, response, or tool visibility. Content inspection requires a verified route through a Forge gateway.