Connect
Open Integrations → Cato Networks. Enter your Cato account ID, regional API endpoint, and API key with read access to EventsFeed. Use the API endpoint for your account’s Cato Management Application region. Save the connection to start discovery. The connection stores the API key encrypted. Discovery can be paused and resumed without changing Cato network rules. Disconnecting revokes the Forge connection and deletes its credential.Discovery
The discovery tab shows whether polling is enabled, the last successful poll, retained AI observation count, latest AI observation time, and bounded source errors. Forge reads all feed records and retains only catalog-matched AI observations. Invalid and unmatched records are skipped before identity lookup or event storage. If the catalog is unavailable, polling fails without advancing the checkpoint. Forge saves a checkpoint after matched observations and their catalog projections succeed, including pages with no matches. Repeated pages reuse the same source event identities. Cato events provide application and network metadata. Cato’s reported allow or block action is historical provider evidence. Events do not contain Forge inspection decisions or prompts and responses. User evidence is preserved when supplied by Cato; Forge does not turn a source IP into an employee identity. EventsFeed retains its queue for approximately three days. A marker or source error stays visible and does not silently reset the checkpoint. Application visibility depends on the events Cato generates.Internet backhaul steering
Cato Networks steering is under development and is not available for customer activation yet. Forge is implementing synchronous Internet Traffic Backhauling over a customer-specific IKEv2/IPsec connection. The intended traffic path is:Availability and validation
Do not create production backhaul rules from these planned prerequisites. Activation requires live allow/block/recovery, identity, certificate, and rollback validation. API connectivity or a configured tunnel alone does not prove inspected traffic.Planned prerequisites
The code-only integration expects:- a Cato API key scoped to the account with Sites, Network Rules, and TLS Inspection permissions;
- a unique private network range for each Forge attachment;
- primary and optional secondary IKEv2 sites using the Forge gateway FQDN and the generated pre-shared secret;
- Cato Internet Network Rules that Forge owns and routes with
BACKHAUL; - TLS Inspection bypass rules for destinations that Forge decrypts; and
- an inspection subordinate certificate signed by a CA the endpoints already trust when Forge content inspection is required.