Skip to main content
Connect Cato Networks to observe AI activity in Forge inventory and Shadow AI. Forge reads the EventsFeed API asynchronously and matches reported applications and destination domains against the AI catalog.

Connect

Open Integrations → Cato Networks. Enter your Cato account ID, regional API endpoint, and API key with read access to EventsFeed. Use the API endpoint for your account’s Cato Management Application region. Save the connection to start discovery. The connection stores the API key encrypted. Discovery can be paused and resumed without changing Cato network rules. Disconnecting revokes the Forge connection and deletes its credential.

Discovery

The discovery tab shows whether polling is enabled, the last successful poll, retained AI observation count, latest AI observation time, and bounded source errors. Forge reads all feed records and retains only catalog-matched AI observations. Invalid and unmatched records are skipped before identity lookup or event storage. If the catalog is unavailable, polling fails without advancing the checkpoint. Forge saves a checkpoint after matched observations and their catalog projections succeed, including pages with no matches. Repeated pages reuse the same source event identities. Cato events provide application and network metadata. Cato’s reported allow or block action is historical provider evidence. Events do not contain Forge inspection decisions or prompts and responses. User evidence is preserved when supplied by Cato; Forge does not turn a source IP into an employee identity. EventsFeed retains its queue for approximately three days. A marker or source error stays visible and does not silently reset the checkpoint. Application visibility depends on the events Cato generates.

Internet backhaul steering

Cato Networks steering is under development and is not available for customer activation yet. Forge is implementing synchronous Internet Traffic Backhauling over a customer-specific IKEv2/IPsec connection. The intended traffic path is:
Forge will manage the backhaul rule, destination updates, provider readback, drift repair, rollback, and cleanup through Cato’s GraphQL APIs. The initial release uses IPsec only.

Availability and validation

Do not create production backhaul rules from these planned prerequisites. Activation requires live allow/block/recovery, identity, certificate, and rollback validation. API connectivity or a configured tunnel alone does not prove inspected traffic.

Planned prerequisites

The code-only integration expects:
  • a Cato API key scoped to the account with Sites, Network Rules, and TLS Inspection permissions;
  • a unique private network range for each Forge attachment;
  • primary and optional secondary IKEv2 sites using the Forge gateway FQDN and the generated pre-shared secret;
  • Cato Internet Network Rules that Forge owns and routes with BACKHAUL;
  • TLS Inspection bypass rules for destinations that Forge decrypts; and
  • an inspection subordinate certificate signed by a CA the endpoints already trust when Forge content inspection is required.
Forge keeps customer and Cato-managed policy objects intact. Disable and rollback remove only Forge-owned rules and sites created by Forge. Site and policy creation, private-revision readback, publish, effective readback, drift repair, and cleanup are automated where Cato exposes the required API. Cato backhaul traffic does not include an authenticated HTTP identity header. Forge associates the preserved Cato source address with the current user and device before applying identity-aware policy. The observation connection reads EventsFeed independently of backhaul steering. Forge does not compile Forge Access policies into Cato-native enforcement rules. Inspected HTTP traffic can create Traffic, Session, and Shadow AI request evidence. Opaque TLS passthrough creates connection-level Shadow AI network evidence only; Forge does not invent request or Session records from SNI. Customer setup and availability requirements will be published after live traffic, identity, certificate, failure, and rollback qualification is complete. References: Cato IPsec Internet backhauling, Cato GraphQL API, and Cato technical guidelines.