CATO is a pioneering solution in network security, developing Secure Access Service Edge technology, which combines security and business communication capabilities in a single cloud-based platform. Aligned with Gartner’s Secure Access Service Edge (SASE) and Security Service Edge (SSE) frameworks, Cato’s vision is to deliver a next-generation secure network architecture that eliminates the complexity, cost, and risks associated with legacy IT approaches based on disjointed point solutions. With Cato, organizations securely and efficiently connect any user to any application anywhere in the world. Its cloud-native architecture allows Cato to quickly deploy new capabilities and maintain the right level of security, without any effort from IT teams.
Characteristics
Migrating from MPLS to SD-WAN: Cato allows customers to replace or extend MPLS using Cato’s SD-WAN and multiple ISP links. This allows your customers to increase capacity and improve resiliency, for the same or lower cost than MPLS. Optimized Global Connectivity: With high-latency and packet-loss customers in mind for global locations and users, Cato achieves predictable access and accelerates access to on-premises and cloud applications. Cato’s private, global core network incorporates WAN and cloud optimization to enhance the network experience anywhere. Secure Internet Access for Branch Offices: It provides a complete network security battery that converges on Cato Cloud. By connecting all locations to the Cato Cloud via Cato Socket SD-WAN appliances, all traffic, both internet and WAN, is fully protected by Cato service security. Cloud Control and Automation: Accelerate cloud access by directing traffic from all edges to the Cato PoP closest to the cloud destination. As Cato PoPs are located at major cloud providers, latency between Cato and these providers is close to zero. Device security and optimization: Cato’s network security battery protects mobile users from threats anywhere and enforces company security policies.
Cato Products
SSE 360: Cato’s cloud-native security foundation, SSE 360, is built using the Cato Single Pass Cloud Engine (SPACE) architecture and converges the following capabilities: Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), Zero Trust Network Access (ZTNA/SDP), and Firewall as a Service (FWaaS) with Advanced Threat Prevention (IPS, Next Generation Anti-malware). SSE 360 scales to decrypt and inspect all enterprise traffic, without the need to size, patch, or update appliances and other point solutions. Security policies and events are managed centrally and uniformly using the Cato self-service management application. Remote Access: Cato SASE Cloud provides users with Zero Trust Network (SDP/ZTNA) access to both on-premises and cloud applications using laptops, tablets, and smartphones. With a Cato client or client browser access, users securely connect to the nearest Cato PoP using strong multi-factor authentication. Traffic flows only to applications that are authorized for users based on the user’s identity, access policy, and context. Throughout the session, traffic is fully inspected by Cato’s security stack to prevent the spread of malware from compromised endpoints. SD-WAN Edge: The Cato Socket SD-WAN appliance connects a physical location to the nearest Cato PoP via one or more last-mile connections. Customers can choose any combination of fiber, cable, xDSL, and 4G/LTE connections. The Socket applies multiple traffic management capabilities, such as the use of active-active links, prioritization of QoS based on applications and users, dynamic path selection to address link outages and brownouts, and packet mirroring to overcome packet loss. The Socket can also route site-to-site traffic over MPLS and the Internet to address regional and application-specific requirements. Global Private Backbone: Cato SASE Cloud runs on a private global backbone of over 75 PoPs connected through multiple SLA-backed network providers. PoPs software continuously monitors providers for latency, packet loss, and jitter to determine, in real-time, the best route for each packet. Cato’s backbone design offers end-to-end path optimization for WAN and cloud traffic, and a self-healing architecture for maximum service uptime. Our customers experience connectivity superior to the unpredictable public internet and more affordable than global MPLS and other legacy backbones. Multi-Cloud /Hybrid cloud: Cato integrates with leading cloud providers, such as Amazon AWS, Microsoft Azure, and Google Cloud, with secure IPSec tunnels or a Cato vSocket virtual appliance. Deployment is quick and easy, and connecting a cloud data center to Cato takes minutes.
All traffic to and from the cloud data center undergoes full security inspection by Cato’s integrated security stack, SSE 360, and is optimally routed from the edge to cloud providers. With Cato, customers can eliminate the need for premium cloud connectivity solutions, such as AWS DirectConnect and Microsoft Azure ExpressRoute. SaaS optimization: Cato optimally directs traffic to public cloud applications, such as Office 365, Salesforce, Box, UCaaS, and Cloud ERP, from the enterprise edge to the cloud application’s data center doorstep. Cato accelerates end-to-end performance by up to 20x, boosting application performance for bandwidth-intensive operations such as uploading and downloading files. All traffic and files exchanged with the cloud application are fully inspected by Cato’s security stack, SSE 360, to protect users from threats, attacks, and data loss. Cato Management Application: Cato provides a cloud-based, self-service management application to control the entire service. It includes a complete configuration of network and security policies, as well as a detailed analysis of network traffic and security events. Self-service management is a unique advantage of Cato over legacy managed network service providers that require customers to submit tickets for any network changes. If needed, Cato and its partners offer managed services options. In all cases, Cato maintains the underlying platform, so customers do not need to upgrade, patch, or otherwise maintain the Cato SASE Cloud.