Settings That Can be Modified by Cato Support

There are many advanced settings that can be modified on an account or site level by Cato Support. Many of these settings are not visible in the Cato Management Application or the Socket, so please contact us if you would like any of these settings applied.

Application

SettingDescriptionDefault Value
Application FinalizationIncreases the time that Cato waits before finalizing application identification.2000 milliseconds
Force FragmentationForces fragmentation of packets even if the DF bit is set. Each app that requires fragmentation must be defined.Disabled

 

IPsec

SettingDescriptionDefault Value
Dangling SAsForce Cato to rekey phase 2 following a phase 1 rekey.If phase 2 is not expired, use the existing SAs.

 

Networking

SettingDescriptionDefault Value
Cato Service RangeChange the subnet reserved by Cato for system traffic.10.254.254.0/24
ICMP Keep AliveGenerate an ICMP keep alive through a tunnel.Disabled
Max Flows per HostChanges the maximum number of flows that a single IP can open at once.20,000
Max Hosts per TunnelChanges the maximum number of hosts per tunnel10,000

 

Security

SettingDescriptionDefault Value
Whitelist IPPrevent any client IP address from being blocked by any Cato security policy. Useful for vulnerability scans.Disabled
Whitelist IPS signatureWhitelist specific threats from IPS for the whole accountDisabled 

 

Socket

SettingDescriptionDefault Value
Bypass Flow TimeoutChange the flow timeout for bypassed traffic on the Socket. Can also be adjusted in the Socket Web UI under Cato Connection Settings, but it will be reset back to default following a reboot or tunnel disconnect.60 seconds
GUI Access from InternetAllows access to the Socket GUI from the Internet, such as through Remote Port Forwarding.Access to the Socket GUI from the internet is blocked.
HAChange HA failover behavior depending on whether the Socket has internet access or a tunnel established to a PoP. Also sets the grace time for failover.If a Socket loses internet access, failover will occur in 10 seconds. If the Socket has internet access but no tunnel established to a PoP, failover will not occur.
MTUChange the Socket's WAN interface MTU.

MTU is set using PTMUD from the PoP to the Socket.

 

Preferred IPChange the PoP preferred IP for a Socket. This can also be done in the Socket Web UI under Cato Connection Settings.Dynamic

 

User Awareness (UA)

SettingDescriptionDefault Value
Event IDsExcludes a Windows Event ID generated on a Domain Controller from triggering an IP mapping for a user.Event IDs 4768, 4769, 4770, 4624, 5145, 5140
Windows UAEnables UA for other operating systems other than Windows.Windows only

 

SDP Client

SettingDescriptionDefault Value
MFA Prompt Grace TimeWhen "Always Prompt" is enabled for MFA authentication, this setting determines how long a Client will not be prompted for an MFA code on future reconnects following a successful connection.5 minutes
SSO Expiration PeriodChange the SSO cookie expiration period. This setting determines when a VPN user authenticating with SSO will need to re-enter credentials.30 days
Blocklist of OS for SDP ClientIdentify the Client OS type, and if it appears in the account blocklist - fail the connection processDisabled 
Cato Client behind SocketDetects if a Cato Client is behind a socket or not. If a socket was detected, the Socket tunnel will take precedence over the client tunnelEnabled 

 

Was this article helpful?

5 out of 5 found this helpful

0 comments