Customers often ask, which types of site is better - Cato Socket or IPsec. Cato always recommends that you use Socket deployments for a site.
These are some advantages that a Socket provides over an IPsec site.
For more information about comparing Socket vs. IPsec sites, please see Connecting Sites to the Cato Cloud.
Cato Socket Sites
-
Sockets include optimized PoP selection. This lets the Socket automatically connect to the best available PoP which minimizes network latency.
-
If there's a connectivity issue with the current PoP, Sockets automatically connect to the next optimal PoP.
Sockets with one link keep connectivity to the Cato Cloud if there's an issue with the current PoP.
-
Sockets include QoS services for upstream and downstream traffic.
-
Includes various Last Mile Monitoring tools and analytics.
IPsec Sites
-
IPsec sites are statically assigned to a specific PoP. If there is a connectivity issue with the current PoP, the site can be disconnected.
IMPORTANT: We strongly recommend that you configure a secondary tunnel (with different Cato public IPs) for high availability. Otherwise, there is a risk that the site can lose connectivity to the Cato Cloud.
-
Due to different implementations of the IPsec protocol, IPsec sites can experience connectivity issues.
-
QoS is applied for traffic in the downstream direction (from the Cato Cloud to the site). The PoP makes a best effort to apply QoS for upstream traffic.
-
IPsec sites only support Active Passive configurations.
3 comments
Does this also apply to Cloud Datacenters with vSockets?
Helo Elvind!
My apologies for not responding to this earlier! The AWS and Azure versions of the vSocket should provide the features defined here. You would need to check the relevant information for the different type of vSockets (AWS and Azure) to see if there are any other limitations. I recommend you check the following articles and let us know if they provide you with the information you are looking for:
Please let us know if this is the information you were looking for!
Kind Regards,
Dermot Doran (Cato Networks)
Hello,
Instead of using Azure vSocket, is it supported to use Azure Virtual Network Gateway and IPsec tunnels ?
Regards,
Pierre
Please sign in to leave a comment.