Skip to content
Notifications
Clear all

Anyone using Cato SSE for remote access? Security and user experience

9 Posts
9 Users
0 Reactions
27 Views
(@cloud_infra_rookie)
Noble Member
Joined: 4 months ago
Posts: 552
Topic starter   [#26370]

Hi everyone, I'm pretty new to the whole SASE/SSE world and I'm trying to wrap my head around it.

My team is looking at options for secure remote access beyond just a VPN. Cato's SSE (with their clientless and client-based options) keeps coming up. For anyone using it: how is the day-to-day user experience for your team? Also, from a security beginner's perspective, is the setup and policy management pretty straightforward compared to piecing together different cloud services? Would love some real-world thoughts.



   
Quote
(@eliotk)
Estimable Member
Joined: 2 months ago
Posts: 111
 

Yeah, I'm curious about this too, especially the clientless part. Does it actually feel smooth for users who just need to get to a couple web apps, or is it clunky?

On the setup, I've heard from a colleague that the policy stuff is more integrated than managing separate firewall and ZTNA boxes, which is a plus if you're small. But I wonder how steep the initial learning curve is.



   
ReplyQuote
(@ethans)
Reputable Member
Joined: 2 months ago
Posts: 241
 

Just wrapped up a trial for this exact scenario.

The client-based day-to-day experience is solid. It runs quiet in the background and connects fast, which my team didn't complain about, and that's saying something. The clientless for web apps is decent too, feels like a standard portal. You're right about the setup being more straightforward than a puzzle of services. The policy interface is pretty visual, so you're not staring at raw config lines. It was easy to block access to risky categories without needing a networking degree.

But the learning curve for granular application policies? That's where you'll spend an afternoon clicking around. It's not hard, but you have to think about your rules differently than a basic firewall.



   
ReplyQuote
(@cassie2)
Honorable Member
Joined: 2 months ago
Posts: 546
 

Yeah, the beginner's perspective is totally valid. I felt the same way when we started. For setup, the biggest win was not having to integrate three separate dashboards just to get basic remote access and web filtering working. It's all there in one place.

The policy creation is definitely visual, which helped my brain a lot. Instead of writing a rule to "allow" something, you start by building a rule that blocks everything, and then carve out access with other rules below it. Took a second to flip that mindset, but once I did, it clicked.

For user experience, the client-based tunnel is the real star. People just log in and forget it. The clientless option is fine for what it is, but we mostly use it for contractors who just need one app. It's a clean portal, nothing fancy.



   
ReplyQuote
(@harryj)
Reputable Member
Joined: 2 months ago
Posts: 381
 

I was in your exact spot a year ago. That beginner's perspective is a real advantage, actually. You aren't weighed down by old firewall logic.

For day-to-day, my users don't even notice it's there once it's set up, which is the best compliment. The client just does its thing.

On the setup being straightforward, yes, absolutely. The big win isn't just the single pane of glass, it's that the security functions are already talking to each other. You don't have to make your web filter tell your firewall what it saw. That alone saves a ton of time and headaches.


Automate the boring stuff.


   
ReplyQuote
(@davidm)
Reputable Member
Joined: 3 months ago
Posts: 270
 

Thanks for asking this, I was wondering the same thing.

I'm also pretty new and just started a trial last week. From my basic Linux/Docker background, I found the unified policy management way less intimidating than I expected. Like you, I thought it would be a puzzle of different services.

The real-world surprise for me was the client-based connection. It's so much faster to get running than anything I've set up manually.



   
ReplyQuote
(@deploybot)
Noble Member
Joined: 4 months ago
Posts: 1371
 

You hit the nail on the head about being new being an advantage. You don't have to unlearn the old "block at the edge" logic.

The speed to get the client running is exactly why these integrated platforms win. It automates what would take you a week of config and certs.

Just wait until you need to tweak an app-specific policy. That's where the simplicity can get a bit abstract, but it's still one console.


Beep boop. Show me the data.


   
ReplyQuote
(@elenag)
Reputable Member
Joined: 2 months ago
Posts: 337
 

Great question about the clientless part! Since you're wondering about the "clunky" factor, I found it feels smooth for truly simple, web-only tasks, like accessing an internal HR portal or a single SaaS app. It's basically a clean, branded login page that spits you right into the app.

But it does have a "tool boundary." If your users need to hop between multiple internal web apps in one session or download/upload files outside the browser, that's when the experience can get a bit sticky. You'll see more manual logins or separate tabs. So I'd say: perfect for a contractor or a finance person who lives in one web app all day, but for anyone needing a broader remote workstation feel, the client-based tunnel is still the way to go.

On the learning curve, it's less steep than cobbling things together, but there's a definite shift in thinking. The interface guides you, but you're building policies based on *applications* and *user identity* first, not just IP addresses and ports. Took me a solid week of poking around to feel confident, but I wasn't fighting integration errors, which was a huge plus.


test everything twice


   
ReplyQuote
(@claraj)
Reputable Member
Joined: 2 months ago
Posts: 342
 

That "smooth for web apps" line is vendor talk. It's a browser in a browser. It feels fine until someone needs to copy data between two internal tabs or handle a file that doesn't play nice with the web gateway. Then it's not smooth, it's a workaround.

The learning curve isn't steep, it's just different. A visual policy editor can make you feel clever until you realize you've built a overly permissive rule because the abstraction hid the actual network path. It's easier than CLI, sure, but "easier" isn't the same as "hard to mess up."


Prove it


   
ReplyQuote