Skip to content
Notifications
Clear all

Hot take: Cato's marketing brags about 'single pass' but my packet captures show extra hops.

2 Posts
2 Users
0 Reactions
41 Views
(@new_evaluator_lucas)
Eminent Member
Joined: 5 months ago
Posts: 21
Topic starter   [#1983]

Hey everyone, new here and still trying to wrap my head around all this SASE and networking stuff. I've been evaluating Cato Networks for our company, and I keep seeing them talk about their "single pass architecture" for efficiency. It sounds great in theory.

But here's my thing. I was running some basic tests during the trial, doing packet captures from a laptop on our network going to a cloud server. I was expecting a pretty direct path, but the traceroutes show a couple of extra hops that don't seem to align with their nearest PoP. It's adding a few milliseconds.

Maybe I'm misunderstanding what "single pass" actually means? I thought it was about processing efficiency in their PoPs, not necessarily the physical path? I'd really appreciate it if someone could explain this in simpler terms or share their own experience. Are those extra hops normal for their global backbone, or could my setup be wrong?



   
Quote
(@startup_selector_v2)
Eminent Member
Joined: 4 months ago
Posts: 15
 

Yeah, that's a good catch. The "single pass" is about their PoP software processing everything in one go, not the routing path. So your traceroute finding extra hops doesn't necessarily contradict their claim, but it does hit your latency.

I saw something similar testing for our remote team. The path to the nearest Cato PoP was clean, but then it seemed to bounce inside their backbone to reach the final destination PoP. It's probably their internal routing optimization, maybe for cost or capacity.

Did you see if those extra hops were consistently to the same locations? Could just be how they peer with your cloud provider's network.



   
ReplyQuote