Skip to content
Notifications
Clear all

Switched from Cato back to direct internet + cloud proxy, no regrets.

1 Posts
1 Users
0 Reactions
4 Views
(@procurement_pro_2026)
Eminent Member
Joined: 5 months ago
Posts: 15
Topic starter   [#1854]

Having recently concluded a significant network transformation project, I feel compelled to share our team's analysis and experience. After a three-year engagement with Cato Networks SASE platform, we have made the strategic decision to revert to a more traditional architecture: direct internet breakouts at major sites paired with a cloud-based secure web gateway (SWG) and cloud access security broker (CASB) proxy. This was not a decision taken lightly, but a calculated move following a thorough Total Cost of Ownership (TCO) review and a reassessment of our actual security and performance requirements.

Our initial rationale for adopting Cato was sound, aligning with common industry drivers:
* Simplified management of a global, hub-and-spoke SD-WAN with integrated security.
* Reduction in appliance sprawl and associated lifecycle management.
* Consolidated vendor accountability for network and security performance.

However, over the multi-year term, several key factors eroded the perceived value proposition, leading to our exit.

**Primary Drivers for the Re-architecture:**

* **Cost Escalation at Scale:** The per-megabit pricing model became increasingly burdensome as our bandwidth needs grew organically. The TCO analysis, projecting over five years, showed a substantial cost delta compared to procuring commodity internet circuits and leveraging a cloud proxy service with user-based licensing. The "all-in-one" premium became difficult to justify financially.
* **Performance Latency Concerns:** While Cato's global backbone is robust, the inherent hair-pinning of all traffic (including internet-destined) to the nearest PoP introduced measurable latency for cloud applications hosted in regions adjacent to our branches. Direct local internet breakouts provided a superior user experience for SaaS platforms like Microsoft 365 and AWS.
* **Vendor Lock-in and Inflexibility:** The tightly integrated nature of the platform made incremental changes complex. Introducing a best-of-breed tool for a specific need (e.g., advanced DLP, or a niche SaaS monitoring tool) was often problematic without traversing the Cato stack. Our new disaggregated model grants us significantly more flexibility in tool selection and integration.
* **Renewal Negotiation Leverage:** When approaching the renewal cycle, the lack of a viable migration path and the integrated nature of the platform severely limited our negotiating position. By designing and implementing our new architecture *before* the contract expiry, we restored our leverage and could negotiate with both the proxy vendor and our ISPs from a position of strength.

**Implementation Overview & Key Considerations:**

Our new topology is straightforward: each major site has a direct internet egress via dual ISPs, handled by next-generation firewalls configured for basic segmentation and redundancy. All user traffic is then routed to a cloud-based SWG/CASB service for consistent security policy enforcement, threat protection, and data loss prevention, regardless of user location. Remote users connect directly via the same cloud proxy client.

Critical success factors for this project included:
* Conducting a detailed application dependency mapping to ensure direct breakout would not break legacy on-premise applications.
* Implementing robust monitoring and analytics from the outset to compare pre- and post-migration performance metrics (latency, jitter, throughput, threat events).
* Phasing the migration site-by-site to de-risk the transition and validate the TCO assumptions in practice.

The result has met or exceeded our key objectives: reduced operational costs, improved performance for critical cloud applications, and regained strategic flexibility in our security tooling. This architecture may not be optimal for all organizations—particularly those with a vast number of micro-branch sites or extremely limited IT staffing for network management. However, for our enterprise profile, the decoupled model proved to be more economically and technically advantageous.

I am happy to elaborate on specific aspects of the TCO model or the migration workflow if there is interest from the community.

- PPro


PPro


   
Quote