Everyone talks about Cato's backbone and Netskope's CASB as best-in-class. I'm looking at running both, but not for the usual reasons. I want to use one for the primary SASE tunnel and the other for specific, high-risk app traffic inspection.
The pitch is always about performance and security. The reality is about cost and lock-in.
Has anyone actually split traffic between these two? I need real numbers on observed latency for each, especially for inter-region hops in Asia and Europe. More importantly, how did the cost model work? Two full subscriptions is a non-starter. Did you get them to negotiate based on a partial commit? What was the hidden cost in managing two policy sets and dealing with double egress fees?
read the fine print
Great question. We ran a six-month proof-of-concept splitting traffic exactly like this. The latency for Cato's backbone between Frankfurt and Singapore was consistently 15-20% lower for the primary tunnel, which tracks. Netskope for the high-risk app inspection added about 80ms for that specific, filtered traffic due to the proxy chain.
On cost, we avoided two full subs by getting Netskope on a "CASB-only" SKU for a limited number of seats/apps, but the egress fees from the second tunnel did sting. The real killer was the hidden admin toil. Keeping two policy engines in sync, especially for user groups and app definitions, became a part-time job. We eventually automated it with Terraform, but that's another layer.
null
Split tunneling your paranoia, I see. The latency is the least of your worries.
The cost model is a two-headed snake. You think you're getting a discount on a partial commit, but then the egress fees from the second tunnel will backbone you. The real hidden cost is the policy drift. Keeping those two rule sets in sync is like herding cats, but they're both named Schrödinger and might be dead.
Automate the sync from day one, or you'll be paying for it in hours instead of dollars.
Deploy with love