Cato Networks Integration

Cato Networks Integration


Configuring your Cato Networks ZTNA to work with Lumia is simple. Follow the steps below, and feel free to contact us at support@lumia.security if you have any questions.
The Lumia-Cato integration is still under development. At this stage, the following functionality is not yet supported when deployed with Cato:
  • Safari browser (on macOS)
  • Microsoft Copilot desktop app for macOS
  • GitHub Copilot desktop app for macOS
We expect this to be supported in Q2 2026.

Prerequisites:

  1. The Lumia tenant certificate must be deployed to endpoints via MDM (or installed manually). If the certificate is not installed and trusted, traffic will not be forwarded to Lumia, even if the Cato rules are configured.

Step 1: Configure a Split Tunnel for Lumia’s proxy

In this step, you will create a split tunnel rule in Cato to allow traffic for the relevant Lumia GenAI domains to be forwarded to the Lumia proxy.
  • Create IP entries for the Lumia proxy IP addresses through Resources → IP Ranges:
    • Lumia 1 - 15.197.85.229
    • Lumia 2 - 166.117.67.20
notion image
  • Create a Split Tunnel Rule (Access → Split Tunnel Policy) so that traffic to Lumia 1 and Lumia 2 will be excluded from Cato.
notion image

Step 2: Register your Cato users in Lumia

In this step, you will register your Cato users with Lumia. This will generate unique Cato proxy rules for each user.
  • Install the Lumia Security - Cato Deployment Extension (the extension will soon be available on the Google Store; in the meantime, manual installation is required).
  • After installing the extension, you will be required to enter your unique Lumia tenant JWT. This is a one-time setup process.
notion image
  • To use the extension and begin the Lumia registration, log in to your Cato dashboard. Keep the tab open until the process is complete.
  • The Lumia-Cato extension registers users on the Lumia platform and adds the relevant information to the Cato Proxy Configuration policies:
    • Skip rules whose Name does not start with “Lumia”.
    • For User Proxy Configuration policies (there should be one user per rule), it generates a Lumia PAC URL and sets it in the proxy rule. Don’t forget to prefix the Cato rule name with “Lumia”.
    • Group Proxy Configuration policies will be automatically expanded (again, the name field of the group proxy policy should start with “Lumia”).
    • The proxy URL will be overwritten, so you can enter any URL (e.g., https://google.com) in the placeholders you create.
  • Once ready, click the Lumia icon in the extension to start the process.
notion image