Defender Gateway
Use Smart Router through the existing Cortex Defender connection on a managed device.
- Defender on your deviceUse the existing endpoint app
- Managed RouterYour organization supplies configuration
- Eligible requestsRouting depends on the client and path
Then verify sync.
Defender Gateway is the Smart Router path that uses the existing Cortex Defender endpoint connection on a managed device. It is not a separate app, download, or gateway deployment.
Before you start
- Set up Defender on the device that sends the request.
- Ask your administrator to configure Smart Router for the organization.
- Use a client and request path that your organization has qualified for Smart Router.
Defender and Smart Router have separate responsibilities. Defender connects supported endpoint AI tools; Smart Router can observe or apply a model decision only when the managed Router configuration and request are eligible.
Use the Defender path
After Defender is connected, send the request through the qualified client and request path.
Verify routing
In observe mode, Cortex records the routing decision and forwards the requested model unchanged. In apply mode, Cortex can change the forwarded model only for an eligible request after its managed configuration passes the routing checks.
For either mode, inspect the routing record for the requested model, Router selection, and forwarded model. A successful provider response alone does not prove Smart Router applied a route. If Cortex cannot safely apply a compatible route, it forwards the original request.
Next steps
- Set up Defender for the endpoint connection.
- Use Smart Router through Defender or Egress Gateway for routing modes, eligibility, and fallback behavior.
- Egress Gateway if an app connects through an organization's shared gateway instead of Defender.