This document gives an overview of major components of AI Gateway.
Supported LLMs
The AI Gateway supports the most popular LLM models today.
- OpenAI (Compatible schema)
- Google Gemini
- Anthropic Claude
Flexible Deployment
The AI Gateway is available as a virtual appliance that you can deploy in your environment with support for the following:
- Public Cloud: AWS
- Private Cloud: VMware ESXi
Note: All configuration and management—covering gateway setup, policy creation, content inspection profiles, logs, and dashboards—are centrally managed via the Netskope Management Console.
Target Audience
The primary audience for this article are:
- Security Administrators:Responsible for the end-to-end lifecycle management of the AI Gateway, including deployment, configuration, and ongoing maintenance. While they maintain strong security and access-control expertise, they typically have limited familiarity with provider-specific AI concepts.This documentation provides step-by-step guidance to help them confidently configure and manage the AI Gateway.
- DevOps and Platform Engineers: Manage the VM infrastructure, networking, and system operations that support the AI Gateway. They are skilled in certificates, tokens, automation pipelines, and infrastructure provisioning. Their role is to ensure that the environment is properly integrated, secured, and optimized for operational reliability.
Prerequisites
To ensure a successful deployment and optimal performance of the Netskope AI Gateway, all necessary prerequisites must be satisfied before proceeding with installation and configuration.
This table details the minimum resources and specific network access needed for deployment.
Infrastructure Network Requirements
| Category | Requirement | Details / Specific Value |
|---|---|---|
| Deployment Platform | Supported Hosts | VMware ESXi virtual machine AWS AMI. |
| Minimum Resources | CPU, Memory, Disk | 16 vCPUs, 32 GB RAM 200 GB Disk Space. |
| Ingress Ports | Management & Access | TCP 22 (SSH), UDP 68 (DHCP Client), TCP 443 (HTTPS), TCP 80 (HTTP). |
| Egress Ports | Core Networking | UDP 53 (DNS Resolution), UDP 67 (DHCP Server). |
| Netskope Egress URLs | Health & Updates | events.goskope.com:443, download- |
| AI Provider Egress | LLM Endpoints | api.openai.com:443, generativelanguage.googleapis.com:443, api.anthropic.com:443. |
| Proxy | Requirements | Must be configured if all egress traffic routes through a corporate proxy. |
Administrative Requirements
This table details the necessary administrative and licensing requirements.
| Category | Requirement | Details / Specific Value |
|---|---|---|
| Netskope Access | Management Console | Active administrator account access for policy configuration and monitoring. |
| Licensing | Feature Entitlement | Valid license for the AI Gateway feature. |
| Credentials | Supported LLMs | Valid API keys or credentials for accessing supported LLMs. |
Routing Requirements
This table details how traffic must be directed to utilize the AI Gateway.
| Category | Requirement | Details / Specific Value |
|---|---|---|
| Traffic Steering | Agent Configuration | Traffic must be explicitly steered to the AI Gateway not directly to the LLM endpoints. |


