Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Direct Yubikey Support in OTP-Module

    Hi there,

    it would be great if the Yubikey (www.yubico.com) could be directly supported in OTP-Module of the Sophos UTM.

    I know that all TOTP-Token (also the Yubikey) are supported. But you need a helper program to generate the TOTP with Yubikey because it doesn't have an internal clock.

    It would be easier (for the enduser) if the Yubikey would be directly supported (For example, by authenticating through the Yubicloud like several Radius Servers do)

    So the user would only need to press the button and the key (that Needs to be validated with the Yubicloud or through…

    73 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      4 comments  ·  Flag idea as inappropriate…  ·  Admin →
    • Firewall Order of Operations

      Firewall Order of Operations

      Based on testing and additional information found in other request, it appears that the proxies/security services have a higher order of operation over the firewall. As such, even with firewall rules in place, the security services override those settings. With email protection, this essentially opens up SMTP on the Sophos UTM to anyone on ALL interfaces. This, thus, increases the surface attack area of the device to an unacceptable level.

      Changing the order of operation would allow the administrator of the device to dictate, via firewall rules, what can and can not access the Sophos UTM…

      40 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        4 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
      • Make the notification editable and fix the typo in the "Notification of potentional leak of data"

        I just setup a new UTM and enabled SPX encryption. The sender receives a notification with a subject of "Notification of potentional leak of data". First off, the word in the subject is misspelled. Users are slamming my department for this "mistake". Secondly, the title of the notification sounds so ominous and negative to the end user. Everyone is worried they are doing something wrong when the action is completely legitimate. I would love to have the ability to customize this notification or just simply turn it off. With the notification turned off the sender still receives the email that…

        4 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          1 comment  ·  Notifications  ·  Flag idea as inappropriate…  ·  Admin →
        • DANE

          DNS-based Authentication of Named Entities (DANE) is a procedure for the security SSL/TLS connections with the help of DNA entries, again by
          DNSSEC are protected.

          30 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
          • support Websockets compatability in UTM 9

            Support websockets for google chrome and firefox. For some reason we are not seeing the issue in Internet Explorer 11,,

            14 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              1 comment  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • websocket support for WAF

              we are hosting a SignalR hub (http://signalr.net/) behind a Sophos UTM 320. We use the Web Server Protection feature extensively in our environment, and as such have opted to use the same for this.
              SignalR will always try to use Web Sockets (http://en.wikipedia.org/wiki/WebSocket), a new HTML5 API, and fallback to other technologies where this isn't possible to be used.
              Since we've been hosting the hub via the reverse proxy, none of our clients are able to connect via Web Sockets :so having support for websockets in WAF would be super cool

              723 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                21 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
              • Email Encryption: Add internal encryption / Add feature to send the password via SMS

                Email Encryption: Add internal encryption / Add feature to send the password via SMS

                3 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
                • Email Protection: Add DNS Group as Smarthost

                  When use a smarthost for outgoing email it is not possible to choose a DNS Group

                  6 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                  • Enhance Web Antivirus Configuration

                    Currently we only have the option of selecting one, two or both antivirus engines (Sophos/Avira/Both). There does not appear to be anywhere to edit the settings of these scanning engines. I know from using both Sophos and Avira on desktops that they have numerous settings. Avira in particular allows the user to change heuristic sensitivity (high/medium/low) and also enable macro heuristics. With Avira you can also select what you want to include in detection (eg dialers/jokes/phishing, as well as traditional malware). Sophos Anti-Virus has the option of enabling detection of 'suspicious files' also, which I should imagine is Sophos' heuristic…

                    6 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      2 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                    • Web Protection: Configurable ports full transparent web filtering - HTTP and HTTPS

                      Would be useful for example to use this feature for web filtering in front of an existing web proxy that has already been configured for other port than 80 (e.g. 8080) without changing for all the clients/applications the proxy settings (e.g. from 8080 to 80).

                      8 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                      • Useful cache statistics (Web cache, DNS, SXL Categorization, Cluster balancing)

                        Since version 9.2 it easy to have the statistic in the Web filtering log to make some interesting stats on cache.

                        Cached= to know if the web object was take form disk cache
                        dnstime=0 the dns resolution was made from cache
                        cattime=0 the categorization is made form SXL cache
                        With the name of the UTM -1 or -2 in the log you can know how much the charge is balance between the cluster.

                        I think this could be a interesting widget stat in the main dasboard.

                        Thanks you

                        6 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
                        • Allow RegEX in Website Tags

                          Add the ability to use a full regex in the new website tag area. Seems like it should be able to take any format the same as the website list area.

                          1 vote
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                          • Add menu item (and command-line utility) to export all SEC configuration

                            - Add menu item (and command-line utility) to export all SEC configuration (groups, policies, update managers, subscription selections) to a flat file. (Preferably a human-readable version as well incase we want to use an old config as a guide when creating a new one.) Add another menu item to restore configuration (selectively) from such a file.

                            It will greatly reduce the size of backups (since DB backups won't be required) and make disaster recovery and SEC machine migration far easier.

                            1 vote
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
                            • SPX encryption: configure the minum password length from now fixed 8 characters to other (higher) values for generated one-time passwords

                              -->
                              I wish a new additional password length field in the GUI in the first tab „SPX Configuration“ of SPX Encryption for passwords of the type "Generated one-time password for every email", where I can configure longer passwords, which means longer minimum password lengths. E.g. 16 characters.

                              Background:

                              The sophos utm then by default generates passwords with a length of 8 characters.

                              Today, this insecure, when the attacker uses a brute force method with special GPU computers.
                              It may be cracked within less than 1 day.

                              The password length, that I can configure on the first tab „SPX Configuration“ of…

                              12 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                1 comment  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                              • Country Selection for Qos

                                This feature is requested to accommodate the need to manage bandwidth allocation for country level, so user doesn’t need to create so many network definitions when setting the rule on QoS.

                                Dear Sophos,

                                You have a very good product. And we don_t consider this as a troubleshooting ticket.
                                We just want to share our clients need regarding QoS.

                                In Indonesia, right now common to use internet connection from ISP_s that separate bandwidth limit for local access and international access. for example, I may have 10 Mbps to access my country networks but I only have 5 Mbps for accessing International…

                                4 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                                • Wireless Protection: MAC-Filter based on vendor

                                  There are several customers who want to allow wireless access only to specific vendors. So it would be great when the MAC filter on a WiFi would only check the first six characters in the list (for example: Kyocera 00:14:60).

                                  1 vote
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                  • WAF block

                                    We are using WAF to protect a website and when blocks occur due to bad ip reputation of the clinet accessing the website the client just receives a 403 error page
                                    with Permission Denied.Therefore the user does not understand the reason of the block action and this have an impact on the client service. We would like to know if there is a way to customize the errors provided by WAF for bad reputation ips

                                    1 vote
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      1 comment  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Allow network range object in SSL VPN

                                      Network range object is not yet supported in the SSL VPN configuration.It will be great if can add this feature too.

                                      1 vote
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Websites Lists - Filter Actions

                                        Currently the Websites lists in a Filter Action is only available in one Filter Action. When you remove the Websites List it cannot be created with the same name across any of the filter actions.

                                        Ideally you should be able to totally remove a Websites List as well as assign the exact same Websites List (with all the same Websites and any future changes) to multiple Filter Actions. I would suggest this has significant benefit to large business; more specifically education. Schools want to be able to add a Website list to all students for block/allow but still keep individual…

                                        9 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Web Protection: Browser authentication without popups

                                          The UTM should avoid open a popup that keeps the user authenticated. This kind of action is always blocked by the main browsers in their default configuration.

                                          The system should intercept the request, ask for user+pass, and show the "authenticated as" screen only. It may try to open the requested website in a popup or through a target _blank link, but the main screen should stay opened with the logout button always available.

                                          Today the current method doesn't work on a large setup when a customer can't control how their users' browsers are configured.

                                          3 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base