Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Block Password Guessing for WAF

    In the configuration for password guessing, I miss the option to enable block password guessing for WAF Authentication.

    See
    - https://www.astaro.org/closed-forums-read-only/utm-9-betas/utm-9-2-beta/50498-9-191-feature-block-password-guessing-reverse-authentication.html
    - https://www.astaro.org/beta-versions/utm-9-3-beta/54271-feature-block-password-guessing-waf.html
    - Mantis ID #30112

    Maybe it ist possible to implement this festure earlier than 9.350

    9 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
    • Disable ssl v2 and v3 on RED

      Please allow SSL v2 and v3 on RED to be disabled. PCI compliance now requires SSL v2 and v3 to be turned off. Need this feature asap for clients to be PCI compliant!

      Thank You

      3 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
      • Microsoft Operations Manager Management Pack

        It would be fantastic if you could provide a Management Pack for Microsoft Operations Manager (currently Version 2012 R2) to centrally monitor UTM appliances and other Sophos products. Dashboard, Alerts (DoS, Portscans, etc.), State of components (Webfilter, VPNs, etc.), Capacity Management (Load, Usage), etc.

        81 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          4 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
        • 6 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
          • iOS and Android user authentication clients

            Cyberoam (a Sophos owned UTM) have client authentication apps for non-domain devices such as tablets to authenticate with an authentication service such as AD.

            13 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
            • Show the unlinked interfaces in HA

              Please show in the webadmin the unlinked interfaces of the ***** instead of only "UNLINKED". Now you have to login to the ***** and find with ethtool which interfaces are actually unlinked.

              24 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  HA/Clustering  ·  Flag idea as inappropriate…  ·  Admin →
              • Store the SPX password specified in the subject using [secure:<password>] in the UTM for <receiver> so that subsequent e-mails to <receiver>

                Store the SPX password specified in the subject using [secure:<password>] in the UTM for <receiver> so that subsequent e-mails to <receiver> will be encrypted using that password without the need to specify the password again and again. Let's reset the password for <receiver> using the existing functionality 'SPX password reset'. Or alternatively provide a different way to specify a permanent password for <receiver>.

                5 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                • Probe network for rogue or conflicting DHCP servers

                  The DHCP Server built into Windows will only start if no other DHCP server is detected on the network segment. I would suggest incorporating this function into the UTM by sending out a DHCP lease request and waiting for a reply before enabling the internal server. If a reply to the request is received indicate to the user that another DHCP server is already active on the network and must be shutdown prior to enabling it on the UTM.

                  In addition to probing before enabling the internal DHCP server periodic requests should be sent out on the network to look…

                  9 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                  • place an additional/dual interface for the remote gateway/local interface of IPsec

                    On site to site IPsec
                    1. on connections there will be additional interface or at least 2 local interface for redundance
                    2. on remote gateways tab there is also at least 2 remote gateway for redundancy

                    1 vote
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
                    • telegram

                      A filter for Telegram messaging app

                      7 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Application Control  ·  Flag idea as inappropriate…  ·  Admin →
                      • Add Support for Manual ipv6 tunnels 6in4

                        Need to be able to create manual 6in4 tunnels instead of just hard coded tunnel brokers.

                        1 vote
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Operating System  ·  Flag idea as inappropriate…  ·  Admin →
                        • Email Appliance - Add secondary SBL (to filter spam) and must Pro-actively scan any Spams

                          The feature we would like to see available would be the option to add secondary sbl providers to filter for spam. We have had dozens of multiple spam get through to our
                          clients on a daily basis. 90% of these are listed on spamhaus sbl or dbl for either ip or domain address. our users don’t want to be burdened with file submission. This would allow for nearly 100% spam filtering.

                          Company and Contact Information

                          Company: City of Roseburg

                          Contact: Support@cityofroseburg.org

                          Sophos Partner (if applicable):

                          Sophos Product Information

                          Sophos Product: SOPHOS EMAIL APPLIANCE

                          Version in Production: v3.8.0.3

                          Feature Request Summary

                          1 vote
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                          • Join Workplace as Client AuthN

                            Starting Windows 8, there is a feature called Workplace. It is using Email and Password to identify a User (it will lookup an SRV record on the email's domain name to identify the server to whom it has to talk to) and finally it will enroll the client with a certificate.
                            Sophos could use this in order to identify clients on the UTM. First enroll with a UTM username and then identify the user for e.g. Web Protection.

                            3 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
                            • SNMP Set Commands

                              It would be great to send snmp set commands to set for example the default route trough a third party interface

                              3 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                              • Add Zenmate and to Blocking In Application Control

                                Add Zenmate plugins to Blocking In Application Control

                                9 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                • PureMessage

                                  Realtime block list. Add the ability for Sophos to include reference to RBLs such as Spamhaus and spamcop. Apparently, doing this at the exchange level while using Sophos is not a good idea, so it would be nice if we could have the ability to set this up from the Pure Message console.

                                  thanks

                                  1 vote
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                  • S/MIME Certificate History

                                    Currently it is only possible to add one s/mime certificate to an internal user. If this certificate expires I have to replace this certificate with a new one. I have to replace this certificate exact on these expiration date. If I replace the certificate before expiration I can be possible that I receive encrypted emails but I can encrypt the mails because the certificate is replaced. If I replace the certificate after expiration the signature and encryption is wrong. So my Suggestion is to add a Certificate history for internal users to solve this issue.

                                    18 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Add ability to change password on Self Help screen in Sophos Safe Guard

                                      Sophos Safe Guard - Self Help screen allows viewing of the current password, but does not allow change of password. Enabling change of password at this screen would increase security level a step further.

                                      2 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Country blocking vs Endpoint Protection to fail to connect and update status of the managed PC

                                        Country blocking prevents Endpoint Protect from communicating with Sophos Liveconnect and cause the EP feature to stop working. CB should either not do that; or exceptions should be pre-populated to prevent that from happening.

                                        2 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                        • breaking HA cluster without a shutdown the s lave.

                                          if the s lave shutsdown after breaking up the cluster, I can't reach it anymore because the unit is in a datacenter. Even console access is'nt possible.
                                          So do a factory reset of the s lave after breaking down the cluster and then a reboot. With console access I can configure the routing and ip's again.

                                          1 vote
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            1 comment  ·  HA/Clustering  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base