SG UTM
Suggest, discuss, and vote on new ideas for SG UTM. The ultimate network security package.
-
Change login screen to Dashboard display
Currently, if you leave the Dashboard up, WebAdmin doesn't timeout. That's advantageous for using the Mail Manager and other WebAdmin popups, but it exposes all of WebAdmin in a way that is a security risk. Having one of those windows open and active should be retained. One solution would be to change the login screen to the Dashboard display without any active buttons. Another approach would be to "lock" WebAdmin access (instead of logging out automatically which closes popups) and to display the Dashboard information with the ability to unlock with Username/Password.
2 votesThis feature has been implemented in ASG 8.200.
Check out what else we improved in this release here: http://www.astaro.com/blog/up2date/ASG8200 -
WebAdmin: Clear Syntax Error Feedback
In WebAdmin, while the error handling is excellent, the feedback when you try to do something that doesn't make sense has room for improvement. In addition to the blinking red boxes that tell you where the error is, add feedback texts telling you exactly what the problem is so the user can understand why what they have done is invalid, not JUST that it's invalid.
eg. If entering an IP definition and you put the wrong style in like 1.1.1.1.1 it should say you need a proper IPv4 address etc..
1 voteThis feature is included as part of ASG Version 8 which will be Generally Available at the end of June.
Watch http://up2date.astaro.com for the official announcement.
-
WebAdmin: iPhone / iPad (iOS) Friendly GUI
Currently there are some features of the Astaro interface that do not work on the iPhone's Safari browser.
The most notable of which, dragging and dropping of definitions and hosts, doesn't work. The only way to create a NAT rule or a packet filter rule is to create new hosts and protocol definitions for each rule. In a pinch this is ok, but still not ideal.
Perhaps a search-box concept with a dropdown suggestion list (like many popular search engines)? Or maybe the community has some ideas?
The drag and drop is awesome for the full browsers though, so I…
103 votesThis feature has been completed and released as part of UTM 9. See http://www.astaro.com/blog/up2date/UTM9 for launch information.
-
Authentication: Mass Deletion of User Accounts
Need a better way to delete multiple user accounts. Currently, the admin has the manually click on the 'delete' button for each user account, and this becomes an arduous task to delete several accounts. Perhaps user deletion based on a specific criteria or regex?
4 votesThis feature has been released as part of the Astaro Security Gateway 8.100 Release
-
Paketfilter display no. of rules
Every time you make a change, the number of displayed rules changes to 10.
E.g. You insert an new rule on position 20. If you save it the no. of displayed rules will switch back to 10. Next step is to change the no. to 50, goto rule 20, activate it and again: 10 rules displayed. If you want to double check the rule, change again to 50 displayed rules, ...
Can you please remember the value of the display-dropdown?4 votes -
Host Definition Section
In the definitions area are listed Networks, Services and Time Events. It would be useful to have a Hosts section as well and have hosts broken out from the Networks section to allow for greater clarity.
3 votes -
Officially Support Chrome
I use AD user Auth. When I start a browsing session with Chrome, the proxy requests my credentials. Other browsers simply forward the NTLM auth.
5 votes -
Support Simplified Chinese in Webadmin
Chinese in Webadmin language is currently Traditional Chinese, not Simplified Chinese which is widely used in mainland China. It would be better to have Simplified Chinese to do business in China.
1 voteThis feature is included as part of ASG Version 8 which will be Generally Available at the end of June.
Watch http://up2date.astaro.com for the official announcement.
-
"Never block network" for User Portal
There should be an "Never block network" option for the User Portal like there is in the WebAdmin Settings Security Options.
Reason:
Sometimes many users from the same company try to log in from the same source IP address, e.g. to check the mail quarantine. If one of them fails to enter the password correctly three times, the IP gets blocked for a couple of minutes which means that ALL users from that company get blocked for that span of time.4 votesThis feature uses the same parameters as the webadmin never block feature, thus is already possible in ASG. Enjoy!
-
WebAdmin: View Logged in Admins
I would like to see on the dashboard a list or count of sessions logged into the ASG. This would let me know if another administrator or a user is logged on the system.
8 votesThis feature has been completed and is ready for testing in the current Sophos UTM 9 Beta version which can be found at http://www.astaro.org/beta-versions/utm-9-public-beta/
Happy testing,
Thx Astaro PM Team -
Definitions: Edit from config menus
It would be very useful to be able to edit definitions from the context menus they are used in. This saves clicks going back to the definitions menu.
3 votes -
WebAdmin: Grouping of Service Definitions
Cuz then we could use that for PF
Would make life much more simple, and a lot more easy to digest, 5 years after creating the stuff ;-)
3 votes -
Support Firefox 3.5
I updated to Firefox 3.5 today, and suddenly I can't drag-n-drop objects in ASG 7.4. This makes FF35 useless. Not sure who to blame, but FF35 support is needed
39 votesThis is compatible and drag’n drop works using FF 3.5 as of AxG 7.500.
-
Reduce Display of IP Addresses
We should have a tiered, prioritized list for definitions so that the "object" can have more specific uses throughout the configuration. The goal is that using any number of factors, an association can be made between a "user" and their actual IP(s) to be used in configuration and reporting without having to resort to the IP itself.
For example the object definition "Angelo" could have any number of the following parameters (to name a few) which are accessed / referenced in a prioritized way to cause a match from top to bottom
1) Directory Name (ad, edir etc..) (best)
2)…8 votesThis feature has been implemented in ASG 8.200.
Check out what else we improved in this release here: http://www.astaro.com/blog/up2date/ASG8200 -
Definition Cloning
I think it would be pretty cool to be able to "clone" certain rules/definitions. For example, if you have a DNAT/SNAT rule for RDP to a specific server using port redirection and a specific interface's addition IP address, and now you need a rule exactly the same except for a different service (not RDP), it would be so much quicker if you could just click on a Copy button and have the WebAdmin open a dialog box with all of the fields filled in exactly like the one you said to copy from and then you can just change what…
2 votes -
Display Astaro hostname at top of Webadmin
Often times I have multiple Webadmins open for all the different sites from the ACC. They all look exactly the same and though I have not made the mistake of configuring the wrong site by accident, I know its coming. I recommend adding the hostname at the top for quick reference to know you are at the right site. Perhaps under the logged in user information?
12 votesThis is already implemented, after a successfull login the title shows username and hostname
-
WebAdmin Global Search
A global menu search feature would be so helpful. Something like the search in Vista/7 Start Menu. So many times I was staring at the GUI trying to remember where is that checkbox I clicked half an hour ago that had the words: encrypt and email in its description.
8 votesThis feature is included as part of ASG Version 8 which will be Generally Available at the end of June.
Watch http://up2date.astaro.com for the official announcement.
-
Exceptions: Usage of "and" / "or"
The current (since 7.000) way of using a logical OR inside a single exception (e.g. in the SMTP proxy: For these source hosts/networks OR these sender addresses OR these recipient addresses) seems absolutely useless to me, because this can be achieved by using more than one exception rule (i.e. one for the source host/network, another one for the sender address, etc.). It is impossible, however, to achieve a logical AND between the conditions, which could be very useful sometimes. The solution is very simple, change all the "OR"s to "AND"s in exception definitions everywhere (SMTP proxy, HTTP/S proxy, IPS, etc.).…
6 votesThis feature is included as part of ASG Version 8 which will be Generally Available at the end of June.
Watch http://up2date.astaro.com for the official announcement.
-
WebAdmin: Save Viewing Options
Every time, I go to IPsec-VPN definitions, service-definitions etc., I'll have to recalibrate my viewing options (items per page, filters). I want them to be stored automatically individually for each page.
3 votesThis has been added in ASG V7.500 under WebAdmin Settings, you can define your default value there.
-
Automatically create a "host definition" for Static DHCP Reservations
There should be some sort of automatic relationship between devices assigned a static IP using the DHCP reservation option and the network host definitions. This would eliminate an extra step when you want to give a DHCP based device a static IP using the DHCP server and then setup a special firewall rule for that device
3 votes
- Don't see your idea?