SG UTM

Suggest, discuss, and vote on new ideas for SG UTM. The ultimate network security package.

SG UTM

Suggest, discuss, and vote on new ideas for SG UTM. The ultimate network security package.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Support Microsoft Authenticator App for OTP

    Support MS Authenticator App for OTP so customers with Office365/MS365 only need 1 authenticator app on their device

    3 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
  2. Possibility to put a description to the accesspoint

    Would be nice to have a description option for the accesspoint in the wireless protection.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
  3. Reboot AP from command line or crontab (scheduled task)

    I've 3 AP connect to a UTM, i would reboot them but not manually with the aweetool, with a schedule task (crontab, rc.local, shutdown -d [time] ecc..., at the moment do this isn't possible..

    This "feature" is very important for a correct connectivity ofthe AP, because
    every one/two/three months you are forced to restart them manually.
    The awetool is useful but yu need to connect to UTM by ssh, start the tool, find the AP and reboot it MANUALLY.
    Give the possibility to create a crontab for do this wil be very very useful, we'll apreciate it.
    thanks

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
  4. To change the label name of Master and ***** in HA:

    To improve team communications by removing perceived discriminatory language.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  HA/Clustering  ·  Flag idea as inappropriate…  ·  Admin →
  5. SSLVPN: Bad Compression header

    Hello,

    I'm using SSLVPN and am getting "Bad compression error" as mentioned in below post:
    https://community.sophos.com/products/xg-firewall/f/vpn/100669/ssl-vpn-bad-compression-stub-decompression-header-byte-102

    Downgrading OpenVPN client to version 2.3.10 solves this issue.

    As discussed with Sophos Escalations Team, raising a request here to upgrade OpenVPN server of Sophos to make it compatible with newer versions of OpenVPN client.

    Ubuntu 18.04 onwards ships with newer version of OpenVPN client and its older versions are no longer supported on Ubuntu 18.04 onwards. Hence, it would great if this can be done at the earliest.

    4 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
  6. new DHCP Option code

    new DHCP Option code:

    Option Name: 200 H323 Gatekeeper
    Vendor: Innovaphone

    Thanks

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  7. S/MIME certificate export durch GUI.

    It will be nice, if there is a button for downloading the extern S/MIME Certificates from Email Protection > Encryption > S/MIME Certificate.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
  8. FastestVPN is the hallmark for success for VPN providers in the world here's why?

    FastestVPN was formed in the Cayman Island in 2017 and instantly became a success, their renowned features made them the best VPN for Android users, and their formidable security protocols, also named them as the best VPN for IOS users as well!
    https://fastestvpn.com/download/android-vpn

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
  9. Dark Mode on XG v18

    Why not implement the Dark Mode on SophosXG v18?

    Or Just add a customization label under general settings?

    16 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Flag idea as inappropriate…  ·  Admin →
  10. Stop SSL VPN from storing users' passwords in client PC's memory

    Currently the Sophos SSL VPN client logs this warning in its log when connecting: "WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this"

    This appears to be a security risk, since a malicious program could conceivably obtain the user's login credentials.

    I opened a ticket with Sophos support for this, but they confirmed there is no way to make the UTM add this option to the .ovpn files when it creates the client installer bundle for a user. The user CAN manually add it to their .ovpn file, but it's not feasible to…

    6 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
  11. mib

    hi all,

    I would like to monitor via snmp users vpn sessions, ie there bandwith and the user logged on at any given time on my utm 9 device.

    thanks,
    Rob

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
  12. ? - on risk level under reports

    Hi Guys, on my application risk report I see ? instead of a risk number. this is on my UTM XG135. for example for port 443. cant this be changed to may be risk 0 instead of a ? as when you view reports we cant actually distinguish what actually this means and have to login to firewall and go and pull up the report to actually see which defeat the purpose of having a report the first place.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  13. UTM AD Realtime Refresh For VPN Users

    I have been doing a setup for a client where we use Cisco Umbrella (web filtering) over the SSL VPN configured on the Sophos UTM.

    This VPN is set to use AD Authenticated users, however we have noticed when we are looking at the logs on the cisco side, the AD user does not match the IP address being used, it looks like the AD user being shown is 24 hours behind, and if a new user connects to the vpn with a new IP which was previously used by another user, this can cause incorrect results.

    Now I raised…

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
  14. use industry standard sorting for ip list in network definitions

    use industry standard for sorting ip list in network definitions instead of the lexicographic sorting method.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  15. page scrolling

    On sections that have multiple pages of items, eg users, hosts, DHCP leases, make it so that when you click to the next page, the top of the next page is visible, not the bottom. Every time I click to a new page I have to scroll up to get to the top of the page.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  16. SSL VPN - create and use a certificate revocation list

    If a user is deleted from the UTM and the account was in use for SSL VPN, his user certificate should be set to a certification revocation list.
    The SSL VPN service should use this revocation list to avoid using old certificates from accounts that were created on the UTM with the same name. This is currently possible, 05/2020.
    The UTM does not maintain revocation lists for users and the SSL VPN service does not use this capability, although OpenVPN offers it.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
  17. Remove support for TLS 1.1/Allow it to be disabled in Sophos Mail Appliance

    PCI scans that see a remote access port open to the internet fail because the appliance still supports TLS 1.1. I have to dispute this every time, and it is a real hassle

    4 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
  18. Filter Action -Downloadsperre per Passwort/Pin Umgehen

    Wir haben in unserer SG-Firewall (Modell:SG230, in der Filteraktion „Default content filter action“ eingestellt, dass bestimmte Dateiendungen beim Download geblockt werden (exe, bat,…).

    Nun ist es für uns als Administratoren trotzdem manchmal notwendig an einem User-PC einen Download zu tätigen. Dafür müssen wir dann den Webfilter temporär ausschalten. Das ist aber ungünstig, da man schon mal vergessen kann ihn wieder einzuschalten. Es wäre von Vorteil wenn ich bei jedem einzelnen geblockten Download die Sperre z.B. mit der Bestätigung eines Passworts oder PINs, welches nur wir Admins kennen, dann trotzdem durchführen könnte.
    Esist einfacher und weniger umständlich, wenn man das direkt…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  19. password complexity rules for local authenticated users

    You can set the simplest passwords for local users (e.g. SSL-VPN).
    I think it is important to be able to set a guideline for the complexity of passwords

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
  20. Firewall Rule : [BUG] The trigger area to turn on or turn off rules is expanding according to the size of the rule

    Please Correct the trigger area ON-OFF on firewall rule policy, please make it just only clickable only on the bottom icon. Now the activates area is expanding according to the size of the rule??
    We have to face the difficulty of using it. we always disable the rule by mistake because we did not recognize the area which is not an icon also do the trigger

    But this behavior did not happen in NAT Rule, Masquerading, or any toggle switch on other features in the firewall.
    We used Firmware Version: 9.702-1

    3 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.