Can you please disable the Server Signature header on the Web Server Protection so that it shows NULL or anything else apart from "Apache".
Although this is not a failure for PCI compliance, it does flag on the check and not showing closes a possible issue.5 votes
The User Portal needs a configurable time out to log users out after a period of inactivity.
Even with session cookies disabled the session will remain open for many, many hours unless the user chooses to manually log out.38 votes
This is something we would look to add in an upcoming version. Thanks!
If guests change their IP adresses, it is not possible to track them in the logs. After a simple IP change, we have no possibility to connect an IP address to a MAC and then to a Voucher/Guest. So you can bypass the logging. This is an importion feature for guest wlan / hotspot feature!56 votes
Thank you for your feedback. We will look into this.
When the internet connection drops at the main site (UTM location) the RED restarts to get the tunnel up again. When (for some reason) the internet connection stays down at the main site all internet activities at the remote location are down due to continuous restarts of the RED. If the *** only tries to pick up the tunnel, the internet at the remote location can still be used.73 votes
WAF doesn't support ActiveSync 14.1, i.e. after you install SP3 for Exchange 2010, you can't use use WAF to protect your ActiveSync Server anymore. This is poor.77 votes
I would like to be able to rename/change the description in the "Branch Name" field of the RED sites. I see that in the WebAdmin there doesn't seem to be a way.
When we get an alert that "redXX is down" it would be really helpful to not have to dig up my notes on which site that actually is. This should be a standard feature.
More detail about this are posted on the forum:
http://www.astaro.org/other-products/remote-ethernet-device-red/47745-rename-red-branch-name.html53 votesUnder Review · AdminJan Weber (Product Manager, Network Security Group, Sophos Features & Ideas Laboratory) responded
We are investigating adding the option to change Branch Name.
In V8 it was possible to Ping Devices behind the UTM Device, in V9 it is Disabled and could not be Enabled with a Packet filter Rule.
This function is useful for us and our Customer which has Devices behind the UTM in his own DMZ that should be monitored by Monitoring Systems etc.18 votes
While already possible by disabling the built-in ICMP handlers and creating your own packet filter rules for explicitly allowing such traffic, we will review the operation of this behavior and if we can refine the GUI here.
Please add Support for route based vpn so you can prefer the BGP route first followed by the IPSec route if your BGP route is not available.23 votes
Astaro please include application control rules applicable to users group in AD. Very important to include.132 votesUnder Review · AdminRich Baldry (Product Owner, Web Protection, Sophos Features & Ideas Laboratory) responded
Although it is possible to use AD groups for App Control right now, there are limitations. We want to make it consistent with Web Filtering policies. We are considering this feature as a candidate for a future release.
When the DHCP server is configured with a large scope - say a capability of a range of 200+ leases. then it can be very difficult to determine how many leases are currently active, especially when leases that have already expired are still shown in the table. One has to manually count the entries in the table. It would be wonderful if a counter was available at the top of the lease table showing the number of current active leases.19 votes
Would be great if you could sort the DHCP Leased IP table by Ascending/Descending order.29 votes
Using the middleware (cc CLI) it is already possible to set link-aggregation to a different mode than the default mode 4 (802.3ad).
We would appreciate to see all other modes becoming an official part of the Web GUI:
- mode 0 (balance-rr)
- mode 1 (active/backup)
- mode 2 (balance-xor)
- mode 3 (balance-broadcast)
- mode 5 (balance-tlb)
- mode 6 (balance-alb)69 votes
Would like to see more detailed reporting in the application control feature. It would be great if you could navigate around and click for info, save, and schedule reports like you can with the Web Reporting which is great.24 votes
being able to specify a 'root' domain name, or pattern, as a network definition, that could then be used in a traffic selector for bandwidth shaping, would help greatly. content delivery networks use hundreds of hostnames, but usually stick with one 'root', example: 'something.nflximg.com' or 'something.llnwd.net' by specifying something like "*.llnwd.net' as the source, we could then limit the traffic as desired.130 votes
RED should be able to do DSL/VDSL (PPPOE), as this way it can be used with an ISP which is very common worldwide in requiring authentication against their modem.242 votes
After a careful review we decided to not include this feature in UTM 9.2. We are now considering it for the next feature release whose launch date has not been decided upon yet.
I'd like to automatically add the comments to backup filename. Everytime I create a backup I add them manually, copying the comments inserted in webadmin. It is useful if you have to fastly find a particular backupped configuration. IE:
devicename_8.103_2011-08-25_09-29-before changing admin password.abf2 votes
Add option for Time-Based QOS rules, Where we can assign time and Bandwidth to a Network.96 votes
The ability to operate a pair of UTM software appliances in a VPC, in different AWS availability zones, configured as HA/clustered pair.
This feature is critical in providing a truly HA VPC solution. I have the need to operate a very highly available VPN endpoint for multiple healthcare providers and this one deficient is preventing us from moving forward with the excellent UTM software appliances.
(Amazon has a white paper outlining how to make the default NAT instance highly available using two NAT instances and a script that detaches and reattaches the virtual interface and MAC to the standby instance.)8 votes
I'd like to see initially the User Portal designed to support Mobile Devices, using the correct temrinology, would be to have a propper 'mobile site'.
Scrolling around the user portal on an iPhone or Android phone is very hard and usually required scrolling, pinching, etc to get things done.
A mobile site would make navigation easier.2 votes
This is something we will look to implement in an upcoming version. Thanks for the idea!
Whilst you can create Departmental reports, containing the Sites, Traffic, %, Pages, Duration and Requests, it doesn't include the Username of the user. It would be really useful if you could create Departmental reports showing all of this information,sorted by usage and include the username, so that a Department Head can see the usage of all his/her employees, in a single report, rather than having a seperate report for each user. It would also be good if it could include the option to have a date/timestamp entries as well.31 votes
- Don't see your idea?