SG UTM

Suggest, discuss, and vote on new ideas for SG UTM. The ultimate network security package.

SG UTM

Suggest, discuss, and vote on new ideas for SG UTM. The ultimate network security package.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Packet Filter "Test Rule" Button

    When using "group" containers of IP addresses in the packetfilter rules, it's often hard to tell which rule will catch a given (single) IP address or port during troubleshooting. How about a page or form where we can put in a test src/dest IP address and/or port and it will tell which packetfilter rule will catch it? Similar to how Packeteer's PacketShapers have the "Traffic Class Test". This would be hugely helpful when users call and say "I can't get to site abc.com" and you want to quickly know if it's in the range of addresses or ports that you…

    12 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    7 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
  2. Add License info to Daily Report

    Add the license info (type of licenses) and or the amount of time left for the licenses on the daily report

    11 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
    Planned  ·  Angelo Comazzetto responded

    This feature was re-prioritized and will now be targeted for UTM 9.2 later in 2013.

  3. Notifications: Time-Based notification windows

    Often there are events that are generated in large numbers during business hours but should never occur after hours. It would be great to b able to set it to only notify if an event happens after hours or on a weekend. Having these rules send notifications all the time generates massive amounts of notifications for genuine logins but I still want to know if there is unauthorized logins during times where they should not usually occur.

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  4. Authentication: Support for FTP Proxy and AD/eDir

    A big ISP in France asks to have a chance to authenticate users against the FTP proxy (exactly as we do for http proxy) against an external database such as AD.

    customer said in this case that no matter if the proxy send to the credential in clear text between user's client and AxG.

    12 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    5 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  5. Networking: Time-Based NAT Rules

    Because of automatic packet filter option in Dnat/snat it should also be possible to add Time events there.

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  6. Networking: NAT Rule Tester

    Hi, we have ASG boxes with a lot of NAT's on. Sometimes a new rule will be created that is a duplicate of something that is already there.

    It would be really useful to have a tool where you could enter a source and destination ip and a port, which would show you if you have any NAT rules which match this.

    7 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  7. Notifications: Warn employees of pending Up2Date install

    I was wondering if it would be possible to have the product send out a notification to a group of users when you schedule a update? So like for example tonight I scheduled the update to 8.304 for 21:00 so say during the scheduling process you can pick users or a group of users to send the notification to just inform them that the firewall will be updating during this time and Internet could be unavailable for approx 10 mins during this time please plan accordingly?

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  8. WebAdmin: Display server/client name on Licensing page

    When looking at the active IP that are taking licenses, it should also display the server/client name, not just the ip address, making it easier to track down what might be using up unwanted/unneeded spots.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
  9. Web Protection: "Web manager" for filtered HTTP proxy items

    Another idea from a customer:
    Similar to the Mail Manager, there should be a "Web Manager" which is allowed to release items that were blocked by the HTTP proxy.

    Example:
    Someone downloads an passwort-protected zip file via proxy. After the download, it cannot be scanned because the file is protected, and is blocked. But the user needs that file. Now the admin would look at the blocked items and release it.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  10. Networking: Server Load Balancing with only 1 Server

    We should be able to create a server load balancing rule with only one server in it. Right now, you have to create/edit a rule with at least two. Not allowing this prevents you from temporarily removing a server from a pool for maintenance.

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  11. WAN Multipath: Use additional addresses for NAT

    when more then one address is configured on a physical interface it should be possible to use multipathing with these additional addresses.
    so that its possible to make nat rules like:
    uplink_itf(second-adress wan1/second-adress wan2)

    7 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  12. Networking: Display active DNS clients

    When viewing DNS settings, you can see the static enteries you have configured, but you should also be able to view active clients... like you can with active leases in DHCP.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  13. Firmware Update via USB Stick

    Copy the up2date-release on a usb-stick, plugin into the usb-port of the asg-device and then press at webmin-gui the (new) button "import update from usb-device".
    This will give you the option to make a update on an asg without download / upload the firmware-release. In some reasons you don't want to make an automatic systemupdate.

    10 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Operating System  ·  Flag idea as inappropriate…  ·  Admin →
  14. WebAdmin: Comment boxes for all areas

    I would like to have a comment box, how we (windows-) admins know from Active Directory-MMCs.
    This comment boxes should be at the bottom of all WebAdmin-config-sites.
    And in this comment boxes, we could write any infos (for other admins), comments, ideas, todo's, ...

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
  15. Allow Multi-Category White / Black Lists

    We need a way to specify more complex content filter rules since the addition of multiple categories.

    Allow the content filter to have blacklisted and whitelisted categories at the same time, and allow them to decide which one "wins".

    For instance, if a user wants to blacklist Games, but allow Educational, they could. They could also allow Shopping, but block Intimate Apparel. Currently if you select only 1 category, the site will be blocked even if you have whitelisted others it matches.

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  16. active directory re-authentication

    web security should reauthenticate against active directory every 10-30min so that when (guest) account is locked they are unable to get through web security

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
  17. WebAdmin: Select interface for SNMPd

    It would nice to be able to bind the snmp daemon to defined addresses.

    For example a problem:
    Monitoring through VPN (ipsec0) is not working cause the snmp-read requests to a local interface of the astaro are answered by the ip of the ipsec0 interface (outgoing). Therefore the replies can not be assigend to the former read.

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
  18. Networking: DNS Incoming Load Balancing

    It would be cool if the UTM could update DNS records to balance the incoming traffic. By changing the DNS answer across the public addresses configured on the UTM, the records could update (although with a delay) in reference to how much bandwidth and connection are used on the WAN links at a point in time to avoid new incoming connections being delivered to overloaded links.

    16 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    7 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  19. Networking: Time-Based WAN Link Balancing Rules

    If multi-path rules can be defined with time-based behavior (for example a rule is from 8am to 5pm active) and the possibility with 2 other feature requests (Create "Uplink Interface Groups" or Multi-WAN-Uplink: User-Defined) you can defined very cool multi-path rules.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  20. Domain/Address-based Quarantine of Messages

    It would be great if we could drop incoming SMTP email based on domain or email address straight into quarantine rather than Blacklist.

    7 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.