SG UTM

Suggest, discuss, and vote on new ideas for SG UTM. The ultimate network security package.

SG UTM

Suggest, discuss, and vote on new ideas for SG UTM. The ultimate network security package.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. RED: Notify of Duplicate Networks

    While playing around with RED, we've recently had the problem that we accidently used a network 192.168.x.x/24 for the RED network that was already used for another VPN connection. That caused some trouble because we could not find why we did not get a connection through RED.

    So it would be great if Astaro could implement a feature that checks if a network is already used somewhere (VPN, routing, etc.) and throws out a warning if someone uses it elsewhere.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
  2. Add Interface information to logs

    For troubleshooting purposes, including the interface that a packet/URL is going out would be very helpful.

    While viewing a live log I would just need the interface, eth0, eth1, br1, etc, added to the line so that I can be sure that my multipathi rules are working.

    For example:

    2010:05:12-07:17:47 proxy httpproxy[4561]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="192.168.0.2" user="" request="0" url="http://somelink.com" INTERFACE="eth1"

    7 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
  3. RED: 1:1 NAT Support for RED devices

    two remote LANs with the same IP range/netmask cannot be connected to the same central ASG by using RED devices in the remote offices. ASG wouldn´t be able to route the traffic on the central ASG correctly.

    All examples have in common (which is likely), that several of the "remote LAN's" will have the same IP ranges (e.g. surely 192.168.1.0/24 and 10.1.1.0/24 will be used often).

    As the RED device bridges the LAN to the central ASG, there is no possibility to route the network traffic correctly on the central ASG.

    So we need a SNAT/MASQ mechanism on the RED…

    41 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    Under Review  ·  6 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
  4. Networking: Uplink Monitor Action to Restart Unit

    As an augmentation Internet Connection Monitoring, we'd like to have the ability to tell the Astaro to reboot if the internet connection is not available after a predefined interval (say 15 minutes). This would solve issues we have with having to power cycle remote ASG units to get them to reconnect with various ISP equipment.

    6 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    4 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  5. Networking: Sync details for ISP

    Home users use a router as dumb modem which connects directly to ASG.It would be great is ASG could provide the sync details from the ISP (sync speed,attenuation etc)

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  6. AstaroOS: Configurable default key size for certificates

    a keysize of 1024 bits is standard (anywhere fix encoded in the deepth of the system) to all autocreated users (ex. backend prefetch with LDAP). There should be a config dialog providing the ability to preset the keysize for all later created certificates

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Operating System  ·  Flag idea as inappropriate…  ·  Admin →
  7. AstaroOS: Bind Proxy to Defined Interface(s)

    Possibility to fix the interfaces for the web or mail proxy. E.g. I want to use the web proxy only for traffic between (LAN and Internet) and (DMZ and Internet) but not allow the LAN to see the DMZ.

    15 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    6 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  8. Networking: Assign DNS Servers via Interface

    I would like to be able to assign DNS servers to interfaces. Right now it's global.

    10 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  9. Mail Security: Use Phising Filter to stop Malicous Links

    The Phising Filter in the mail security already filters URL's in mail for known phising servers. Please also add the possibility to filter more URL categories - at least "Malicious Sites" and "Spyware/Adware". Or the nonplusultra feature would be, if we could filter mails against any of the Smartfilter XL categories (as P2P and others).

    The rising number of mails linked to malicious sites will make this feature very desireable.

    ==> http://www.searchsecurity.de/themenbereiche/bedrohungen/phishing-und-spam/articles/258639/?nl=1&cmp=newsletterapplikationssicherheit13-04-2010

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
  10. Mail Protection: Compress and Convert files

    We often have a situation, that our customers send us mails with BMS-files attached instead of using PNG or GIF.
    I want to have an option, that I can define, which attachments can be converted from BMP to PNG or GIF. Maybe this can be combined with a ruleset so that I also can define, that a LOG or TXT-Attachment can be zipped, if it is greater than a limited file size.
    This feature will save a lot of space on our mail-server and also on our POP3-clients.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    7 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
  11. Authentication idle timeout

    The maximum length of time the user can stay authenticated when idle (not passing any traffic to
    the external network).

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  12. Reports/Alerts: Allow Customization / Logos

    Extend the customization options allowing for custom logo's, headers and footers on the various mailed reports, and email alerts

    13 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  13. Reporting: Fully audit a single / group of Addresses

    I'd like to be able to set 5 ip's aside and see a report of what they use and where they go.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  14. Network Security: Enhanced Search for Packet Filter Rules

    I want to search Source/Target/Service/Grouping/State/Comments fully with operators. It would be nice to search IP's inside of groups, and objects for example, and string together searches using AND , OR, NOT etc...

    14 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    8 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
  15. Reporting: Per-Interface Bandwidth Totals

    In the daily report which is sent to me by mail the IP traffic is mentioned in the first line as "Traffic Processed".

    With multiple internet uplinks, VPN "interfaces", RED's, and Wireless AP's, it would be great if you could break down that total and show me some interface summaries for this!

    22 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    Under Review  ·  4 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  16. Web Security: Increased Cache Options

    i wish to have more configuration options in http/s cache settings.

    for example cache all from microsoft updates for x days/weeks/years, cache every gif, jpg, png, css for x days/weeks/years

    or do not cache php, asp, js.

    14 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  17. Notifications: Notify on Blocked URL by Filter

    Whenever a url is blocked by the url filter, have an email notification sent to appropriate admin users to advise who's trying to access blocked content.

    12 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    7 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  18. Notifications: Bandwidth Utilization

    Be able to get a notification when the network utilization spikes.

    12 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  19. Ability to manipulate E-Mails

    I would appreciate it to have the ability to manipulate E-Mails like rewriting envelope senders/recipients, some functions to set conditions and the corresponding actions, something like a granular DLP on the gateway itself.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
  20. Definitions: Change Definition "Types"

    When you add a Network or Service definition, you have to give it a type. For example Host (that you have to supply an IP) or DNS Host (that you have to supply a dns to be resolved). Since you create a definition of a specific type, you cant change it afterwards so if you have many rules relying on that definition and you need to change a static IP (of type host) to a dynamic dns host (type of DNS Host) for example, youll have to create a new definition first, check where the old definition was…

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.