SG UTM

Suggest, discuss, and vote on new ideas for SG UTM. The ultimate network security package.

SG UTM

Suggest, discuss, and vote on new ideas for SG UTM. The ultimate network security package.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Perform checks when creating host definitions

    "security made simple" is a vital aspect of network security and in keeping with that model I suggest the following checks while creating host definitions:


    1. When creating a host with an assigned IP, the system should check if that IP is already assigned or not. In a large scale network even though you can search and sort host definitions, it is prone to human error and therefore proper rudemantory checks by the system during creation should be performed.

    1.1 one should not be able to create a host with an IP within a dynamic range

    1.2 one should not be…

    3 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Flag idea as inappropriate…  ·  Admin →
  2. Check the DHCP server's 'Range' when creating a Host with Static IP

    When one clicks the [Make Static] button on the 'IPv4 Lease Table' tab, there should be a check that the IP to be used is outside the 'DHCP Range' listed. Prior to that button existing, we just used the regular Host definition process, but that's probably more difficult. Even then, a quick check to see if the assigned IP is in any DHCP range would seem to be easy. For example, I just got the following:

    secure:/root # cc get_objects dhcp server|grep 'range

                        'range_end' => '172.16.31.110',
    
    'range_start' => '172.16.31.101',
    'range_end' => '192.168.66.254',
    'range_start' => '192.168.66.100',
    'range_end' => '10.100.100.63',
    'range_start' =>
    4 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  3. AWS Transit Gateway Support

    Currently, the Amazon VPC setup does not support the new Transit Gateway in AWS. When you attempt to import via config file or secret key it errors out with a Regex error.

    I went up the whole chain of premium support and the GES Engineer let me know it currently isn't supported.

    As Transit Gateway is the future of Inter VPC & S2S networking this would be nice to have supported.

    18 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    6 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
  4. 1 vote
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
  5. vpn

    Please block Star VPN. It is connecting on the user machines and they can browse freely.
    Thanks

    1 vote
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
  6. Please block Star VPN under Proxy VPN

    Hi there,
    Please add Star VPN under proxy VPN.
    Thanks

    1 vote
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Application Control  ·  Flag idea as inappropriate…  ·  Admin →
  7. AWS VPN Automatically Create IPS Exception

    We recently migrated our AWS VPN's from their 'Classic' to their 'New' style. We had major issues with this (and not a lot of documentation from either Sophos or AWS on what the issue could be).
    AFter having 4 Sophos engineers look into the problem, it turns out that the new AWS VPN uses NAT-T which was being caught by the UDP flood protection, as it's between two 169.x.x.x IP's at either end of the tunnel.

    Since importing an AWS VPN config is supposed to be largely 'hands off', creating all the BGP and VPN settings in the background, it…

    3 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
  8. Reflexion

    How Do I setup a scheduled report?

    I would like a daily report emailed to me of any deferred messages for any of our customers.

    I would like a Monthly report emailed to me of the users for each customer.

    I would like a monthly report emailed to me of the blocked messages for each customer. Preferably by threat level.

    1 vote
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  9. Flood emails with the same source

    It would be interesting some blocking method for e-mail sended from a same address in a small space of time.
    Eg: the address bruno@sophos.com sends 1000 email to the protected domain on UTM in 2 seconds.

    Remembering that this would not apply to the whole domain but to an speciffy address.

    This would be interesting when an email box is hacked and used to send many spams.

    17 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
  10. Let’s Encrypt - configurable key size

    Would be nice if it would be possible to configure the key size of automated created Let’s Encrypt certificates by Sophos UTM with Let's Encrypt Method --> described here: https://community.sophos.com/kb/en-us/132940

    2 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  11. How to find out active openvpn-connections, documentation for UTM9 API

    I would like to find out wether users are connected via openvpn or not. With a single request:

    https://my.utm9/api/status/openvpn/openvpn-officemunich

    to get:

    {
    "connectionname": "openvpn-officemunich",
    "active": false,
    "last
    starttime": "2019-12-30 08:00:00",
    "last
    endtime": "2019-12-30 08:14:03",
    "history
    description": "only last 24 hours are saved",
    "history": [

    {
    
    "start_time": "2019-12-30 08:00:00",
    "end_time": "2019-12-30 08:14:03",
    },
    {
    "start_time": "2019-12-29 23:10:00",
    "end_time": "2019-12-29 23:14:03",
    }

    ]
    }

    It is a great idea to have an API for Sophos UTM9 and to publish documentation here:

    https://www.sophos.com/en-us/medialibrary/PDFs/documentation/UTMonAWS/Sophos-UTM-RESTful-API.ashx

    This documentation is from 9/2017 and I hope to find more substantial info in this document or…

    1 vote
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
  12. ssl vpn IP blacklist / whitelist

    i am getting a lot of rouge traffic trying to connect to my SSL VPN - black listing and white listing IP's, IP ranges or ISP's would be good

    i know that it's secure and chances are they will never get in - though all the extra protection helps and if a flaw was ever found in openvpn this would help

    5 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
  13. Simultaneous logins setting by groups

    we need Simultaneous logins setting through which we fetch from the AD, with that we are able to set user login restrictions any number of login in one click

    2 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
  14. Multiple vlan support on pppoe interface

    I it possible to create support of multiple vlans on one pppoe interface? We do need it for our internet provider Telfort/KPN/XS4ALL. PFsense does support it, but Sophos UTM (software) does not.

    Internet is on vlan 6
    IPTV on vlan 4
    Connection PPPOE

    1 vote
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  15. Web Protection Only EndPoint Agent

    It would be awesome to have a lower cost agent just to deploy congruent webfiltering etc to mobile devices. Having to pay for the full agent just to switch everything else off (especially now that Sophos Central is the recommended route for the other features) is superfluous and a bloatier solution.

    2 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  16. Set a full set of snmp / api class / call for basic and deeper PRTG monitoring

    could it implemented, that the utm can be monitored by snmp - in all variants of working, activated modules by snmp or api.

    it is in this century not possible to monitoring deeper details of the utm. basically, there are any point s reachable - but it makes not the needings of an working utm with reds, vpns and else without any deeper investigations.

    Of course, be a partnership with paessler, like it was made by other software creators.
    So, it could be set as a given sensor in the PRTG gui, supported from Sophos / Paessler - it will…

    2 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  SNMP Monitoring  ·  Flag idea as inappropriate…  ·  Admin →
  17. Usage of Sophos AP over a IPSec tunnel

    Currently ( 9.605 ) it's not possible to use a Sophos AP on a UTM for remote locations which are connected via IPSec VPN tunnel and not a RED. The AP is being recognized, you can manage it and see all the connection attempts.
    The only thing not working is the DHCP server on the UTM which is not able to send his DHCP packets into the tunnel to the AP. It would be great if this function cold be added.

    3 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
  18. Custom Block Messages depending on different networks

    We want to be able to show different block messages to request from different users/networks/filteractions.

    We have one public hotspot were we provide internet access and another private company wifi.

    We want to be able to only show the administrators info (like telephone number) to the private wifi.

    Please implement this as a feature if possible.

    3 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  19. da (P)FS bei TLS zwingend für Behörden laut BSI gefordert ist und ach bald im BSI-Grundschutz aufgeführt wird.

    Feature Request eine generelle Option in der GUI wird benötigt , damit nur Forward Secrecy fähige Ciphers verwenden werden können, damit auch andere TLS Versionen damit abgedeckt wären.

    Das Problem ist, das das BSI im April neue technische Maßnahmen für den IT-Grundschutz heraus gegeben hat.

    Darin wird für Web-Anwendungen nur noch TLS 1.2 und TLS 1.3 mit FS empfohlen.

    Der eingriff über CLI ist nicht gewünscht:
    ................................................
    /var/storage/chroot-reverseproxy/usr/apache/conf/reverseproxy.conf
    Finden Sie recht weit oben die Zeile :
    SSLCipherSuite ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS
    Das was hier eingetragen ist. wird vom Rev-Proxy angeboten.
    Änderungen hier und Folgeprobleme (Sitchwort Backportability alte Clients zu neuen Cipher suites) sind…

    9 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
  20. SSL VPN Remote Connection after a time automatically configured from the firewall, disconnect

    For an industrial remote connection, we need restrictive configuration options. with a UTM firewall, we would have to be able to interrupt remote access from the firewall. It would be great if each dialed connection could be disconnected after a certain time, as an example of an hour. with increasing internet attacks, we unfortunately have to pay more and more attention to possible entry gates.
    Will it be possible to find such a feature in Sophos firewalls in the near future? Especially for our purposes, with the SG115 UTM. At best a script that would install this feature?

    Translated with …

    2 votes
    Sign in Sign in with: Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.