XG Firewall
Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.
-
Apply QoS / routing rules to XG generated traffic
It would be really useful if you could apply QoS and routing policy to data generated by the XG, such as signature updates. So these updates do not impact the WAN bandwidth low speed links.
1 vote -
Select which pattern module updates are downloaded automatically
We have a number of XG firewalls connected to very low bandwidth / high latency WAN connections.
On the old Cyberoam OS it was possible to select which pattern modules are updated automatically. This saved unnecessary data being downloaded as we only need IPS and Application signatures to stay up to date.
1 vote -
Allow Link-Local IPs for Health check AWS uses them for interface IPs
Allow Link-local IP for Health check under gateways. AWS uses link-local IPs for interface IP so if you are using tunnel interface mode for ipsec and have both gateways setup for failover you are unable to use a health check currently because you do not allow link-local IP. You are able to ping it though device console so it would work if you would just allow Link local IPs
1 vote -
Easy Routing
please add an option for easy Routing information to choose between only ipv4 or ipv6 for networks which have both and uses DDNS
1 vote -
PPTP - Set timeout for users that are inactive
We have users who are connecting via PPTP to the VPN that are not terminating their PPTP VPN session on their PCs. They are using Windows Built-In VPN application to connect.
This results in a single user having several sessions taking up IP address from our set VPN IP range.
Unless I'm not seeing it, can the option to terminate PPTP VPN sessions based on activity be added?
We're using SG330 (SFOS 18.0.4 MR-4)
2 votes -
cisco
Cisco ASA to Sophos XG Migration tool
1 vote -
WAF Source Filter by FQDN
Currently WAF rules can only have their source filtered by IP or by Network, while regular DNAT rules can be filtered by IP, IP Range, IP List, MAC Address, MAC List, Host Group, Network, FQDN Host, FQDN Host Group, or Country Group.
I'd like the functionality of the WAF source filter to be expanded to have the same capabilities as a full DNAT rule.
I'm specifically after the FQDN host so we can filter and use DynDNS hostnames but the other things would be handy as welll
1 vote -
synchronised ID authentication (Heartbeat) for different UPN domains in one DC
DCs can only authenticate against one UPN domain. My AD uses several UPN domains, so that e-mails coincide with user accounts, as we own different domains. So I can only use Heartbeat authenticacion with users in the same domain as configured in DC, or I have to create as many DCs as domains, which does not make any sense.
Can you enable the capability to authenticate against different domains, by allowing to add several domains in the domain field of the DC access server?
1 vote -
http waf connections reset after changing remote desktop waf template rule
as described in your article: https://docs.sophos.com/nsg/sophos-firewall/17.5/Help/en-us/webhelp/onlinehelp/nsg/sfos/tasks/MicrosoftRemoteDesktopGateway2008andR2.html
As soon as a new HTTP based rule configuration has been created and saved or an existing HTTP based rule configuration has been altered and saved, all HTTP based business rules will be restarted. Any underlying client connection using a HTTP based business rule will get lost and has to be re-established.This should not happen, and it should be corrected.
1 vote -
Support for Industrial Control and Automation Protocols (SCADA) in DPI / IDS
Idea originally posted by TheMachineWhisperer in 2018 but never responded to by Sophos.
Security for industrial automation, critical infrastructure, and SCADA systems is very much a critical issue.
We would like to see some development to include capability for Deep Packet Inspection and control of industrial control protocols such as:
Modbus TCP
Ethernet/IP (CIP)
OPC Classic (DCOM / RPC)
Siemens S7
DNP3
etc.Inclusion of rules for these into IDS and would also be welcomed.
A number of vendors approaching us are starting to get into this specialist area of the market and it would be great to see Sophos…
1 vote -
API user last login other details
Want to get the following details for VPN users.
- User create date
- User last modified date
- User last connection date
- User last date of password change
This information via API would assist with internal compliance audit and auto disable of accounts not in use as well as automated emails to change passwords.
4 votes -
Bandwidth Graph for IPSEC VPN Tunnel
Bandwidth graph for IPSEC VPN tunnel gives us the overview of the traffic consume by the VPN tunnel currently which is not possible in Sophos XG, only the interface graphs can be view.
3 votes -
Enable/Disable SSL/TLS inspection per firewall rule
In v18 of SFOS of my XG firewall, SSL/TLS inspection is a global on/off setting. I would like to be able to control the use of SSL/TLS inspection per rule instead of globally.
I have an old copier trying to send secure emails and the inspection engine is erroring out with a timeout error. There is no way to make an exception for this. If could just create a new firewall rule so this copier could send out emails would be great while leaving SSL/TLS inspection enabled for all the other rules. v17 everything worked fine.
2 votes -
Quarantine report - Phishing/Spoofing
Sender field, in quarantine report email, currently presents only the forged/fake address of a Phishing/Spoofing email.
A good idea would be to add the real Sender Address, and maybe color it with RED to be eye-catchy and alert the user to pay attention to it.
Alternatively, display only the original email address.2 votes -
IPSEC Site to Site with IKEv2 and RSA Keys should rekey instead of reauthenticating when phase 1 expires
Actually, when phase 1 expires with IKEv2 and RSA-Keys, reauthenticating happens, which is leading to a short VPN interruption ans the corresponding log entries showing the connection as down and up again.
I'd like to propose to implement "reauth=no" in the VPN Configuration. This will lead to rekeying instead of reauthentication when phase 1 expires. Rekeying happens on the fly without interrupting the tunnel and also without the log entries.
This feature request was created based on the Sophos support ticket number [ ref:00D301GN6a.5003Z1728jB:ref ].3 votes -
Ability to pull traffic reports that display IPs as well as Associated Mac Address of the PC using the IP.
We would like the ability to generate traffic reports from our XG firewall that include the Mac address of the PC using an IP at the time. Currently we can see the IP and the Host name of the PC however since DHCP can lease that same IP out to multiple computers within one month, we would like a way to differentiate which PC used the IP and how much traffic Each PC used. Thus displaying the IP alongside with the associated Mac address and total data usage would be very ideal.
We would like to pull a weekly report…
1 vote -
Multicast Forwarding For Entire Netywork
It would be helpful if there was an option to select an entire network or a range of IP addresses for multicast forwarding. Currently, only individual IP addresses can be entered.
2 votes -
IPoE IPv4 in IPv6 Static Global IP Address Service [Japan JPNE V6 Plus Service ]
I would like Japan's JPNE to support IPoE IPv6 Plus (IPv4 in IPv6 fixed global IPv4 service) provided by NTT's NGN network.
FortiGate is supported, so please use Sophos XG Firewall.
2 votes -
Email notification when WAN link is up
When our ISP is down, we receive an email notification that the particular WAN connection is down. However, we never get a notification when it is back up. Instead we have to go into the web GUI to confirm. I would really like to be notified when our connection is up after it being down. I have talked to support about this and they have said that Sophos does not support this feature please reference [ref:00D301GN6a.5003Z1BCbKS:ref ] for more details.
2 votes -
Bugs in Authentication Agent for macOS
When OTP (one-time password) is enabled for User Portal it causes the Client Authentication Agent for macOS to not work UNLESS the user enters their username and password PLUS their OTP token.
I have tested and confirmed this with Sophos support.
Enabling OTP for the User Portal should have NOTHING to do with the Authentication Agent for macOS. Furthermore the Authenticator agent should never require a OTP. Otherwise the poor user will need to re-enter his or her credentials every time their Mac is rebooted.Second bug: There is an on-going display issue with the Authentication Agent for macOS. The…
2 votes
- Don't see your idea?