XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Reverse proxy add encodedslashes option

    Please provide the option in the Reverse proxy to enable encodedslashes for a specific virtual webserver.

    Because some web applications use for example %2F for a slash and the reverse proxy cannot translate this back to / because of allowencodedslashes is not enabled by default. So this results in a 404 error.

    http://httpd.apache.org/docs/current/mod/core.html#allowencodedslashes

    This is essential for Web Applications like SAP Fiori! I think we not the only company who have this issue.

    9 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  2. Proxy Pathing

    Provide the facility to publish sub-directories in path selection as well as static 'web server'. This is useful for many different reasons and has traditionally been known as proxy pathing. This allows a user to enter an FQDN and to have that transparently connect to a sub-directory of the web server. Also, it allows virtual directories of a single FQDN to transparently map to different sub-directories of the same server, or even a different web server entirely.

    7 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  3. Web Server Protection: Certificate-based Authentication

    Hello Team,

    Asking assistance if we could be able to add Certificate-based Authentication for web server protection. We have customer here needing this as requirement on their set up.

    6 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  4. WAF Signature ID does not show in GUI Log viewer; only availible via console logs

    Team, This request is to include the actual signature ID being invoked in the GUI WAF logs. Including this will assist us when figured out which rule to bypass, if needed.

    6 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  5. ModSecurity version 2.X.X to version 3.X.X

    The latest version sof ModSecurity WAF rules are in version 3.X.X. Is there a plan to get these added to webserver protection, since they produce less false positives and perform better than the 2.x.x rules.

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  6. Add protocoll of current Windows product to the business rules ... (Windows 2016 / 2019)

    You had support for Remote Desktop Gateway protocoll (Windows 2008 and 2008 R2) implenented. In the state of the art fw, the modern OS (Windows 2012, Windows 2012, Windows 2019) is not supported for some protocolls.

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  7. redirect

    Hello,

    We need to be able to redirect from https://mydomain.com to https://www.mydomain.com. Right now this is not possible. See support ticket #8223918

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  8. WAF Service Reboots when we make change to any WAF rule of web server

    Hi,
    Currently when we make a change to any web server or any one waf firewall rule, the impact is that the whole service reboots and causes a drop in connection for all the WAF services running.
    This should not be the case. only the rule that is being edited should be affected and not all the services.
    This is also how its done in MS TMD

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  9. Add X-Forwarded-For / CF-Connecting-IP support

    Many of the sites nowadays are behind CloudFlare. It would be great to have an option to inspect and see the real IP address in the WAF logs / Reports.

    It will be like 1 raw entry in the Apache configs!

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  10. Disable trace http in GUI.

    Currently disabling trace http is only possible using the Advance Shell using some commands. Please make this option possible in the GUI.

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  11. RSA SecuID authentication support for published Web Servers

    Alot of customers use RSA SecuID tokens to authenticate published web apps. This feature is important wrt Web Server Protection as other products like Barracuda WAF takes the advantage.

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  12. FTP server Anti-Virus scanning like WAF

    DNAT/NAT/Load balancing rule or WAF should have FTP server option. So that any files uploaded or downloaded from FTP server in any secured ZONE like LAN or DMZ should be protected. Cyberoam has such facility but it is lacking on SOPHOS. If FTP client upload ransomware or virus than it will blow up the secure network. it is security loop hole.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  13. tls verification errors must be logged

    As long as you open a https page via browser you may see that there is an ssl verification error and xg did block traffic.

    as tls verification is also implemented in FTPS (Scan FTP for Malware) you wont get any message on fails, you just can imagine that traffic won't pass because of an tls error.

    same if https is use by applications e.g. internal software updates

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  14. Dynamic (Automatic) Certificates on Web Server Protection

    Currently under WebServer Protection, you are required to setup an SSL Certificate for each Web Server that you are trying to protect. In a web hosting environment this is not plausible or even practical.

    Use Case Scenario:

    - CPanel Web Hosting server could potentially be hosting 100's or 1000's of Web Sites.
    - It is best practice to SSLize Websites. Using standard http is no longer desirable, and it's easier than ever now to automate SSL certificates on websites hosted with CPanel (See next point)
    - CPanel provides automatic SSL certificate deployment from Comodo Secure to any website you want…

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  15. Inline WAF

    1) WAF is not supported when deployed inline.
    2) WAF not supported if NAT/traffic is not terminated on the firewall

    Ticket reported : [#7882861] WAF requirment

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  16. WAF Configuration

    Hi Guise...I have some query regarding WAF.
    As per the document WAF will support only HTTP/https Application layer traffic..

    Can i able to configure for a server open with port 22 for public world...

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  17. "rewrite html"

    As suggested by the support I add the suggestion associated with ticket #7420116 here as well.

    Please consider supplementing manuals for your products that include HTTP/Web proxies. The "Rewrite HTML" option causes not only HTML rewriting but also HTTP headers rewriting based on the head section <meta/> tags with the http-equiv attribute. The headers rewriting functionality seems to be undocumented.

    Please note that such an unconditional rewriting causes problems for web pages that have a construct like the following:

    <head><noscript><meta http-equiv="refresh"…></noscript></head>

    Adding a HTTP header based on such a construct causes a site to malfunction because it redirects the client…

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  18. raise request

    Hello Team,

    we are getting issue to load below sites, firewall catching weak cipher from server.

    https://www.hpdaas.com/welcome

    https://usstagingms.hpdaas.com/welcome

    https://usdevms.daas.hppipeline.com/welcome%E2%80%8B

    request you to give us any alternative solution.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  19. WAF possibility to edit SecRequestBodyNoFilesLimit value

    In the WAF configuration is impossible to edit the SecRequestBodyNoFilesLimit instruction.
    If an user upload a file greater than 1 Mb receives the error
    Request body no files data length is larger than the configured limit - 413 Request entity too large

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  20. WAF - Increase Page Timeout

    We would like it to be possible to increase the timeout period in for underlying web servers. In some specific requirements, web pages will take longer than 60 seconds to load - thus exceeding the hard-coded timeout of the Sophos XG.

    Please allow us to increase this timeout manually.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos Features & Ideas Laboratory
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.