XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Alert customisation

    Please could it be made possible, so we can edit the alert emails that are sent i.e. IPS

    Currently, we receive emails on an IPS event but it appears to be lacking information

    we currently get the firewall serial number, the hostname of the firewall and its management IP, the date and time of the event and the Alert ID

    It would be nice to see not only the threat (Message) but it would be good to see the attacker IP and the source IP the attacker was trying to reach.

    This would save having to go through the firewall…

    5 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  2. Anomalies in the Executive report data being send by XG430 & XG30

    In the Executive report at section "Applications & Web" being send by XG430 (SFOS 18.0.1 MR-1-Build396) & XG330 (SFOS 18.0.1 MR-1-Build396), it omits the users in the list, when compared with the portal/GUI interface of XG430 & XG300.

    The Data shown in the Exective Report should be correct to the last possible drill down data at portal/GUI interface.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  3. Addition of Export Policy in Excel or any readable Format

    Addition of Export Policy in Excel or any readable Format, so that management can review properly and advice if anything desired.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  4. syslog

    Please enable sending of VPN logs (charon.log and strongswan.log) files to syslog server. This is needed to analyse these logs offline.

    4 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  5. ssl vpn remote accsess user Used time (in minutes) report download to PDF,CSV,HTML

    ssl vpn remote accsess user Used time (in minutes) report download to PDF,CSV,HTML

    6 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  6. SSLVPN Report

    Hello Team,

    We are looking for a reporting feature or logs data to identify SSLVPN users data, on which WAN link they are connected. This will help us to identify users data & bandwidth usage details and we can plan to segregate users as per need and depending upon primary and secondary/backup WAN link speed.

    Thanks!!!

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  7. report

    in the graph of the use of the wan it would be nice that clicking on any bandwidth would report ip that created that event

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  8. Seperate Sophos Connect Alerts from IPsec Alerts

    Please differentiate the site to site tunnel alerts from Sophos Connect tunnel alerts. The way it works now is that the same alerts (17801 Established and 17802 Terminated) are generated for site to site IPsec tunnels and Sophos Connect tunnels. I don't need to be notified when a Sophos Connect tunnel goes up/down, but I do need an alert for site to site up/down. The frequency of the Sophos Connect alerts makes it impossible to notice when a more important site to site tunnel goes up or down.

    20 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  9. Increase maximum records as 200 instead of 50 in Mailed report of VPN

    Maximum records are showing only 50 in scheduled mail alert of VPN Logs and due to this unable to get the complete reporting which is imbecile feature if not getting complete report.

    Suggesting to you that increase maximum records as 200 in auto mail alert

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  10. XG:135 there is reporting constraints in Sophos

    There is reporting constraints in Firewall .At a time only 200 Records can be dowloaded.
    This is affecting for data analysis.Please make some update to download a report at one shot.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  11. Current Activities: Add column for Hostname - only shows IP-address in v18

    Under Current Activities (e.g. Live Connections) only the IP-address is shown.

    This often requires navigating to different sections (e.g. DHCP) to hunt down the hostname.

    Efficiency would be greatly enhanced if a column were to be added showing the hostname.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  12. reports

    Good day, Would you please create a feature that would give options on which detailed report you want, Customize> Web report> Summary or detailed > date range> Generate.

    Customize> Application report> Summary or detailed > date range> Generate.

    If you do not go to the Customize tab you won't be able to get a detailed report it only gives a summarized report.

    The current report on the Sophos XG Firewall 17.5 includes all the web requests which makes the report difficult to read especially for someone who doesn't know anything about our side of work.

    Should we give someone a…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  13. Bounced Email Logs (Log Viewer Tab)

    Hello Support,

    I have raised a case 9862438 for a query related to bounced email logs shown in log viewer tab as well as to send those logs via syslog to any syslog server. But unfortunately the Support person said that this option is not available right now in XG Firewall. Please add this feature in upcoming firmware(s) so that we can get all the necessary logs and also able to forward those logs to syslog server to set an alert.

    Regards,
    Mansoor Ahmed

    5 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  14. SSL vpn report

    I need to take ssl vn report usage time from xg frewall.
    the existing option shows only no of connections and bytes download
    I mean usage report

    14 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  15. Required WAN interface utilization in report format (graphical or Excel or PDF) on report section.

    As of now we are not getting reports of WAN utilization on Current activities > Report section , We required the same in the graphical format so to download easily and monitor ISP wise reporting

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  16. IPsec Notifications

    We use the IPsec email alert to monitor our site to site connections.

    I notice that you migrated the option to the notification list in V18, however each time that the connection gets disconnected we received about a dozen emails at the same time, one for the parent connection and one for each client connected. This is followed by the same quantity of emails for reconnecting, os in total we are receiving up to 20+ emails each time an IPsec connection drops and reconnects.

    Now think on our Escenary having more than 20 Sophos devices sending these alerts to the…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  17. Firewall IP objects and linking info to policies

    This is a partial overlap on idea "Show where object is in use on attempted deletion" but this is a solution for this problem.

    in "hosts and services" -> "IP host" & "IP host group" & "FQDN host" & "FQDN host groups" (+ maybe some other type of objects). Clicking on an object would show which rules the object is used in (or if its not in use).

    Sorry about category, couldn´t find a better suited one.

    3 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  18. The VPN reports should include the total hours of connection per user in a time period.

    If we want to know how many hours a user stayed connected during the day along the month we don't have this information, we have no information about time of connection all we have is the total traffic per user. We also need the time per user.

    13 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  19. multiple firewall rules in log viewer filter

    It would be helpful to be able to view multiple firewall rules in the gui log viewer filter portal simultaneously. Current behavior is only a single firewall rule can be in the filter at a time.

    5 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  20. generate top 20 Web Users showing the amount of data used and active time spent

    Hello Team,

    We have customer here requesting to have option under reporting to generate top 20 Web Users showing the amount of data used and active time spent. For your assistance please.
    Thank You.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.