XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. IPSec with IP Range and List Type

    In the IPSEC connection, we have the option to create an IP range.
    But we cannot choose the created rang.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  2. Keep Alive Function for XG Firewall

    Our XG IPSec VPN Tunnel to Microsoft Azure does not stay up, because when there is no activity Microsoft shuts down the tunnel. To overcome this, we have had to implement a 5 minute ping to each of our 5 warehouses from a VM in Azure. A keep alive feature on the XG side would solve this problem. Other firewalls, such as Dell's Sonicwall, have a keep alive feature that addresses this issue.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  3. Sophos Connect Client - Implement Policies like UTM

    UTM had the option to create multiple Sophos Connect policies for managing configuration files from the GUI. Each policy could have customised settings relevant to that connection.

    Now you're required to download the Connect Admin tool to configure basic things like 'Allowed Local Network(s)', Client DNS Suffix, Auto-Connect Tunnel etc. etc.

    This should be added to the WebAdmin GUI like it was in UTM.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  4. Feature Request - SSLVPN UI Improvements

    Being that the SSLVPN is based on OpenVPN could you please add a freeform text field to the SSLVPN page under Advanced that would allow us to enter custom server configuration parameters? Better still would be the ability to view and edit the entire config file itself but that may be asking a bit much.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  5. Feature Request - Add Alternate Shell option to RDP Bookmarks

    It would be really awesome if you could add the Alternate Shell parameter to the RDP Bookmark setup so we can have an RDP bookmark that launches a shared application on a server. Since you took away our HTTPS bookmarks this is our only real alternative, to share a browser application via RDP that points to the website we wish to publish a bookmark to.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  6. Feature Request - Include SSLVPN Site-to-Site in Device Access Profile

    When you create a profile to allow an Admin User to connect VPN tunnels that does not apply to the SSLVPN tunnels, only IPSec. Either create a separate SSLVPN category or add a line for it, or simply include it in the generic "Connect tunnel" right.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  7. To generate VPN Logs based on Source IP with Time Stamp

    Need Report to Get Details about which VPN User Logged in With TimeStamp, Source IP Address, and Resources accessed during the remote Session.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  8. IPSEC failover vpn condition - Add an option to ping a local device on remote site

    It would be very handy if there can be an option to ping a remote device via local ip address. as some time vpn failover doesn't work as it can still ping the external ip address even if for some reason tunnel goes down.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  9. SSLVPN authentication by RADIUS Authentication via Active Directory

    Implementation of SSL VPN users on Sophos using RADIUS authentication. The RADIUS server to use the Active Directory to authenticate the SSL VPN request.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  10. SSL VPN client for PC -

    I would like to have the SSL VPN client have the ability to save the username and password as well as an option to start at login or system start up. I have been able to do this manually with services and text file for auth with shortcut, etc but would be much easier built into the software. Most other clients have this and it has not been officially supported nor developed into the app at all. I have been using SG and XG appliances for about 6 years now with no sign of having this added. Thanks in advance

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  11. macOS Sophos connect client paste password

    macOS Sophos connect client paste password :
    It would be cool if we can paster our password in Sophos Client Connect in macOS rather than write manually especially when the password is very strong.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  12. VPN client autoupdate for remote users

    Is there a Sophos idea existing, that the VPN client should be checked for updates when the VPN client dials in ?
    if necessary, automatically updated before the VPN client connects.
    The download is provided by the XG Firewall and the client is up-to-date without admin rights or end user oder administrator intervention.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  13. Add the Option to Download Windows 10 Always ON VPN Profiles

    Microsoft supports adding always on VPN profiles to Windows 10, would be great to be able to have an Always ON VPN profile that can be generated and downloaded from the VPN page in WebAdmin on the XG Firewall.

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  14. Enable multiple source NAT in IPSEC tunnel

    Currently we are unable to NAT multiple source subnet with single IP on Sophos XG firewall, kindly enable it.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  15. ssl vpn

    Would like to see an option to create additional SSL VPN profiles based on AD Group membership. Having a single DHCP scope for all SSL VPN significantly hinders the potential of this feature. Being able to place different users into different subnets would allow administrators to tailor firewall rules for each group that better fit a given groups role within the organization. The current system requires I either grant excessive network permissions to standard end users, or otherwise make the SSL VPN completely useless for administrators attempting to address emergency issues remotely.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  16. Want to add option for Two WAN link for L2TP VPN

    Please add a option to select one more Local WAN port in Local Network details, in L2TP remote access VPN tab. As of now its only for one WAN port.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  17. SSL VPN ACCOUNT LOCKOUT

    Similar to the admin lockout screen - it would be useful to block users logging into ssl vpn after x amount of incorrect attempts - either lockout for a predetermined amount of time or what would be awesome would be to lock and allow an admin to unlock.

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  18. IPSec Remote Access mode should hand out IP's to Android clients

    We should be able to hand out virtual IP for users on a plain IPSec (not Sophos Connect) by config or by user static remote access IP defined.
    Sophos XG's IPSec configuration does not have the ability to configure "rightsourceip" when setting up Remote Access IPSec connection. With this ability we could use the built-in android IPSec XAuth VPN client and not rely on third party apps.

    [IKE] <AndroidIPSec-1|28> peer requested virtual IP %any
    [APP] <AndroidIPSec-1|28> [IPPOOL] (acquire_address) acquire_address...
    [APP] <AndroidIPSec-1|28> [IPPOOL] (acquire_address) Access Server not provided IP for user: ********
    [IKE] <AndroidIPSec-1|28> no virtual IP found for %any requested…

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  19. Mode Transparent/Unifié

    Il manque aux possibilités du RED le mode Transparent/Unifié. En effet pour nos clients Education il n'est pas possible que les accès Internet ne transitent pas par le XG. Si la liaison Internet ne fonctionne plus sur le site principal, il vaut mieux alors pour des raisons de sécurité que les élèves ne puissent plus accéder à Internet.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  20. SSL Site To Site VPNs between SG and XG

    When you want to migrate customers from an SG to an XG Firewall one of the hardest issues come when you can't establish SSL site to site VPNs between SG (Astaro) and XG when the SG is the master.

    Why can't the EPC files be compatible?

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID Staging Test
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
← Previous 1 3 4 5 6 7
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.