XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

Suggest an Idea...

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Remove the Limit of 50 Configs in OpenVPN GUI

    Currently there is a limit of 50 configs in OpenVPN GUI.
    There are already prereleases of the original OpenVPN GUI which remove those limit and add nested configurations.

    I would like to see that in Sophos XG SSL VPN Client too.

    0 votes
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • sso
    • facebook
    • google
      Password icon
      Signed in as (Sign out)

      We’ll send you updates on this idea

      0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
    • RED Service (port 3400) should be considered a Local Service like User Portal or SSL VPN

      The RED service should be considered a Local Service and allowed to attach to the Zone of our choosing. This would allow us to easily add Local ACL's to limit which external IP addresses port 3400 is open on among other things. As currently configured having port 3400 open and using a self signed certificate fails PCI compliance scanning.

      1 vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • sso
      • facebook
      • google
        Password icon
        Signed in as (Sign out)

        We’ll send you updates on this idea

        0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
      • SSL VPN OTP format

        SSL VPN OTP should be able to be configured to not be current password + OTP. We would just like it to be OTP to log in, we should have the option to just use the OTP from the authenticator app.

        2 votes
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • sso
        • facebook
        • google
          Password icon
          Signed in as (Sign out)

          We’ll send you updates on this idea

          0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
        • Sophos Connect IPSec mapping Network Drives

          Sophos Connect IPSec Client should have a possibility to execute a loginscript after successfull connection for mapping network drives. (for example like Sonicwall VPN Client)
          or possibility to execute a script on the client side.

          1 vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • sso
          • facebook
          • google
            Password icon
            Signed in as (Sign out)

            We’ll send you updates on this idea

            0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
          • Log the source mac / hostname over ssl vpn

            Log the MAC address/Hostname of the client that is connecting over the SSL VPN tunnel.

            1 vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • sso
            • facebook
            • google
              Password icon
              Signed in as (Sign out)

              We’ll send you updates on this idea

              0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
            • Sophos Client Connect auto connect user when on insecure wifi or away from office

              A cool function of the new Sophos Client thats available for 17.5 would be if it could be configured on the firewall to auto connect on insecure wifi or away from office. (Both should be options) I have users who would not want this at their house, but I would want to force it if they were connected to hilton wifi or starbucks wifi.

              1 vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • sso
              • facebook
              • google
                Password icon
                Signed in as (Sign out)

                We’ll send you updates on this idea

                0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
              • IPSec over LAN zone interface

                With SG you can configure IPSec site to site using LAN interfaces but with XG you only can configure IPSec site to site over a WAN zone interface. Please allow to do it also over LAN zone interfaces. Thanks

                6 votes
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • sso
                • facebook
                • google
                  Password icon
                  Signed in as (Sign out)

                  We’ll send you updates on this idea

                  0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                • SSL VPN users must have the timing access for LAN resource

                  Almost every Firewallsystem offers an option to enable VPN Access for an user just for some time. In Example : klick on the user -> Enable VPN Access for next 8h.

                  So VPN Access ends with 8h of use and there is no need to deactivate it manually.

                  Please provide this function.

                  5 votes
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • sso
                  • facebook
                  • google
                    Password icon
                    Signed in as (Sign out)

                    We’ll send you updates on this idea

                    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                  • IPSEC tunnel in transport mode

                    I need to enable ipsec tunnel in transport mode and also tunnel interface feature

                    2 votes
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • sso
                    • facebook
                    • google
                      Password icon
                      Signed in as (Sign out)

                      We’ll send you updates on this idea

                      0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                    • IPSec Connect Client Token field

                      Hi,
                      can you please add a token field that users don´t need to write Password+Token in one field.

                      It´s better when it´s seperated, like the CheckPoint Client.

                      1. Username
                      2. Password
                      3. Token

                      1 vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • sso
                      • facebook
                      • google
                        Password icon
                        Signed in as (Sign out)

                        We’ll send you updates on this idea

                        0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                      • need to vpn connect with corp network before user login to their system where using xg

                        need to vpn connect with corp network before user login to their system where using xg

                        3 votes
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • sso
                        • facebook
                        • google
                          Password icon
                          Signed in as (Sign out)

                          We’ll send you updates on this idea

                          0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                        • VPN Bandwidth report

                          Hello Team,

                          We have customer here requesting to check if possible to generate report for bandwidth utilization for ipsec vpn tunnel. Customer would like to see what application or traffic activity is eating up the bandwidth for ipsec vpn tunnel. For your assistance please. Thank You

                          3 votes
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • sso
                          • facebook
                          • google
                            Password icon
                            Signed in as (Sign out)

                            We’ll send you updates on this idea

                            0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                          • Multiple Users on a HTML5 Object

                            I've just come across the restriction that HTML5 bookmarks can only be used for one user at a time, meaning you have to create 20 odd bookmarks so you can have concurrent users accessing the same resource, even with the extra bookmarks the users have to click on each one to find one that's not in use. It's naff to say the least. Having a single object with multiple connections would make this go away.

                            3 votes
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • sso
                            • facebook
                            • google
                              Password icon
                              Signed in as (Sign out)

                              We’ll send you updates on this idea

                              0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                            • ssl vpn udp

                              I am using CR OS Version 10.6.5 MR-1. SSL vpn support UDP and TCP both protocol. in upcoming CR OS version/latest CR OS Version 10.6.6 MR-3; SSL Vpn with UDP protocol not working. I have many time talk regarding same with CR Cust Care Support team, they said cr os developer not allow to support udp in ssl vpn. I Suggest you SSL Vpn with UDP works 6X fast than TCP. Due to this lack of gap I would not recommend to upgrade CR OS, as costumer IT will be helpful if cr os in latest version work SSL Vpn…

                              1 vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • sso
                              • facebook
                              • google
                                Password icon
                                Signed in as (Sign out)

                                We’ll send you updates on this idea

                                0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                              • Created user should receive a email from firewall

                                If the administrator creates a user in the firewall,
                                then the user should receive an email like "your user account is created and credentials for login"
                                if you add this option in Sophos XG Firewall it will be very easy to the administrators or else admin wants to share the credentials to the user.

                                1 vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • sso
                                • facebook
                                • google
                                  Password icon
                                  Signed in as (Sign out)

                                  We’ll send you updates on this idea

                                  0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                • Configless SSL Client

                                  I would like to see a SSl VPN client that does not require reinstalling the application after every config change. The SSL VPN client config should be updating when it connects after a modification is made.

                                  20 votes
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • sso
                                  • facebook
                                  • google
                                    Password icon
                                    Signed in as (Sign out)

                                    We’ll send you updates on this idea

                                    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                  • 2 votes
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • sso
                                    • facebook
                                    • google
                                      Password icon
                                      Signed in as (Sign out)

                                      We’ll send you updates on this idea

                                      0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                    • IPSec Email notification

                                      In Sophos XG330, Is it possible to add a function where we can modify or customised the IPSec Email Notification wording from the current default notification?

                                      4 votes
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • sso
                                      • facebook
                                      • google
                                        Password icon
                                        Signed in as (Sign out)

                                        We’ll send you updates on this idea

                                        1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Required Domain authantication for L2TP VPN

                                        Required Domain authantication for L2TP VPN.

                                        only local users are able to connect through L2TP but not domain users

                                        2 votes
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • sso
                                        • facebook
                                        • google
                                          Password icon
                                          Signed in as (Sign out)

                                          We’ll send you updates on this idea

                                          1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Ability to add or update SSL VPN profile without dropping all tunnels

                                          Whenever you make a change to a SSL VPN Server connection in XG(Even the description!) it drops all connected sessions temporarily when you save the changes. I should be able to change the name or description on a server connection profile without dropping a session!

                                          4 votes
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • sso
                                          • facebook
                                          • google
                                            Password icon
                                            Signed in as (Sign out)

                                            We’ll send you updates on this idea

                                            0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3 4
                                          • Don't see your idea?

                                          Feedback and Knowledge Base

                                          icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-lightbulbCreated with Sketch.