XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

Suggest an Idea...

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. OpenSSL

    Can we please update OpenSSL to a newer version and also maybe compile it to use the AES extensions in the CPU for those of us that have processors that support it? 50 road warrior vpn users and 12 red devices, and 5 site to site tunnels can crush a 310.

    1 vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • sso
    • facebook
    • google
      Password icon
      Signed in as (Sign out)

      We’ll send you updates on this idea

      0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
    • VPN PSK retrieval

      Provide a mechanism by which a site to site VPN pre shared key could be retrieved.

      2 votes
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • sso
      • facebook
      • google
        Password icon
        Signed in as (Sign out)

        We’ll send you updates on this idea

        1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
      • Clientless VPN Bookmark Groups should show up as folders

        Bookmark groups should be shown on the userportal as a folder rather than just showing the contents of the group on the main page. This would help a lot where users are members of multiple bookmark groups which are organized by type/location/department/etc.

        1 vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • sso
        • facebook
        • google
          Password icon
          Signed in as (Sign out)

          We’ll send you updates on this idea

          0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
        • Printer, clipboard, and file redirection for clientless rdp along with fullscreen and multimonitor support.

          The clientless VPN for RDP is extremely limited in its abilities.
          The standard RDP client can allow the server on the inside of the network to redirect the printers of the client PC so print jobs can be sent to the client PC. It also allows for drives on the client PC to be made available to the server and seamless use of the clipboard. The Cisco variant (using internet explorer) allows for these with no issues and supports a full screen mode. While neither supports Multi monitor, a lot of power users want to use both screens. While we…

          1 vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • sso
          • facebook
          • google
            Password icon
            Signed in as (Sign out)

            We’ll send you updates on this idea

            1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
          • Netbios over VPN

            When i connect through Connect VPN. I am not able to access my internal servers with their host name, kindly add this Netbios name feature in Upcoming patch as well as inform me when it is available.

            1 vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • sso
            • facebook
            • google
              Password icon
              Signed in as (Sign out)

              We’ll send you updates on this idea

              0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
            • PCI Compliance failed due to site-to-site IPSec VPN connection

              XG Firewall should have options to make it PCI complaint. We are failing PCI compliance because our store is connected to main office via IPSec site-to-site VPN and it's easy to just disable VPN service than justify the need of site-to-site VPN.

              2 votes
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • sso
              • facebook
              • google
                Password icon
                Signed in as (Sign out)

                We’ll send you updates on this idea

                1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
              • Sophos Connect Client auto connect.

                The Sophos Connect Client should have an auto connect feature, so that when a computer or laptop is rebooted, the Client connect automatically so that the users don't have to connect himself

                2 votes
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • sso
                • facebook
                • google
                  Password icon
                  Signed in as (Sign out)

                  We’ll send you updates on this idea

                  0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                • Sophos Connect Client - SSLVPN support

                  Sophos Connect VPN client, should support SSL VPN also, so there can be both a IPSEC profile and a SSLVPN profile, because some networks does not allow IPSEC and vice versa, then there is no need for two clients, just one ;)

                  5 votes
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • sso
                  • facebook
                  • google
                    Password icon
                    Signed in as (Sign out)

                    We’ll send you updates on this idea

                    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                  • Sophos Connect - Add groups to "allowed users"

                    In the current implementation we are unable to select groups in the "Allowed users" field. Selecting groups would vastly improve time spent rolling Sophos Connect out for our pilot users.

                    I bet a lot of other customers also use LDAP against their domain to fetch users from there. Having to maintain pilot users two places makes this a headache.

                    Thanks

                    10 votes
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • sso
                    • facebook
                    • google
                      Password icon
                      Signed in as (Sign out)

                      We’ll send you updates on this idea

                      1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                    • Fix feature SSL VPN Clientless Web Access

                      The feature SSL VPN Clientless Web Access that cannot access the remote web page when link is contain dynamic javascript content. This happen on the web page that have a link when the click show the pop up windows and web page that generated dynamically with javascrpt.

                      2 votes
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • sso
                      • facebook
                      • google
                        Password icon
                        Signed in as (Sign out)

                        We’ll send you updates on this idea

                        2 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                      • IPSEC Tunnel - IP Host Group for Remote Networks

                        Ability to create IP Host Groups for Remote Networks within an ipsec tunnel

                        1 vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • sso
                        • facebook
                        • google
                          Password icon
                          Signed in as (Sign out)

                          We’ll send you updates on this idea

                          0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                        • Sophos connect client

                          Sophos connect client should be available for Android and IOS aswell.
                          iPhone config file for the native client is full tunnel There should an option to change this..

                          1 vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • sso
                          • facebook
                          • google
                            Password icon
                            Signed in as (Sign out)

                            We’ll send you updates on this idea

                            0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                          • Remove the Limit of 50 Configs in OpenVPN GUI

                            Currently there is a limit of 50 configs in OpenVPN GUI.
                            There are already prereleases of the original OpenVPN GUI which remove those limit and add nested configurations.

                            I would like to see that in Sophos XG SSL VPN Client too.

                            1 vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • sso
                            • facebook
                            • google
                              Password icon
                              Signed in as (Sign out)

                              We’ll send you updates on this idea

                              0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                            • RED Service (port 3400) should be considered a Local Service like User Portal or SSL VPN

                              The RED service should be considered a Local Service and allowed to attach to the Zone of our choosing. This would allow us to easily add Local ACL's to limit which external IP addresses port 3400 is open on among other things. As currently configured having port 3400 open and using a self signed certificate fails PCI compliance scanning.

                              1 vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • sso
                              • facebook
                              • google
                                Password icon
                                Signed in as (Sign out)

                                We’ll send you updates on this idea

                                0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                              • SSL VPN OTP format

                                SSL VPN OTP should be able to be configured to not be current password + OTP. We would just like it to be OTP to log in, we should have the option to just use the OTP from the authenticator app.

                                3 votes
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • sso
                                • facebook
                                • google
                                  Password icon
                                  Signed in as (Sign out)

                                  We’ll send you updates on this idea

                                  0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                • Sophos Connect IPSec mapping Network Drives

                                  Sophos Connect IPSec Client should have a possibility to execute a loginscript after successfull connection for mapping network drives. (for example like Sonicwall VPN Client)
                                  or possibility to execute a script on the client side.

                                  7 votes
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • sso
                                  • facebook
                                  • google
                                    Password icon
                                    Signed in as (Sign out)

                                    We’ll send you updates on this idea

                                    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Log the source mac / hostname over ssl vpn

                                    Log the MAC address/Hostname of the client that is connecting over the SSL VPN tunnel.

                                    2 votes
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • sso
                                    • facebook
                                    • google
                                      Password icon
                                      Signed in as (Sign out)

                                      We’ll send you updates on this idea

                                      0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Sophos Client Connect auto connect user when on insecure wifi or away from office

                                      A cool function of the new Sophos Client thats available for 17.5 would be if it could be configured on the firewall to auto connect on insecure wifi or away from office. (Both should be options) I have users who would not want this at their house, but I would want to force it if they were connected to hilton wifi or starbucks wifi.

                                      1 vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • sso
                                      • facebook
                                      • google
                                        Password icon
                                        Signed in as (Sign out)

                                        We’ll send you updates on this idea

                                        0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                      • IPSec over LAN zone interface

                                        With SG you can configure IPSec site to site using LAN interfaces but with XG you only can configure IPSec site to site over a WAN zone interface. Please allow to do it also over LAN zone interfaces. Thanks

                                        14 votes
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • sso
                                        • facebook
                                        • google
                                          Password icon
                                          Signed in as (Sign out)

                                          We’ll send you updates on this idea

                                          1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                        • SSL VPN users must have the timing access for LAN resource

                                          Almost every Firewallsystem offers an option to enable VPN Access for an user just for some time. In Example : klick on the user -> Enable VPN Access for next 8h.

                                          So VPN Access ends with 8h of use and there is no need to deactivate it manually.

                                          Please provide this function.

                                          5 votes
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • sso
                                          • facebook
                                          • google
                                            Password icon
                                            Signed in as (Sign out)

                                            We’ll send you updates on this idea

                                            1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3 4
                                          • Don't see your idea?

                                          Feedback and Knowledge Base

                                          icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.