XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Increase idle timeout to 24 hours for SSL VPN remote users

    Currently the idle timeout for SSL VPN remote users is only 1 hour at maximum. Please increase it to 24 hours or longer as an option. We have remote users that run data sync through the VPN session for long hours and we do not want the user to be cut off because of a mere one-hour idle time. I'd imagine this is a relatively simple code change and has no negative effect on anything? Please help.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  2. IPsec Load Balancing

    IPSEC Site to Site Load Balancing. This is for me must have option. UTM had it and I dont know why there is no Load Balancing on XG.

    18 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  3. Don't allow inline creating IP Range or IP List if they can't be used

    Establishing an IPSec between two XG devices and adding IP or Network is fine. But try adding an IP Range or a IP List. You are able to create it (and can see it later in Hosts and Services) but there is no way to choose it as a local or remote address type.

    This is quite confusing and shouldn't be there in the first place if it serves no purpose.

    Cheers.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  4. Force AD password change when logging in

    Force users to change active directory passwords if they login via SSL VPN or user portal

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  5. N2N Overlay Integration

    NTOP.org has a piece of software called n2n which is a great way to quickly create a P2P VPN over layer 2, it would be awesome if Sophos could add this protocol to the XG as yet another option for creating a VPN. Welcome to the era of Software Defined Networking.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  6. Sophos Connect RADIUS Auth

    I need to be able to authenticate Sophos Connect clients using RADIUS so that I can use my MFA service Duo. There are other use cases that this would support as well. Also, with radius authentication it should not use the internal firewall user database. It is inconvenient to require all of my users log into the firewall once so the user is created.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  7. VPN site-to-site monitoring via SNMP

    I want to monitor individual vpn site to site trough SNMP, right know only I can monitor a channel IPSec0 but only is the traffic of all vpn site to site.

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  8. VPN from LAN

    Hi
    In Sophos SG we can make a vpn connection to firewall from LAN . but in XG firewall it is disabled.
    we use it to shre internet for LAN Users and need it . Ii think it is a good idea . Please enable it.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  9. Per-user certificate authentication from third party CA

    Allow certificate based authentication for client VPN to authenticate users based on a certificate issued by a trusted third party or internal CA server. Additionally, grant authorization based on group membership of user presenting the certificate.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  10. Change MTU size on RED devices

    As there is a know issue with Citrix connections over a RED interface, I would like the possibility to change the MTU size on the WAN interface of a RED, or on the RED interface of the managing firewall.

    this can be done by running the following command from the advance firewall via putty ifconfig RED interface i.e. RED1 mtu XXXX

    Please be aware that a reboot or an firmware update will revert this back to the normal settings

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  11. Sophos Connect Client - AD password reset

    It would save a lot of client frustration if there was a mechanism built into the Sophos Connect client that allowed users to securely reset their AD account password in the event that it has expired.

    21 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  12. Grouping for VPN connection definitions

    We're now able to group firewall rules into folders, which is quite useful. Would be nice to be able to do this for VPN connections too.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  13. VPN access to Guest users

    Hi,

    I would like to request you to that enable VPN policy for Guest users. We had successfully given vpn policy to guest users but in sophos XG. We need to give vpn to guest for clients or candidates for screentesting so please look into this.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  14. Sophos Connect - Integrate Sophos Admin into XG

    It would be ideal to expand Sophos Connect to have the firewall push the policies dynamically as users login or allow for profiles (like SSL-VPN).

    This will allow for an always updated policy rather than futzing with .scx files and trying to get changes imported onto road warriors.

    7 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  15. Clientless VPN Bookmarks need more settings and ones that are there need to work.

    Please fix the HTTPS and RDP clientless VPN options, as they are now they seem either broken of half-heartedly implemented (I was being kind when I meant to say half something else). Also, it would be nice if you could add some more options, especially to the VNC/RDP module, things like color depth, resolution, encoding, etc. would be greatly appreciated.

    6 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  16. Bookmarks should appear or disappear based on connectivity

    Would be great if you could make bookmarks aware of connectivity and appear only when that bookmark will actually do something. If the destination of the bookmark cannot be reached (tunnel down perhaps?) then the bookmark should either disappear or show up greyed out and not allow it to be selected.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  17. On-demand RED Tunnels

    Would be nice if you could add an option to activate a RED tunnel only when traffic is destined for a network on the other side of the tunnel. In this way we could have RED devices behind cellular modems and not use massive amounts of data just to maintain a tunnel that isn't being used. The overhead to maintain a RED is about 2K/s which doesn't seem like much but over the course of 30 days will add up to over 500MB which is a lot on a limited cell plan.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  18. VPN PSK retrieval

    Provide a mechanism by which a site to site VPN pre shared key could be retrieved.

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  19. Clientless VPN Bookmark Groups should show up as folders

    Bookmark groups should be shown on the userportal as a folder rather than just showing the contents of the group on the main page. This would help a lot where users are members of multiple bookmark groups which are organized by type/location/department/etc.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  20. Printer, clipboard, and file redirection for clientless rdp along with fullscreen and multimonitor support.

    The clientless VPN for RDP is extremely limited in its abilities.
    The standard RDP client can allow the server on the inside of the network to redirect the printers of the client PC so print jobs can be sent to the client PC. It also allows for drives on the client PC to be made available to the server and seamless use of the clipboard. The Cisco variant (using internet explorer) allows for these with no issues and supports a full screen mode. While neither supports Multi monitor, a lot of power users want to use both screens. While we…

    16 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID Test Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    7 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.