XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Fix feature SSL VPN Clientless Web Access

    The feature SSL VPN Clientless Web Access that cannot access the remote web page when link is contain dynamic javascript content. This happen on the web page that have a link when the click show the pop up windows and web page that generated dynamically with javascrpt.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  2. IPSEC Tunnel - IP Host Group for Remote Networks

    Ability to create IP Host Groups for Remote Networks within an ipsec tunnel

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  3. Remove the Limit of 50 Configs in OpenVPN GUI

    Currently there is a limit of 50 configs in OpenVPN GUI.
    There are already prereleases of the original OpenVPN GUI which remove those limit and add nested configurations.

    I would like to see that in Sophos XG SSL VPN Client too.

    6 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  4. RED Service (port 3400) should be considered a Local Service like User Portal or SSL VPN

    The RED service should be considered a Local Service and allowed to attach to the Zone of our choosing. This would allow us to easily add Local ACL's to limit which external IP addresses port 3400 is open on among other things. As currently configured having port 3400 open and using a self signed certificate fails PCI compliance scanning.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  5. Sophos Connect IPSec mapping Network Drives

    Sophos Connect IPSec Client should have a possibility to execute a loginscript after successfull connection for mapping network drives. (for example like Sonicwall VPN Client)
    or possibility to execute a script on the client side.

    9 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  6. Log the source mac / hostname over ssl vpn

    Log the MAC address/Hostname of the client that is connecting over the SSL VPN tunnel.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  7. Option to create a Blackhole route for use when VPN is down

    Blackhole route will be used for vpn routes when vpn status is down will not be sent over default route.

    10 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  8. Sophos Client Connect auto connect user when on insecure wifi or away from office

    A cool function of the new Sophos Client thats available for 17.5 would be if it could be configured on the firewall to auto connect on insecure wifi or away from office. (Both should be options) I have users who would not want this at their house, but I would want to force it if they were connected to hilton wifi or starbucks wifi.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  9. IPSec over LAN zone interface

    With SG you can configure IPSec site to site using LAN interfaces but with XG you only can configure IPSec site to site over a WAN zone interface. Please allow to do it also over LAN zone interfaces. Thanks

    19 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  10. Allow temporary VPN access for a user

    Almost every Firewallsystem offers an option to enable VPN Access for an user just for some time. In Example : klick on the user -> Enable VPN Access for next 8h.

    So VPN Access ends with 8h of use and there is no need to deactivate it manually.

    Please provide this function.

    12 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  11. IPSec Connect Client Token field

    Hi,
    can you please add a token field that users don´t need to write Password+Token in one field.

    It´s better when it´s seperated, like the CheckPoint Client.


    1. Username

    2. Password

    3. Token

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  12. Multiple Users on a HTML5 Object

    I've just come across the restriction that HTML5 bookmarks can only be used for one user at a time, meaning you have to create 20 odd bookmarks so you can have concurrent users accessing the same resource, even with the extra bookmarks the users have to click on each one to find one that's not in use. It's naff to say the least. Having a single object with multiple connections would make this go away.

    5 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  13. SSL vpn user not able to access vpn remote access

    SSL vpn connection is all about remote connection to the local Lan and also it should be for VPN connection also. when we connect through SSL vpn we can access only local machines but not the remote VPN machine , thus admin has to provide another local machine for remote SSL_VPN user. Your thoughts on this......

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  14. Configure RED failover when connection is unavailable

    when xg firewall goes down for power or connectivity problem, the red ,even if configurated in split mode, disconnect all user from internet. this is a real big problem because if central xg go down all other location with red can't work... is possible to add on the red a "warning" configuration that permit to red lan to navigate only to internet (lan) with a default configuration and return in standard mode when central xg go up?

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  15. Configless SSL Client

    I would like to see a SSl VPN client that does not require reinstalling the application after every config change. The SSL VPN client config should be updating when it connects after a modification is made.

    35 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  16. Customize IPSec Email notification

    In Sophos XG330, Is it possible to add a function where we can modify or customised the IPSec Email Notification wording from the current default notification?

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  17. Allow Domain authentication for L2TP VPN

    Required Domain authantication for L2TP VPN.

    only local users are able to connect through L2TP but not domain users

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  18. Ability to add or update SSL VPN profile without dropping all tunnels

    Whenever you make a change to a SSL VPN Server connection in XG(Even the description!) it drops all connected sessions temporarily when you save the changes. I should be able to change the name or description on a server connection profile without dropping a session!

    4 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  19. Auto-discovery IPSec VPN (ADVPN)

    Please add ADVPN feature. It is very useful and requested option by the client.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  20. esp dump

    offer the same ESP DUMP Feature like in UTM 9.X on shell to have a deep view in VPN traffic and tunnel enviroment

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Sophos ID New Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.