XG Firewall
Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.
-
VPN Wizard: No NAT-T and other aspects
For Sophos Firewall Manager to have NAT-T and other aspects on VPN wizard
2 votes -
Wake On LAN - Send Magic Packet to Clientless Hosts
Would it be possible to incorporate sending WOL packets to host before trying to connect to them using Clientless access?
16 votes -
SPX - Sender Notifications
When sending an encrypted e-mail it would be nice if the Sender would receive confirmation from the appliance that the e-mail was indeed encrypted and sent to the recipient. Could you add this as an option in the SPX templates if it isn't already there?
8 votes -
Network Threat Reports - Links to Tools
It would be awesome if you could make the link for an Attacker's IP address take us to a place like CentralOps.net or even the built-in tools so we can reverse DNS the IP address to figure out if the threat is credible or not. Also awesome would be the ability to then block that attacker permanently by creating a firewall rule to reject traffic from that specific address with a simple button click.
5 votes -
Device Specific Authentication
UTM allows us to configure different web profiles where different device-specific authentication can be set.
This is very useful in environment where BYOD is required and more than one profile is needed.
So inherit from UTM.79 votes -
DHCP Static Assignment from List of Leases
On the UTM9 you could assign a static lease to a device by clicking on a Make Static button, please add this functionality to the XG.
66 votes -
Use E-mail Sensitivity header for SPX Encryption
Rather than require a plugin to encrypt an e-mail can you add the option of using the Sensitivity header which has been around for quite a long time now and is used by your competition (IronPort) to trigger encryption. A simple check box in the setup of the SPX profile will be sufficient. Just seems like you are trying to re-invent the wheel with your Outlook Add-in which in its current state on the UTM won't even install on most computers without an error.
2 votes -
DLP - trigger encryption based on keywords in subject
Please add the ability to encrypt e-mail based on a keyword at the beginning of the Subject of an e-mail like "Secure" or "Confidential" or "Encrypted". This functionality already exists on the SG, can you bring it over to the XG? In lieu of this could you provide more than just a plugin for Outlook? Something for mobile devices? An extension for Thunderbird?
9 votes -
WIFI - HOTSPOT - Email authentification with report
It's was a good idea to create just email authentification in Hotspot and to have report with all mail. Free Wifi is good but a lot of Customer want to have a revenu with free wifi.
8 votes -
Email Quarantine and SMTP spool management
A feature to allow Admins to do the following:
- View and perform actions (delete, download, deliver, report FP) on SMTP and POP3 Quarantine
- View the SMTP mail spool and perform actions (delete, download, view, bounce, retry)
- View SMTP log, with filters, searching, sorting
- View corrupt/undeliverable SMTP messages and perform actions (delete, download)216 votes -
Web Filter exceptions based on User Agent
I believe this is related to an existing suggestion:
http://feature.astaro.com/forums/330219-sophos-xg-firewall/suggestions/10944024-resolve-netflix-streaming-issueUTM customers are able to get around Netflix streaming issues using the workaround detailed here: https://www.sophos.com/support/knowledgebase/121646.aspx
This involves creating an exception for traffic based on its User Agent. There is no option to do this when configuring exceptions in XG as far as I can tell.12 votes -
Customize Logo for SPX Portal
Like the UTM allow for a custom logos to be uploaded and used for the SPX portal page (possibly block pages as well?). This is currently not available when making SPX templates.
20 votes -
Download archived Logs
Archive and download old logs in tgz format like in UTM: Logging and Reporting > View Log Files > Archived Log Files.
42 votes -
Notification Rules
At the moment no way to customize notification. I receive mail when the WAN gateway is down/up.
You need to provide us a way to create rules where we can decide when receive notification, alert level (warning, information, critical),who will receive the notification. As soon you integrate SMS, please also allow us to receive SMS (it is an old way) but when the mail does not work....
I would suggest you to create a panel as the Network Policy Rule rule to manage notification rules.461 votes -
Network Traffic Quota warning via email
The system should send users an email when 50%, 80% etc. of their cycles Network Traffic Quota is consumed.
18 votes -
Two IPSec Peer on VPN Configuration
We have more customer with many branches and two or more Internet connection. We want to enable a Singla VPN SA that could be terminated on two differents Peer IPSec Gateway, so we can create a reliable VPN Connection that can use two different Internet connection, depend on what we can specify as first and second Remote Peer VPN.
7 votes -
Add options for IPv6 DHCPv6-PD
My ISP supports native IPv6, they support prefix delegation using DHCPv6-PD to assign a /56 subnet. They do not assign the WAN interface an IPv6 address (i.e. no IA-NA) and only provide a prefix delegation (IA-PD). Currently XG (and UTM9) doesn't work with my ISP to get a PD because there are no options to request IA-PD only. My ISP edge router will respond to a solicit message with a IA-NA and IA-PD request but it would appear that the XG doesn't conform to RFC7550 when it sends a IA-NA message and receives a "NoAddrsAvail" from my ISP edge router.
310 votes -
Enable selectable SSL certificate for SMTPS scanning
The Email Protection lacks ability to select a specific host certificate for an exposed SMTP server. Right now only CA certificate can be chosen and host certificate is dynamically created. SSL Certificate in Email Protection could be assigned the same way Web Certificate is in Web Protection.
10 votes -
Add ability to create MAC host groups.
In the list of host objects, all have the option to create groups, except for MAC hosts. Please add ability to also create groups for those objects.
22 votes -
time of click protection
For real protection from malicious emails, this is one of the best way to protect organization. This hasn't been in Sophos email appliance, UTM but I wonder if they will be adding it to XG. Without this, there is no easy way to compete with Fortinet/Proofpoint ... I won't even mention this is demanded by customers.
12 votes
- Don't see your idea?