Ability to apply UTM filters on traffic from Discover Interface so to create a report for POC
Discovered traffic from Discover interface could be made more meaningful by applying web and application filters so to get some meaningful UTM reports not just application visibility for the new customer who wants to check the UTM capability of device before buying OR before device goes to inline production environment.
Fortigate has some nice way with one-arm sniffer interface and sniffer firewall policy.
It would definitely help sophos gaining more customers while doing POC
