XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

Suggest an Idea...

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. WAF possibility to edit SecRequestBodyNoFilesLimit value

    In the WAF configuration is impossible to edit the SecRequestBodyNoFilesLimit instruction.
    If an user upload a file greater than 1 Mb receives the error
    Request body no files data length is larger than the configured limit - 413 Request entity too large

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  2. We are not able to see the actual public IPs which are accessing the Web Server behind WAF , we need this feature for many reasons

    We are not able to see the actual public IPs which are accessing the Web Server behind WAF , we need this feature for many reasons like forensics and statistics.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  3. XG Log Viewer for WAF needs major improvement

    We use XG for Web Server protection. The log viewer is really poor and I strongly believe does not provide a reasonable way to see clearly the traffic which is passing and traffic which is failing.
    I have raised #839149 in October 18. Despite responding that I need more information, all I get is :

    "this behavior is already logged with DEV under ID NC-43502. There are certain messages that will be colored red in the log viewer, typically ones that originate from WAF itself, like a block action by CTF or AV. To see the detailed WAF Logs, u…

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  4. FTP server Anti-Virus scanning like WAF

    DNAT/NAT/Load balancing rule or WAF should have FTP server option. So that any files uploaded or downloaded from FTP server in any secured ZONE like LAN or DMZ should be protected. Cyberoam has such facility but it is lacking on SOPHOS. If FTP client upload ransomware or virus than it will blow up the secure network. it is security loop hole.

    3 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  5. ModSecurity version 2.X.X to version 3.X.X

    The latest version sof ModSecurity WAF rules are in version 3.X.X. Is there a plan to get these added to webserver protection, since they produce less false positives and perform better than the 2.x.x rules.

    5 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  6. Add protocoll of current Windows product to the business rules ... (Windows 2016 / 2019)

    You had support for Remote Desktop Gateway protocoll (Windows 2008 and 2008 R2) implenented. In the state of the art fw, the modern OS (Windows 2012, Windows 2012, Windows 2019) is not supported for some protocolls.

    4 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  7. Request to have IP List to be configure under Allowed /Blocked client networks under Access Permission on WAF Firewall Rule

    Hello Team,

    We have customer here requesting to have IP List to be configure under Allowed /Blocked client networks under Access Permission on WAF Business Application Firewall Rule.

    For your assistance please. Thank You.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  8. Webserver Protection Password Validation for Forms template.

    Webserver Protection forms authentication do not have any kind of validation for wrong username or password. IF a user types in incorrect credentials there is not notification why, just reloads page. This product is not ready for production without it. Even the Hotspot login page have customization for errors. https://docs.sophos.com/nsg/sophos-firewall/17.5/Help/en-us/webhelp/onlinehelp/nsg/sfos/concepts/LoginPageTemplate.html

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  9. tls verification errors must be logged

    As long as you open a https page via browser you may see that there is an ssl verification error and xg did block traffic.

    as tls verification is also implemented in FTPS (Scan FTP for Malware) you wont get any message on fails, you just can imagine that traffic won't pass because of an tls error.

    same if https is use by applications e.g. internal software updates

    3 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  10. WAF - Increase Page Timeout

    We would like it to be possible to increase the timeout period in for underlying web servers. In some specific requirements, web pages will take longer than 60 seconds to load - thus exceeding the hard-coded timeout of the Sophos XG.

    Please allow us to increase this timeout manually.

    2 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  11. Allow customizable block pages for WAF

    Allow customizable block pages for WAF

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  12. web application firewall

    WAF redirect custom port http automatically to https.

    it can not forward automatically when uses custom port. Example: listening port : 8080 with url: www.example.com and redirect HTTP and HTTPS (tick). User from internet request type url: http://www.example.com:8080. It will not automatic redirect https://www.example.com:8080. It shown " Your browser sent a request that this server could not understand Reason: You're speaking plain HTTP to an SSL-enabled server port.
    Instead use the HTTPS scheme to access this URL, please." It is only work for port 80 redirect to https instead of custom port (based on Sophos Support Team). User…

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  13. DNAT

    apply traffic shaping based on folder wise in web server hosted in LAN

    Traffic shaping based on each sub-folder/URL in IIS web server by using DNAT for Inbound Traffic

    Not based on IP

    0 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  14. redirect

    Hello,

    We need to be able to redirect from https://mydomain.com to https://www.mydomain.com. Right now this is not possible. See support ticket #8223918

    5 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  15. WAF - Country Block

    Hej,
    please add the posibility to add a country or country group to "Allowed Client Networks" and "Blocked Client Networks". This is very important for us.

    Thank you.

    Best regards,
    Michael

    14 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  16. WAF Service Reboots when we make change to any WAF rule of web server

    Hi,
    Currently when we make a change to any web server or any one waf firewall rule, the impact is that the whole service reboots and causes a drop in connection for all the WAF services running.
    This should not be the case. only the rule that is being edited should be affected and not all the services.
    This is also how its done in MS TMD

    5 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  17. Dynamic (Automatic) Certificates on Web Server Protection

    Currently under WebServer Protection, you are required to setup an SSL Certificate for each Web Server that you are trying to protect. In a web hosting environment this is not plausible or even practical.

    Use Case Scenario:

    - CPanel Web Hosting server could potentially be hosting 100's or 1000's of Web Sites.
    - It is best practice to SSLize Websites. Using standard http is no longer desirable, and it's easier than ever now to automate SSL certificates on websites hosted with CPanel (See next point)
    - CPanel provides automatic SSL certificate deployment from Comodo Secure to any website you want…

    3 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  18. Web Server Protection: Certificate-based Authentication

    Hello Team,

    Asking assistance if we could be able to add Certificate-based Authentication for web server protection. We have customer here needing this as requirement on their set up.

    6 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  19. WAF Signature ID does not show in GUI Log viewer; only availible via console logs

    Team, This request is to include the actual signature ID being invoked in the GUI WAF logs. Including this will assist us when figured out which rule to bypass, if needed.

    5 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
  20. Inline WAF

    1) WAF is not supported when deployed inline.
    2) WAF not supported if NAT/traffic is not terminated on the firewall

    Ticket reported : [#7882861] WAF requirment

    3 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Webserver Protection  ·  Flag idea as inappropriate…  ·  Admin →
← Previous 1 3
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.