XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

XG Firewall

Suggest, discuss, and vote on new ideas for Sophos XG Firewall. The next thing in next-gen.

Suggest an Idea...

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. MAC address binding with SSL_VPN users machine

    Hi,
    We have configured SSL_VPN clients. I require settings like user can allow to login or install agent in specific given laptop only. Users should not allow to login SSL_VPN in any other machine.
    Can you please help me to do settings like this

    Thanks

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  2. Mobile (Portable) RED

    It would be fantastic to have a portable Wireless RED, such as a Netgear AC800S https://www.netgear.com.au/home/products/mobile-broadband/hotspots/AC800S.aspx with RED functionality. We could install this in our fleet vehicles where our officers have an in car computer and run it off of 12V. It would also help with staff who think its too hard to VPN into the network when abroad, to simply have the single device which gets them back to our network.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  3. SSL VPN (remote access) - edit options / advanced config - for .ovpn files

    Hello Everyone

    We should be able to edit some of the options of the .ovpn file

    Right now I need to manualy edit theese two options a lot in the .ovpn file directly:

    comp-lzo no -> yes (so SMB traffic does work)
    route-delay 4 -> 0 or 1 (so the route are set faster and remote ressources can be accessed immediatly)

    When there are a lot of users this is a lot of work as every user generates its own .ovpn file

    It would be really nice if this could be set for everyone on the XG UI or trough…

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  4. XG SSL VPN MAC Restriction

    XG210 FW

    To allow MAC binding for SSL VPN (remote access) in order to increase security and allow users VPN connection from specific machines (e.g. company laptops only) - as VPN client could be installed in different machines without such restriction. I called tech support and confirmed that such feature is not available for XG eventhough the function is there but it doesnt work when registering MAC address.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  5. pre-shared key

    In XG, when the pre-shared key of one IPSec tunnel is changed, it affects all the tunnels. This problem was there in Cyberoam also. Kindly work to get rid of this behavior in future firmware releases.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  6. Option to Download Sophos Connect Client and Config from LAN / WAN IP

    Option to Download Sophos Connect Client and Config from LAN / WAN IP

    Enable Option, where we can configure the Sophos Connect Client and .scx file to be downloaded from Public IP. Something similar to the way it is for Sophos SSL VPN client.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  7. Increase idle timeout to 24 hours for SSL VPN remote users

    Currently the idle timeout for SSL VPN remote users is only 1 hour at maximum. Please increase it to 24 hours or longer as an option. We have remote users that run data sync through the VPN session for long hours and we do not want the user to be cut off because of a mere one-hour idle time. I'd imagine this is a relatively simple code change and has no negative effect on anything? Please help.

    2 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  8. IPsec Load Balancing

    IPSEC Site to Site Load Balancing. This is for me must have option. UTM had it and I dont know why there is no Load Balancing on XG.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  9. IPsec Load Balancing

    IPSEC Site to Site Load Balancing. This is for me must have option. UTM had it and I dont know why there is no Load Balancing on XG.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  10. IPSec with IP Range and List Type

    Establishing an IPSec between two XG devices and adding IP or Network is fine. But try adding an IP Range or a IP List. You are able to create it (and can see it later in Hosts and Services) but there is no way to choose it as a local or remote address type.

    This is quite confusing and shouldn't be there in the first place if it serves no purpose.

    Cheers.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  11. SSL VPN portal user log on Windows: username and password remembering and Auto logon check box are not in the sophos. we need it.

    SSL VPN portal user log on Windows: username and password remembering and Auto logon check box are not in the sophos. we need it.

    2 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  12. IPsec VPN Ping rechability over the different source LAN

    We want the VPN IPsec configuration work on Interface mode. Also,allow the ability to put in a Source/Destination address for ping to validate the traffic flow. This would be help us when troubleshooting routing and VPN issues immensely.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  13. Public ip logging for SSL VPN in iView

    Would be nice to log public ip address of SSL VPN users on iView. It currently logs only DHCP address given out by the XG unit internally.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  14. SSL VPN with Active Directory OTP token generation uniq element to add.

    Current firewall Active Directory integration and OTP autogeneration via user portal for SSL VPN don't use unique element. Enable this on one firewall is working. Enable the second firewall and Mobile auth app will override first by second as account name in OTP token is the same as to use email address attribute from AD eg. user@company-domain.com. Local user on XG firewall will use user@firewallname. Propose resolution is to do OTP token account name user@company-domain.com-firewallname. That will make OTP token unique per firewall and you will be able to have AD authenitcation for SSL vpn with unique OTP…

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  15. change password

    Force users to change active directory passwords if they login via SSL VPN or user portal

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  16. N2N Overlay Integration

    NTOP.org has a piece of software called n2n which is a great way to quickly create a P2P VPN over layer 2, it would be awesome if Sophos could add this protocol to the XG as yet another option for creating a VPN. Welcome to the era of Software Defined Networking.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  17. Sophos Connect RADIUS Auth

    I need to be able to authenticate Sophos Connect clients using RADIUS so that I can use my MFA service Duo. There are other use cases that this would support as well. Also, with radius authentication it should not use the internal firewall user database. It is inconvenient to require all of my users log into the firewall once so the user is created.

    2 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  18. VPN from LAN

    Hi
    In Sophos SG we can make a vpn connection to firewall from LAN . but in XG firewall it is disabled.
    we use it to shre internet for LAN Users and need it . Ii think it is a good idea . Please enable it.

    1 vote
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  19. Per-user certificate authentication from third party CA

    Allow certificate based authentication for client VPN to authenticate users based on a certificate issued by a trusted third party or internal CA server. Additionally, grant authorization based on group membership of user presenting the certificate.

    2 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
  20. Change MTU size on RED devices

    As there is a know issue with Citrix connections over a RED interface, I would like the possibility to change the MTU size on the WAN interface of a RED, or on the RED interface of the managing firewall.

    this can be done by running the following command from the advance firewall via putty ifconfig RED interface i.e. RED1 mtu XXXX

    Please be aware that a reboot or an firmware update will revert this back to the normal settings

    3 votes
    Sign in
    (thinking…)
    Sign in with: sso facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  VPN and RED  ·  Flag idea as inappropriate…  ·  Admin →
← Previous 1 3 4 5 6
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.