Astaro Security Gateway Feature Requests
Welcome to our official feedback forum. Do you have an idea? Do you recognize a good idea when you see one? We want to hear from you!
-
Wireless Security: Authentication via Active Directory Credentials
Add the ability to connect to the wifi network / hotspot using your AD credentials.
The “company” wifi network can then be accessed using your credentials and when an account is removed or disabled you also cannot connect to the wifi anymore. With that feature you don’t have to change the wifi code whenever a person leaves the company. Maybe also add AD group membership so you can easily grant a select group of people access to your wifi network.56 votes -
Wireless: SMS Passcode for HotSpot
Add a fourth variant for hotspot type "SMS Passcode". User enters his mobile phone number into captive portal, and will obtain a passcode via SMS. Just got this requirement today from a partner, who wants to set up a free public wifi hotspot this way for a customer...
22 votes -
real 2 way OTP SMS Authentication
real 2-way SMS-OTP-VPN Authentication:
SSL Client VPN (and SSL Clientless VPN):
1. enter username and password.
2. the ASG will send a sms otp token and waits for user input
3. enter sms token
4. authentication completely.to realize this, we need the Radius Challenge / Response feature
or the ASG sends an email with a token to a smsgateway and wait for the user input..17 votes -
Web Security: URL Filtering of HTTPS without "full" Interception
Enable the option to filter HTTPS traffic based on category for transparent proxy mode, based on the domain lookup. (No SSL interception necessary.)
It would not be as granular as full scanning, since the rest of the URL is encrypted, but it would provide some level of content filtering.26 votes -
Reporting: AD/eDir Backend Group "Departments"
Logging and Reporting - Web Security
Would love the ability to run reports based off of AD/eDir backend groups. Either by adding this functionality separately or by allowing the addition of backend groups to the ASG's built-in "Departments".
8 votes -
Networking: Masquerading (NAT) Balancing Across All Public IP's
Enterprise customers want to have a chance to use ALL pubblic addresses configure on the WAN interface, even though the HTTP proxy is turned on.
Since this special functionality is builtin into iptables, it would be nice just to have it into the webadmin, like a check box "USE ALL AVAILABLE IP ADDRESSES FOR MASQUERATING", or box to include which ip addresses will be used for masquerating (that would be even better).The reason for this feature is to keep users working, even if the primary WAN IP address is banned.
10 votes -
Authentication: Multi-User Support for Astaro Authentication Agent (AAA)
Every enterprise, university, or other large corporation has multi user computers. It would only make sense to have multi user support added to the AAA client. By default it should not install into the user's profile. It should be a workstation installation and you should have the option of installing it for all users like most programs have.
An added bonus would be if the user didn't have to enter in their credentials, the credentials would be pulled from the machine using the SSO features and automatically entered into the AAA client.
45 votes -
WebAdmin: Limit UserPortal Choices Per-User
Hi,
it would be great, if i could disable the user-portal items on a per user base.
Scenario:
I am the admin of an UTM9 with some HTML5-VPNs and the SMTP-stuff, i have some roadwarriors with SSL-VPN and the support from a service provider use the IPSec-Client for remote access.
The enduser-portal is enabled, so the people above can download their clients and configurations and change the passwords.
Now we have WLAN for our guests with a voucher.
The nice girl from the reception should issue the vouchers for the guests....and nothing more....but she get all the stuff she doesnt… more11 votes -
Endpoint Protection: Local Update Server
Although reasonable bandwith is available at most sites, it doesn't make sense, that each endpoint is updating his protection form the internet. There should be an option that either the ASG itself is the (primary) update server or one or two endpoints. I would prefer to have an extra 10 or 20 GB partition for such a feature.
19 votes -
Network Security: Self-Defending Features
"Automatic Self Defending Actions"
Based on another feature request "Automatic realtime log parser / threat analyzer" a implementation for automatic countermeasures on specific events, would allow to build active "self defending actions" as banning source IP's of potential attackers on base of failed login attempts or brute force attacks for a specific time. This cold be used for ASG services, but also published internal services through a ASG as FTP, OWA, RDP etc.
- Builds up on the feature request "Realtime Log parser / threat analyzer"
- Events in "Realtime Log parser / threat analyzer" can trigger user defined actions… more11 votes -
Network: 4G USB Support
The support for 3G modems implemented in 8.200 was great, but due to limited bandwidth maybe only useful as a failover link. Can this support also include 4G modems as the Huawei E398? With 4G, network speeds up to 80 MBit is achievable. I would use this support at customers' appliances as well as my sw appliance at home, bundling 4G with DSL!
24 votesstarted ·
AdminAngelo Comazzetto
(Admin, Astaro)
responded
We have increased device support in the UTM 9 beta which began in March. Several 4G adapters should work using a new driver set. Try yours out and let us know at astaro.org!
-
Generate a Certificate Signing Request CSR with ONE CLICK
Generate a Certificate Signing Request CSR with ONE CLICK
9 votes -
More Powerful Flow Monitor
In the Flow Monitor, it would be nice to be able to click on a Host/Client, and list all of their connected Host/Clients, ports that they are using, and bandwidth used for each of those. Currently The Flow Monitor only list total traffic used by a Client/Host, but for more information the text logs have to be searched.
It would also nice to be able to have fine grain control of that traffic (throttle and blocking) in real-time from inside the flow monitor. Options like Temporary blocks, or data caps, would all be bonus too.
37 votes -
Web Security: Exceptions for Parent Proxy
We are required to use a parent proxy for all sites. In certain instances, it is necessary to bypass the parent proxy setting when an exception is made. For instance, certain users should have access to a site that is blocked by the parent proxy. Creating an exception for this URL that also allows the user of that exception to bypass the parent proxy is an absolute must.
12 votes -
Networking: Enterprise Server Balancing
Today I fear a datacenter with several ASG and we are building a cluster environment to provide the VMWare virtual firewall service to our customers.
Lately, we have received many demands for load-balance/fail-over of bundled applications. We would like that feature in Sophos UTM was a little more mature ... so we would not need to use other appliances for this solution.
Today, Astaro allows only load-balance for TCP, UDP, HTTP, HTTPS, but without much intelligence.
A good example would be load-balance/fail-over to be implemented as below:
Method Description:
Source IP Hash: The traffic load is statically spread evenly across… more8 votes -
VPN: Spice Protocol for HTML5 VPN
Please add support for the Spice protocol. It is an Open Source solution for interacting with KVM Virtual Machines, and gives you a rich user experience. It is a kind of Remote Desktop protocol. Also, support for more Remote Desktop types would be cool, like *NX, and XDMCP.
9 votes -
limit traffic usage and warn the admin
We need a feature to monitor the WAN traffic of expensive satelite uplinks. When the paid data volume is nearly exhausted the ASG writes a mail to the Admin. So we need a max. data volume value und a threshold value.
13 votes -
Networking: Route Track Monitoring
With RTM we can track the Gateway for a static route , so that incase if gateway is not reachable the route will get disabled autoimaticaly
this lets me put the Active / passive route to one destination via multiple paths.8 votes -
Networking: Server Load Balancing to one IP
Very simply, I want to set up LB for future server expansion or to have some offline server as a fail-over. The sad thing is that the GUI does not let me only set up 1 "Real Server". This is an example of over thinking GUI capabilities that make it less useful. I had to create a fake IP for a server that did not exist. The other drawback to that, is the router now sends out ARP calls asking for someone to identify themselves as the newly defined IP for which there is no running server.
4 votes -
VPN: Act as a VPN Client
Add a VPN Client support such as L2TP inside ASG so it can connect to a VPN Server without having Site2Site.
Much like most consumer VPN router can do to connect to an Enterprise.
36 votes