Astaro Security Gateway Feature Requests
Welcome to our official feedback forum. Do you have an idea? Do you recognize a good idea when you see one? We want to hear from you!
-
Increase supported RAM to 2GB for "lower" hardware appliances
In this way ASGs with 1GB RAM (ie 110/120/220) could upgrade to 2gb without losing support. It would be definitely very appreciated.
207 votes -
Add weighted phrase filtering to the content filter
Since the inclusion of a locally stored filter database in 8.2, it seems far more practical now to run all searches against a list a weighted or banned words or phrases. Similar to Dansguardian with customizable values for each entry.
42 votes -
Fix Android IPSEC/L2TP Connections
As for now for the most Android Users, regardless of version or ROM, the stock Android's IPSEC/L2TP connections does not work (just take a look at the many threads in the forums). The issue is discussed for months, but nothing happened. So here is the request, just to show how many Astaro Customers/Users are interested in a solution for the problem.
91 votes -
Can change the Local VPN ID in PSK
ASG cannot build the IPSec VPN tunnel with some 3rd party firewall/vpn gateway at one special situation. That is the central vpn gateway is other brand and it cannot accept an 'ANY Remote VPN ID' option at MAIN mode, and remote ASG has not a fix public IP address at remote node.
The reason is that the central vpn gateway does not know the peer's IP, so it cannot use the IP as peer VPN ID and ASG cannot change its local VPN ID when we set up the Authentication type as Pre-Shared Key. The default local VPN ID is… more22 votes -
Web Security: Support YouTube Educational Features
YouTube has a "for schools" (http://www.youtube.com/schools) option that requires either a custom HTTP header to be sent with requests, or a URL rewrite (much like the safe-search options already available).
I would like to see an option to create a custom HTTP header or URL rewrite for sites other than the 3 safe-search ones that exist. I suggest adding the ability to append a string to URL's that match a regex at the proxy or filter action level (e.g. For sites that match ^https?://(www.)?youtube\.com/.*, add "X-YouTube-Edu-Filter:<string>" to the HTTP header, or "?edufilter=<string>" to the end of… more
25 votesplanned ·
AdminAngelo Comazzetto
(Admin, Astaro) responded
This feature will be part of the ASG V9 Release which will enter Beta in Spring 2012.
-
More Powerful Flow Monitor
In the Flow Monitor, it would be nice to be able to click on a Host/Client, and list all of their connected Host/Clients, ports that they are using, and bandwidth used for each of those. Currently The Flow Monitor only list total traffic used by a Client/Host, but for more information the text logs have to be searched.
It would also nice to be able to have fine grain control of that traffic (throttle and blocking) in real-time from inside the flow monitor. Options like Temporary blocks, or data caps, would all be bonus too.
7 votes -
Networking: Site-to-Site VPN Bonding
I am looking layer 2 vpn bonding as it is exist in some free edition.
7 votes -
Reactive Firewall Rules
It would be great if we had the ability to turn on 'reactive rules' to start dropping all traffic from source IPs that trip a threshold of IPS or PF rules. Say someone is scanning your website for IIS vulnerabilities and trips 20 IPS rules in 1 minute (administrator defined parameters), then the ASG would create a rule at the top to block all traffic to and from the attacking source IP. Having the rule dissolve after N hours could also be an option, as well as being able to turn this rule on for specific interfaces or subnets, or… more
9 votes -
4 votes
-
WebAdmin: Role for Site-to-Site VPN Access Control Only
While Network Security Manager is already possible, it would be helpful if "Site-to-Site VPN" was an available right in the Web-Admin Access Control. Then it would be possible to set up a user who can only access that specific feature without them having other network security access.
6 votes -
Expand ipsec.conf control to webadmin
ipsec.conf has some critical settings for whole device or per site-to-site connection. In particular myid and leftid settings which are REQUIRED when the Astaro is behind a routed network being NAT'ed. This allows you to advertise the real public IP despite the Router's NIC not having that IP. Plus it's already possible, why hinder yourself by hiding something like that? This is a VERY easy thing to do and necessary to make this router more usable behind NAT's.
3 votes -
Astaro as a VPN Client
Add a VPN Client support such as L2TP inside ASG so it can connect to a VPN Server without having Site2Site.
Much like most consumer VPN router can do to connect to an Enterprise.
9 votes -
Password special characters
Switched WebProxy and users (passwords) with special characters like ä, ü, etc. are not recognized. corresponding passwords with ae, ue, etc. according to already!
Auth. AD over the network.1 vote -
Networking: Collapse & Clone Rule Groups
It would be nice to have the ability to collapse and/or clone rule sets that are part of the same group to reduce clutter on the page.
9 votes -
Reporting: Allow filtering on web reports for all fields/columns
It would be nice to filter reports to allow searchs for, e.g, blocked sites by users.
If we select the "User" report, neither "action" or the "URL" can be used for filtering. If we select the "URL", we can filter by "action" (blocked) but it misses the source/user.
I realy like the way the new reporting works, but it seems to enable the filtering only on the columns fixed in the "available reports" drop-down menu.
49 votes -
More "Last WebAdmin sessions" Logs
Currently the Management Overview log only shows the last 20 changes made by administrators. It would be nice to list more/all of the changes made.
9 votes -
Networking: Display Static & Dynamic Leases Together
My previous firewall was a SonicWALL, and on the DHCP Lease Table page, it showed all DHCP Leases, including those assigned by Static Mappings, and those assigned by Dynamic Range (in separate tables, on the same page).
In Astaro (as of v8.203), the DHCP IPv4 Lease Table ONLY shows hosts assigned an IP via the Dynamic Range (no Static Mapped hosts are shown).
I would like to see both Static and Dynamic DHCP leases shown.
4 votes -
7 votes
-
Wireless: Wireless security for third-party AP/Wireless Routers
We should have Wireless Security support for third-party WAP or Wireless Routers for us people that already have WAP/Wireless Routers.
(eg. Cisco, Netgear, Linksys, etc.)(Moreover Astaro's WAP aren't cheap)
79 votes -
Astaro OS reliability
Providing ultimate reliability and recovery, If Astaro OS and configuration files can be stored on a non-volatile solid-state disk or RAM. In the event of a hard disk failure, the solid-state disk or RAM allows the system to continue its operations.
It is secondary that a System recovery be a matter of installing a new hard disk and initiating the recovery if hot swappable HDD option be available also to lower models to the likes of ASg525 and 625. The system automatically restores itself to normal operating state.
3 votes
