UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
RED: DSL/VDSL (PPPOE) Support
RED should be able to do DSL/VDSL (PPPOE), as this way it can be used with an ISP which is very common worldwide in requiring authentication against their modem.
193 votes -
RED: Compression Support for Tunnels
Please implement data compression ability for RED Tunnels. This would allow more effective throughput using RED devices with slow internet connections - especially with slow uplink speeds, and also saving RED Bandwidth on Internet Uplink on HQ if there's for example heavy usage of good compressible content as HTTP traffic, SMB access etc.
118 votesThis feature has slipped from UTM 9 and will be added in a future version in the short-term.
-
RED: Support Backup Hostname for RED Connection
Currently, REDs and ASG must find and connect through the definition of a single host-name that is fully resolvable in the public. While this can use the DynDNS feature in ASG already for "fail over", it might be more simpler to just offer another host-name field to be used in the event RED looses connection to the main host-name?
Even with multiple WAN links avaialable to an ASG, the REDs use of just a single hostname poses a problem if that particular WAN link or ISP should drop for a time (e.g. fiber cut, dead modem, etc). The downed REDs…
73 votes -
RED: Virtualized RED Appliance (vRED)
Virtual Appliance image using as RED Device
65 votes -
RED: Dedicate UTM as RED Device
It would be VERY useful to have an Option to activate an ASG as RED-Device (also known as RED-Hub-Mode). ASG works as RED-Device/Client.
ASG connects directly to another ASG using RED-function. Thus you can share SAME Networks at different Locations and bandwith is only limited by ASG and not to 30 MBit/s of a RED-Device without the need for an additional device.
60 votes -
RED: Support VLAN's behind RED
capability to create VLAN on a "Red interface" to support voip or camera vlan
46 votes -
RED: Add power-over-ethernet (PoE) to RED appliances
Our company uses PoE VoIP telephones. It would be a nice feature to be able to plug a PoE VoIP phone directly into the Red. This would provide much needed connectivity for our road warriors and employees that work out of their homes. Money would be saved since we wouldn't need to pay for dedicated business lines. A bonus would be that many commercial wireless AP's support PoE as well.
35 votes -
RED: Uplink via WiFi
RED rocks. It's simple and it works. I would like to see an option where the uplink would not have to be a hard cable to an Internet connection. Make it an option where the WAN link could be WiFi
34 votes -
26 votes
-
RED: Uplink and UMTS/3G Signal Status
It would be great to know the status of the internet connection uplink(s) in use on our RED sites. Especially with the 3G/UMTS option, perhaps a way could be found to display the signal strength as well for extra benefits?
25 votes -
RED: Selective Split-tunneling
I would like to have granular control on what traffic is split-tunneled through the RED. Specifically based on port number.
20 votes -
RED: Fail open if device fails
Currently all in-line RED deployment options (Standard/Unifed, Standard/Split, Transparent/Split) will fail "closed" when the UTM is unreachable. Ah option to permit the RED to fail "open" when the UTM is unreachable and allow traffic to the internet (as it does during normal operation with split-tunnel traffic) would greatly reduce dependence upon the central location for businesses that heavily use internet hosted applications. We can live without the AV & URL filtering for short periods of time.
18 votes -
REDs : Usng the 3G uplink to perform firmware updates
We have an opportunity that has about 90 remote sites and due to the cheap alternative of using 3G USB dongle for Internet access, they would like to see that the REDs device would have the ability to not just use the 3G connection as a failover link but is a primary link for all subsequent updates after initial provisioning at the HQ, Ethernet connection in those remote area is not possible.
16 votes -
RED: Configure UTMS/3G failover (or keepalive)
At the moment it is not possible to use multiple failover options for UMTS. This means that it can take up to 2 minutes for the UMTS to startup if the wired line fails.
I have some customers which want to use the RED and also would like to use the failover, but it needs to work quicker.
It would be a good enhancement if the client gets an option how long the Astaro will wait till the failover takes please, and has an option to keep the UMTS connection open(to help reduce connectino setup time)
14 votes -
Inverse Split Tunneling
Currently Split Tunneling is setup so that by default all traffic is sent to the internet and traffic to be sent to ASG is the split traffic's definition. It would be very convenient to add another setting where the reverse is true. By default all traffic goes to the ASG and the traffic defined as split gets sent directly out to the internet.
This would be huge advantage for a few reasons. Sending known good traffic directly to the internet would reduce the bandwidth needed at the central office. It would lower the latency for said traffic (very useful for…
12 votes -
RED to working thru captive Portals
I travel alot... and I would love to extend my network into my hotel room. Systems like iBahn, which is found in alot of US hotels use a captive portal, RED needs a way to work with those portals and then connect to the gateway unit... even if it means a little web app in the unit its self... PLEASE work on this...
12 votes -
Troubleshooting for RED
to be able to do basic troubleshooting on RED devices it would be fine to include CLI access and some basic commands like:
tcpdump
traceroute
ping
telnet (for Port checks)
...this would be fine, if something fails between remote location and central device. It would be nice to be able to prove functionality for other involved parties.
9 votes -
Reporting: Display 3G / UMTS line usage for RED
It would be nice to have an Report about all the REDs and how long they use the failover 3G connection. This would be helpful to reduce costs with UMTS-Dongles with on demand contracts and to debug problems with the primary connection.
8 votes -
Allow DNAT at RED location
It was my vision of the RED device that I would be able to replace the router/firewall devices at remote client sites and manage the sites from a central console or ASG. I was surprised last night when I learned that I cannot forward ports through a RED node.
In my scenario I have two branch offices which are using RED devices with two ASG220s (HA) at the Data Center. One branch office just has employees, so that one is fine. The second branch office currently houses the Small Business Server and a PBX phone requiring SIP. The SBS will…
8 votes -
7 votes
- Don't see your idea?