UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
SSL VPN: Convert .ovpn to .apc/.epc for Site-to-Site SSL Tunnels
Please make a tool to conver regular openvpn configuartion files to your apc/epc format. Without such a tool it is impossible to use an astaro as client for existing openvpn server.
301 votes -
VPN: Add Win7/Vista SSTP support for SSL VPN
Windows Vista and Windows 7 have built in SSTP VPN. If Astaro would support that feature, you could use VPN without installing an additional vpn client
197 votes -
RemoteAccess: Static IP for SSL-VPN
PPTP and IPsec vpn both support static virtual ip addressess assigned. Customers want to have this feature also for SSL-VPN. This way, internal users can access resources that are connected by SSL-VPN, like the printer attached to the laptop connected via Remote ACcess
151 votes -
VPN: Manually Disconnect a logged-in User
I would like to have a option on the Remote Access Status Page to throw out a logged-in-User. In some cases it would be necessary to log out a user manually with the webadmin-interface.
141 votes -
VPN: Support for Citrix Servers via the HTML5 VPN Portal
We would like to offer Citrix access to users via the HTML5 VPN portal.
64 votes -
VPN: Default Keyboard layout setting (Per-User) for HTML 5 VPN
Allow configuring the default language / keyboard setting for HTML5 VPN per User in the User Portal (required by RDP Sessions). I for example always have to switch on every connection from default keyboard to swiss-german keyboard
61 votes -
VPN: IKE V2 Support
IKE V2 is the newest innovation to IPSec and makes using of mobile clients a lot easier. I wish to integrate IKE V2 as soon as possible.
See: http://tools.ietf.org/html/rfc4306 (RFC 4306)60 votes -
VPN: Blackberry VPN Client Support
The built in BlackBerry VPN client uses AES-128, SHA1, IKE DH Group 5 (for low CPU powered devices) and PFS. See pages 271-274 in http://docs.blackberry.com/en/admin/deliverables/7228/Policy_Reference_Guide.pdf . What is not defined in this is are the IKE and IPSec SA Lifetimes, and the PFS group used. Currently Astaro's IPSec remote access GUI does not support IKE DH Group 5. However, Astaro (I think) uses StrongSwan for the underlying VPN functionality on ASG - which already supports IKE DH Group 5.
So this feature request is to
1. Enable the support of IKE DH Group 5 in the Astaro GUI for IPSec…59 votes -
VPN: Allow UTM to act as a VPN Client
Add a VPN Client support such as L2TP inside ASG so it can connect to a VPN solution without needing to setup Site2Site.
50 votes -
Routing: OSPF routing inside GRE tunnels.
GRE tunnels inside IPSEC tunnels with OSPF routing.......
45 votes -
AD/eDir Backend Group for Remote Access L2TP, IPsec & Cisco Client
Presently, the only Remote Access available to Backend grops (except RADIUS) is for the SSL VPN.
40 votes -
VPN: SSL VPN for Windows Mobile
What about an ssl vpn client for windows mobile?
36 votes -
VPN: Local VPN ID choices when using Pre-Shared-Key
If one side of a VPN is another product, it might not accept an 'ANY Remote VPN ID' option, while the UTM doesn't have a fixed IP.
Thus, the other VPN gateway doesn't know the UTM IP, so it cannot use the IP as peer VPN ID. UTM cannot change its local VPN ID when we set up the Authentication type as Pre-Shared Key. The default local VPN ID is the external IP address and cannot be changed.Please support changing the local VPN ID when the Authentication type is Pre-Shared Key, then we can use hostname or email address…
33 votes -
VPN: Windows 7 Native IPSEC Support
native ipsec client support for the integrated windows 7 ipsec client.
32 votes -
VPN: Officially Integrate Tunnelblick Mac SSL VPN
While the SSL VPN in ASG works great using the Tunnelblick client on MAC, it would be nice to have it officially integrated.
Granted it's not hard to download the configuration and use it with Tunneblick, but having it all available right from UserPortal just like the Windows SSL VPN Client would make it even better.
31 votes -
VPN: Auto-Update SSL VPN Client
It would be nice if the SSL VPN client would automatically update itself from the UTM when the client connects and a new version is available.
29 votes -
Management: Wake-on-LAN (WoL) Support
Lots of use cases where the UTM could send WoL commands. Such as to HTML5 VPN targets which are powered off.
Basicaly in the preferences we could set the destination server MAC Address to use for the wake on lan command... and have a small waiting message/progress bar until the target server is booted.
29 votes -
VPN: SSL VPN for Windows RT
Add an SSL VPN client for Windows RT.
28 votes -
Belgian French keyboard support for HTML 5 VPN portal (RDP Connection)
Add all missing keyboards for users who use RDP over HTML 5 VPN portal
27 votes -
Remote Access: SHA-2 algorithms for SSL-VPN authentication
There should be more options under "Remote Access > SSL > Advanced > Authentication algorithm" than "MD5" and "SHA1" as the OpenVPN backend also supports SHA2 algorithms like SHA-224, SHA-256, SHA-384, SHA-512...and they appear to be there, just not available in WebAdmin?
loginuser@vpn:/home/login > /var/chroot-openvpn/sbin/openvpn --show-digests
You can specify a message digest as parameter to
the --auth option.
MD2 128 bit digest size
MD5 128 bit digest size
RSA-MD2 128 bit digest size
RSA-MD5 128 bit digest size
SHA 160 bit digest size
RSA-SHA 160 bit digest size
SHA1 160 bit digest size
RSA-SHA1 160 bit digest size
DSA-SHA 160…27 votes
- Don't see your idea?