UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
Monitoring: Add Zabbix / Nagios client
A lot of us (at least with bigger environments) are using systems like Zabbix or Nagios to monitor their stuff.
An direct integration of the clients into Astaro would it make a lot easier to integrate the Astaro boxes into it. SNMP alone does not provide a lot of values which are interesting to monitor. Like:
- Packet filter violations
- IPS stats
- VPN Users online
- and much more245 votes -
Management: Enable UPS sharing
It should be possible to make the UTM the UPS master and other servers obtain notifications from UTM or UTM becomes a client of another UPS server offering informations.
189 votes -
Backup: Partial Backup/Restore
Allow a user to create and restore backup files that contain only parts of the configuration.. users would be able to selectivly make use of various parts of the configuration in other firewalls, allowing for easier rollout of multi-site locations. As well, they can restore only parts of a backup file that are required, thus allowing for faster recovery and without affecting all areas of the box.
100 votes -
Management: Remove all Manufacturer Branding
We would like to remove (or replace) the Sophos/Astaro branding on outward facing things like the UserPortal, Block Pages, Email Digest etc...
72 votes -
Management: Auto-Populate Networking Definitions via Scan
By scanning the local IP-space of connected/configured internal (non-gateway) interfaces, discovered IPs should be auto-added to the definitions list using their hostname as the title (if available) otherwise just fill in the IP for both the address and the name.
This saves admins having to define their objects from scratch, and they can always delete the object definitions they don't want/plan to use. This should be done either automatically, as part of the wizard, or on request.
48 votes -
WebAdmin: How many PCs in my Network are online?
I wanna see in Dashboard how many computers are online or different ip-addresses are active.
48 votesWe might include this to WebAdmin in the future, for now, you can do it manually via the command line. As root, type:
count_active_ip.plx —showcount
-
User Portal: Using nested Active Directory Groups in allowed users
In the End User Portal I'm able to specify allowed users/ groups.
Therefor I'm able to define a group based on a Active Directory group, limited to backend group membership.
Now the limitation:
The User Portal only accepts AD Groups which are directy related to AD-Users. The use of nested AD groups (Users --> AD-Group1 --> AD-Group2) are accepted by User Portal, but without any action.A needful enhancement would be the functionality of nested AD Groups, using in User Portal
40 votes -
AD OU and Group Synchronization
With more companies using the NSG platform for Web, Email and Endpoint Management, having the ability to import OU's and Groups become more important for policy management and reporting.
Having granular policy control for Web use or Email DLP is very important for both public and private sector businesses. Most mid - large businesses require a level of departmental reports, typicaly based on users being members of particular groups or OU's.
For more than a few hundred machines, endpoint policy control is easier with the ability to group and apply machines based on how they are grouped in AD -…
39 votes -
Management: Archive backups like logs
UTM only supports automatic backups sent by email or to a UTM Manager repository.
It would be great to export them via SCP, FTP, Network Share like log files can.36 votes -
Management: Backup/Export mail quarantine, reports, database and logs to USB Hard Disk / Flash Drive
Backup or export the quarantine folders and other data not included in the backup files on the UTM. For example a mail being held in quarantine could be extremely important. If a device fails that data would be lost. Allowing external storage even just to a single restorable backup file would be a big selling point
32 votes -
31 votes
-
WebAdmin: Configuration Changes Commit/Rollback Support
Hi,
If should be great to save an history of the configuration each time an administrator save something and maybe create a restore point to rollback to the initial configuration if something does not work after some modifications.
Thanks,
21 votes -
WebAdmin: Custom Administration Roles
Expand granularity of WebAdmin roles. Current access gives an "Office Manager" too much control across too many areas under each "manager" or "auditor" level term. We have the need to let one person Release Spam and add URLs to control office traffic
It would be nice if there was a list of available areas and operations with the ability for us to make a role composed of our selections.
20 votes -
add configuration change control to webadmin
Here's what I see this feature looking like: When enabled, admins can make changes to the current config, but changes would not be applied to the running system, until the change control is approved.
Approval should be configurable, so that only authorized users can approve a change control, and optionally, require more than one admin's approval to be approved.
Multiple simultaneous change requests should be allowed, and the approval section should report the requested changes, and any changes which conflict with other requests. (i.e. two requests that edit the same object or value)
Once approved, a request should able to…
11 votes -
grace period for expired license
Please, provide a fixed grace period after the license expiration (5, 10 or more days).
This prevents to disable the features licensed if for any kind of reason the admin was not able to install the new license.9 votes -
Astaro Command Center - VMWare FUSION support
Astaro Command Center - Please Provide VMWare drivers and integration components for FUSION so Macintosh Users using VMWare can use this product. Currently you only support VMWare's esx and vsphere.
9 votes -
Management: Unify Static DNS / DHCP mappings to Object Definitions
Use the same data for DNS static entries as for Network host definitions.
Like this we would not need to enter the same data twice.9 votes -
Extended change log
The changelog in the main management tab is limited in it's length - and is also cluttered up by logins without changes and failed logins.
It would be a good thing to have a complete list of changes throughout the overall history of the ASG (on perhaps another place like "Support"->"Advanced" ) for a complete review of all changes.
9 votes -
Management: Full Change Log Publishing
Please start publishing complete change logs for new firmware releases. It is ridiculous to have to hunt for hours in the forums to find some answers. Complete change logs are a must have feature for production use -- I need to know what was changed across versions to a) judge impact on prod b) be able to quickly diagnose issues arising after upgrade (happens all too frequently)
8 votes -
make Sophos Endpoint updates by WebCID possible over HTTPS
Please make it possible to use HTTPS for WebCID updates of the product Sophos Endpoint Protection. Now only HTTP is possible, this is undesirable because authentication details (credentials) are being sent over the internet in plain text.
8 votes
- Don't see your idea?