UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
Intrusion Prevention - Modified Rules SID not ID
Intrusion Prevention -> Modified Rules -> Advanced
When adding your own "Modify Rule" It asks for the Rule ID,
when it is really the rule SID you need to use.
A Minor change to the wording, but I've been caught out by this several times over the years.1 vote -
I like to have the option of been able to change the email notification display name which is hard coded. I manage few firewalls and is conf
It would be good to be able to change the notification display name which is hard coded now. I manage few firewalls and all notifications come with the same display name "Firewall Notification System" so to identify where it is coming from I have to open the notification and check for the full email address.
1 vote -
Have the utm send WOL packets.
In the network services area of the utm it would be nice to have a an option to program a list mac addresses of server / pcs that you would want to wake from power off state.
Also in the dhcp server option for the dhcp server to log PCs to this database also.3 votes -
Server Load Balancing: Enable/Disable/Weight Real Servers via an API/Special HTTP Response Code for automatic Deployments
We often deploy new Configurations and Software to our real servers behind about 15 SLBs. By now we always have to login to WebUI to manually rebalance the Real Servers we wan to maintain, and rebalance them back for the second half of a SLBs Real Servers.
It would be nice to have an SSL+Login API to do it automatically using something like Capistrano or even a predefined per-SLB HTTP Response Code, the SLB knows to rebalance to 0 for specific Servers.18 votes -
PPoE option in RED
Please put ASAP the PPoE option in the RED 50, DHCP/StaticIP is not enough, in my country PPoE is used by the principal broadband operator and once this option is not present and once the ADSL modem is not routed, I need keep another router between the red and adsl modem to provisionin IP to RED.
1 vote -
Improved Email Encryption
Improve Email Encryption possibilities similar to Zertificon Z1 (refers to most ideas also)
3 votes -
Reset a device to factory settings using a paper clip
When a Sophos UTM device is rendered inoperable due to a software or configuration problem, provide a means to reset the device to factory settings by using a paperclip to press a reset button. Like a Airport express device or many other electronic devices, it should not be possible to press the reset button accidentally.
When the reset button is depressed, beep several times, format the internal hard disk, install the software from an internal flash drive, or hidden recovery partition and when done, beep several times to notify the user its done.
When the system is restored, permit the…
3 votes -
Autoadjust IPS rules based on Network Protection rules
Automatically select only the applicable IPS rules and performance settings based on the network protection rules, e.g. only select HTTP Rules and HTTP performance settings if by filter only HTTP is allowed
1 vote -
Auto enrollment on captif portail for wireless protection
to provide a web access for customers inside hotel or public domain with only name, surname and email adress for example.
4 votes -
Button to flush conntrack table
Button to flush the conntrack table on need
1 vote -
Enable repeating for AP30
It would be great if the AP30 also had the repeating option. The AP50 is too expensive for normal clients.
5 votes -
SSL VPN virtual IP via DHCP server
The Remote Client should get a virtual pool IP from the local DHCP Server when he is connecting via SSL VPN, instead of the UTM vitual pool IP.
1 vote -
Temporarily disable On-Access-Scans
It would be great to have the ability to disable the On-Access-Scans for a certain amount of time on the client.
E.g. via right click on the systray icon:
"Disable On-Access-Scans..."
"for 1 hour"
"until reboot"This should, of course, only be possible for admins, perhaps only after entering the tamper protection password!?
7 votes -
Allow modification of "ModSecurity: Request body (Content-Length) limit"
For web sites with larger uploads (e.g. ownCloud) there is currently a 128MB (134217728 byte) limit in Web Server protection, the so called request body limit in ModSecurity.
Please add the possibility to configure this parameter (it's "SecRequestBodyLimit" in the Apache config) to allow larger uploads to sites protected by WAF.2 votes -
IPS : configure IPS to block the hacker to hack mail id to send mail with that account
I am using my UTM625 as my mail gateway and I allowed some of emails to relay messages to the gateway.One of my users email has been hacked and used to sends mass amount of emails within short period of time without my IPS on my UTM stopping it.I suggest you add this feature as it, I think, is basic Spamming/DOS preventing method.
1 vote -
report on detection specifics based on how the potential threat is detected, i.e. – on-access or scheduled scans
Client is looking to report on detection specifics based on how the potential threat is detected, i.e. – on-access or scheduled scans. It appear much of the pre-reqs should already be in placed as the endpoints report this data in the alerts they email out and the fields appear to exist in the database however they do not correlate properly. The field is specific is the 'ScannerType' in the ThreatEvents table. The 2XX data fields in the database do not accurately reflect anything
3 votes -
wildcards
ES5000, no facility to exclude subdomains from policy using wildcards. ie. Be able to exclude gsx addresseses from being encrypted if the policy for SPX encryption is based on subject CONFIDENTIAL, At the moment only domains can be excluded not subdomains.
Vote
1 vote -
In SMC 3.0 - GUI reporting on device types and activation dates
Company and Contact Information
Company: Gosford City Council
Contact: Elwyn Williams / Matt Roberts
Sophos Partner (if applicable):Sophos Product Information
Sophos Product: Mobile Control
Version in Production:3Feature Request Summary
How will this new feature address your business requirements?: Enable us to view takeup of device types on mobile management over time – reporting such as showing current device types, and a report on activation date perhaps
Can you also report on installed applications on all devices? – determine if anyone using an inappropriate application.
How would you rate the importance of this feature?; 1 = Critical, 5 =…2 votes -
Accommodate RobCopy with SAV use
Company and Contact Information
Company: Ausco Modular Pty Ltd (Parent Company: Algeco Scotsman)
Contact: David Wedrat - +61 7 3864 7862 / +61 434 601 401
Sophos Partner (if applicable): N/ASophos Product Information
Sophos Product: Sophos Anti-Virus
Version in Production: 10.2.7Feature Request Summary
How will this new feature address your business requirements?: Bug Fix
How would you rate the importance of this feature?; 1 – Robocopy is VITAL to our business.2 votes -
Create a Noninteractive network bootable AV Scanner
Company and Contact Information
Company: ESH Group
Contact: Ashley Hill
Sophos Partner (if applicable):Sophos Product Information
Sophos Product:SBAV ( or adaption of Sophos Endpoint Protection )
Version in Production:10.2Feature Request Summary
How will this new feature address your business requirements?:· A noninteractive network ( or PXE ) bootable AV scanner would give enterprises the ability to regularly perform a company wide scan of the network from a trusted operating system to provide confidence all known threats are detected and removed as modern malware regularly can only be detected and removed from safe mode.
· The ability to…
2 votes
- Don't see your idea?