Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. Mail Security: Configuration Changes Based on Reporting

    The Quarantine Report should provide a 3rd option (besides release & whitelist), namely whitelist domain. This would trim the size of the user's whitelist considerably and cut down on false positives from the same domain.

    4 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
    • AstaroOS: Choose CLI keyboard layout in WebAdmin

      Hello,
      the tech support suggest me to ask here this feature: when you log in directly to consolle (connecting usb keyboard to ASG) the default keyboard layout is american. In this way if you have to use special charaters for password (in most of cases you'll do!) it's hard to digit the correct keys! It would be great (and very easy I suppose) to choose the default keyboard layout in webadmin, in my case IT.

      4 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        4 comments  ·  AstaroOS  ·  Flag idea as inappropriate…  ·  Admin →
      • Mail Security: SMTP Routing by individual mail address

        It should be possible to configure a mail route, which is used for special e-mail-adresses only. The e-mail adresses can be configured via the Mail-Security/SMTP-Profile WebAdmin.

        For example, we want admin@xcompany.com to go to 192.168.50.88 while everything else for that domain goes to 192.168.50.22

        4 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          1 comment  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
        • WebSecurity: HTTP/S MIME-Type Whitelist

          As is possible with Mail Security, add the ability to the exceptions tab to "exempt" certain mime types from filtering.. Allows for MIME types to be removed from filtering and scanning to increase compatability with perhaps streaming we do not support natively, and balances the feature offerings with the mail security choices.

          4 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
          • Web Protection: Allow Overriding the Content Filter for File Extensions

            I have URL Filtering set up to allow an Active Directory group to temporarily bypass the URL Filtering by entering a users AD credentials. Is there a way to allow an Active Directory group to TEMPORARILY bypass the extension blocking such as an .exe file in the same way by entering user credentials?

            4 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              1 comment  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • Ability to Blacklist\Whitelist from the SMTP Log

              The SMTP Log is a great tool for finding out exactly what happened to your message quickly. What I propose is to increase this tools functionality. Currently you have to find out why your e-mail was blocked or where spam e-mail really came from in the SMTP Log and then go to another section to Whitelist or Blacklist the e-mail. I adding a few buttons to the SMTP Log messages to simply add the E-mail to Blacklist\Whitelist, Submit as Spam and Deliver. This would simplify the whole process.

              It would also be nice to add a header button, so that…

              4 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
              • Allow DSCP tagging on inbound internet traffic from a certain host.

                With internet (cloud) based services being used more, having the ability to tag inbound traffic from known hosts with DSCP tags would be good for lower speed dedicated WAN links (which are generally quite slow and centralized at one site).

                Our organisation does this at a datacentre using UTM and we are needing to implement QoS on inbound internet traffic so that VOIP traffic takes priority over file transfers etc from the servers at the datacentre to the clients at the remote sites over dedicated WAN links (which will follow DSCP tagging rules).

                The internet strips all DSCP tags so…

                4 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                • Mail Security: Use Phising Filter to stop Malicous Links

                  The Phising Filter in the mail security already filters URL's in mail for known phising servers. Please also add the possibility to filter more URL categories - at least "Malicious Sites" and "Spyware/Adware". Or the nonplusultra feature would be, if we could filter mails against any of the Smartfilter XL categories (as P2P and others).

                  The rising number of mails linked to malicious sites will make this feature very desireable.

                  ==> http://www.searchsecurity.de/themenbereiche/bedrohungen/phishing-und-spam/articles/258639/?nl=1&cmp=newsletter_applikationssicherheit_13-04-2010

                  4 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    2 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                  • Auto enrollment on captif portail for wireless protection

                    to provide a web access for customers inside hotel or public domain with only name, surname and email adress for example.

                    4 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                    • Quarantine Manager RSS feed

                      I'd like to see an RSS feed added to the mail manager in the user portal, specifically for end users. Some of my users are micro managing their email quarantine by just staying logged into the mail manager all hours of the day. With RSS support MS Outlook 2007 and Internet Explorer, this could probably be sold as an Outlook / Internet Explorer integration as well.

                      4 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        2 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                      • change Voucher code length and complexity

                        changing the length of a Voucher Code and assign which complexity the code shoud have...

                        3 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                        • dynamic port for oracle

                          hi i want that the firewall handle dynamic ports for oracle comunications that start on tcp1521 then they change the ports dynamically. currently we are opening all non standrd port for database traffic. in cisco firewall i just open 1521 then the firewall will monitor the communication to automatically discover and open dynamic ports.regards

                          3 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                          • Server load balancing check port

                            It would be great if we could select a port to check.

                            If I configure a loadbalancing for service http, i don't want to check for port 80 - I'd like to check port 666/tcp for example (a kind of loadbalancer-Switch in IIS).

                            3 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                            • Network Security: Automatically Parse Logs / Analyse Threats

                              A feature to automatically parse local ASG logfiles AND received syslog logfiles from remote devices in realtime, and find user defined events. Would be helpful for example with all published services towards internet as FTP, SSH, Terminalservices, OWA etc. Usually anyone will be affected by brute force attacks or login attempts to these services from unauthorized people. As there is usually no notification in case of such events as failed logins on a terminalserver for example and has to be searched manually in the servers logs.

                              - Sophos UTM appliances should be able to parse local and via syslog received,…

                              3 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                1 comment  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                              • Create an ALERT that triggers when a user has been BROWSING internet for two consecutive hours?

                                Site have a WEB Appliance (hardware WS5000) and need to:
                                Create an ALERT that triggers when a user has been BROWSING internet for two consecutive hours?

                                3 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                • Web Protection: Masquerade HTTP Proxy to Addtional IP(s)

                                  Masqerade NAT rules should apply even with traffic that goes through the http proxy.

                                  3 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    3 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Create a master group of PRODUCTIVITY LOSS that is comprised of sub groups of all the categories, so that reports can be run

                                    Site have a WEB Appliance (hardware WS5000) and need to:
                                    Create a master group of PRODUCTIVITY LOSS that is comprised of sub groups of all the categories, so that reports can be run
                                    (ie How long has Joe Bloggs been on non work related sites?)

                                    3 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Networking Protection: Packet Filter Rule Labelling for Log

                                      It is great to have the fwrule field in the Packet Filter log, but rule numbers sometimes change, and then it becomes very difficult to search the older logs for a match on a given rule. It would be a lot easier if there was an option to name a rule and this name was logged in either the fwrule field or a new rulename field.

                                      3 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Reporting: Detailed activity for Web Security uploads

                                        Please implement a logging and reporting of the upstream activity of the users. Currently (v8.300) there is only a detailed reporting and logging of downstream activity.
                                        But in fact upstream may be the more dangerous part of web usage in a company, when it comes to data theft etcetera. In the moment I cannot tell my boss what user XY has uploaded to website ABC.

                                        3 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                        • report on detection specifics based on how the potential threat is detected, i.e. – on-access or scheduled scans

                                          Client is looking to report on detection specifics based on how the potential threat is detected, i.e. – on-access or scheduled scans. It appear much of the pre-reqs should already be in placed as the endpoints report this data in the alerts they email out and the fields appear to exist in the database however they do not correlate properly. The field is specific is the 'ScannerType' in the ThreatEvents table. The 2XX data fields in the database do not accurately reflect anything

                                          3 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base