Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. Networking: DSCP-Based WAN Uplink Rules

    I´d like to see a service definition based on dscp/tos values to seperate my traffic to different uplinks by tagging it with dscp tag. Currently it is only possible to make bandwidth reservation based on dscp but not routing .

    3 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      1 comment  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
    • Networking: Add rules/services enable disable to Uplink Monitoring actions

      It would be nice to be able to disable rules when all active interfaces are down and it switches to a standby one.

      For example only allow VOIP and e-mail while blocking web surfing.
      Optionally also bring up or down some IPsec/SSL tunnels.

      3 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
      • WebAdmin: Quickly restart / toggle of services without losing configuration

        If a service is not working properly (such as WiFi or DHCP service) could be selectively shutdown these without reboots the whole system.

        3 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
        • Web Server Protection: Rate limiting for anti-d/dos protection

          The WAF should have rate limiting functionality to protect against DoS attacks. This could take the form of blocking or slowing down connections from a certain IP if >X number of requests have been received over a certain time period.

          3 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
          • Android Endpoint Monitoring / Control Sophos Security & Antivirus

            We have many Android phones and tablets running the Sophos Security & Antivirus App. We would like to view/control the configuration of this app via the UTM. to be clear: I am not asking for control of the separate Sophos MDM app/product, just Sophos Security & Antivirus for Android. Ideally if Android Endpoint Antivirus management and reporting can be centralized and added into the UTM as a managed Endpoint, it would be very helpful for managing (and auditing!) our corporate-wide security policies.

            3 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • Almost two Web Profiles in Sophos UTM 100 BasicGuard

              In this segment exist two user types, the Managers and the Workers. Usually the Manager have a more permisive access to internet and the other workers need a more controlled internet access. It's is usuall in all business.

              3 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
              • Mail Archiving: More than 200 search results

                It is currently not possible to see more than 200 search results when looking for an email with AMA. If someone is looking for an email and they do not have all the details to narrow their search, having the ability to see more than 200 results is greatly needed.

                3 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                • Web Server Protection: Max File Upload Size

                  It would be nice to limit the maximum file size that could be uploaded.

                  3 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
                  • Web Protection: Per-User Bandwidth quotas by Category

                    – like entertainment (200 MB), Educational (100MB) etc… usage assignment to users.

                    3 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                    • Notifications: Notify on IP address conflicts

                      Implement http://ipwatchd.sourceforge.net/

                      Track network issues directly on the gateway!

                      3 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        3 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
                      • Logging: Option for forensic web logging

                        Very sensitive customers need to log the complete HTTP transaction (the request and response with the HTML provided by web server during the transaction). Even if it's very I/O demanding, it's a key feature that is mandatory to have to chance to sell just WEB Security in government offices, banks and customers that manage classified information

                        3 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                        • RED: Display Link for Version Lights and Codes

                          It would be nice on the UTM to have a Link to a help screen that lists the Light Available on that RED Version and the Light Codes for the boot sequence. Ver 1 has a System, Router, Internet and Tunnel, while other might have a System, Internet and Tunnel only. Also the little 1 sheet setup guide on newer RED devices doesn't detail what the light error codes mean. So you now have to guess if the problem is with the provider or with the RED itself.

                          3 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            1 comment  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                          • 3 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                            • Save Button for Changes

                              Changes in the GUI shouldn't be active immediately. There must be a save button to activate changes. It is very important to prevent mistakes and you can change several setting and activate all at the same time to not lose the connection.

                              3 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                              • Mail Protection: Deliver copy of all mails to an archive server

                                As all mails (incoming and outgoing) flow through our astaro machine, it would be the perfect place to add a 'mail archive' hook:
                                - either add a bcc address to all outgoing and incoming mails
                                - or deliver all mails to TWO servers: the mail server and the mail archive

                                3 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                • Notifications: Time-Based notification windows

                                  Often there are events that are generated in large numbers during business hours but should never occur after hours. It would be great to b able to set it to only notify if an event happens after hours or on a weekend. Having these rules send notifications all the time generates massive amounts of notifications for genuine logins but I still want to know if there is unauthorized logins during times where they should not usually occur.

                                  3 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
                                  • RED: Configurable port for communications

                                    If the RED could communicate (establish a VPN) on a port other than its default, this would allow easy integration into a network with a locked down firewall without having to involve local IT resources.

                                    Since ports 80 and 443 are often left open in small network environments, the device could be even more easily drop-shipped for installation.

                                    3 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Network Protection: Blackhole via the DNS Proxy

                                      The features OpenDNS give are awesome, if something like that was implemented on Astaro that would make administration easier for many users. The ability to be able to go through and quickly be able to force all users to point to 127.0.0.1 for malware related sites or open proxies.

                                      3 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        Under Review  ·  4 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Web Protection: Exceptions for Unscannable/Encrypted Files

                                        At the moment the astaro can only allow or block unscannable and encrypted files globally. Please provide a possibility to set this up for certain domains.

                                        3 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Recipient based e-mail signing

                                          Customers want recipient based e-mail signing instead of sender based e-mail signing on the Sophos UTMs mailgateway.

                                          3 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base