UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
Wireless Security: Authentication via Active Directory Credentials
Add the ability to connect to the wifi network / hotspot using your AD credentials.
The “company” wifi network can then be accessed using your credentials and when an account is removed or disabled you also cannot connect to the wifi anymore. With that feature you don’t have to change the wifi code whenever a person leaves the company. Maybe also add AD group membership so you can easily grant a select group of people access to your wifi network.172 votes -
Networking: Use Listbox Widget for DNS Domains in DNS Request Routing
Allow for multiple domains per set of DNS servers.
As it is now i mostly add some internal domains to it and say which DNS servers it needs to use for it as also the in-addr.arpa zones. Now i need to make a new set for every domain which is very tiresome and unnecessary if i could just say use these DNS servers for these domainS.
2 votes -
Web Protection: Support WCCP
Customers request support of WCCP for redirecting traffic flows in real-time to an out of path appliance installed. Please add support for this.
54 votes -
Web Application Security: White / Blacklist Support for Visitor IP's
I would like to see an option to deny or allow certain ip adresses that can access the webservers. Not only based on country but on the ip adres itself.
34 votes -
Web Security: Time-Based Application Control Rules
Hi,
time based application filtering would be very nice, for example make it possible to use facebook apps at lunch time but rest of day block it104 votesThis is a candidate for an upcoming version.
-
Outdoor Wireless Access Point Model
Outdoor Wireless APs for mesh networking on outdoor environments.
200 votes -
RED: Uplink and UMTS/3G Signal Status
It would be great to know the status of the internet connection uplink(s) in use on our RED sites. Especially with the 3G/UMTS option, perhaps a way could be found to display the signal strength as well for extra benefits?
25 votes -
Endpoint Protection: Add Sophos Application Control
Include sophos endpoint style category application controls in the management features of UTM.
This will complement network based application detection and control.18 votesThis feature is currently planned for UTM 9.2 later in 2013.
-
Web Protection: Global URL Blacklist & Whitelist For All Profiles
It would be nice if we could create for the blocking a group of URLs, which may be analogous to the block "URL Filtering Categories" in the "Filter Actions". For example, the URL's to be blocked must not enter in every profile under blacklist.
63 votes -
RED: Support Backup Hostname for RED Connection
Currently, REDs and ASG must find and connect through the definition of a single host-name that is fully resolvable in the public. While this can use the DynDNS feature in ASG already for "fail over", it might be more simpler to just offer another host-name field to be used in the event RED looses connection to the main host-name?
Even with multiple WAN links avaialable to an ASG, the REDs use of just a single hostname poses a problem if that particular WAN link or ISP should drop for a time (e.g. fiber cut, dead modem, etc). The downed REDs…
73 votes -
Wireless Protection: QR Code Vouchers for Hotspot
In addition to passwords for entry via the wireless captive portal, it will help us if QR Codes can be printed on vouchers too.
Users with smartphones are able to scan the QR code with the mobile phone, which contains an individual URL to activate the session, equivalent to typing in the vouchers passcode in the captive portal.20 votesGreat idea, we’ll have a look at this.
-
NAC/Endpoint-Control of remote access users
Normally you can only check username and password (in extension a certificate ) during remote access authentication. There is no ability for checking the environment of the user, f.e. what device is he using, AV running and up-to-date, Firewall on, not using special applications, etc. .
There must be a applet used during clientless SSL-VPN access for checking the user environment against important security functions and after checking the user has to match into a security zone. Depending on which zone the user lands, there are different rules working for access the internal site.169 votes -
Web Protection: Google App domain controls via HTTP header insertion
Google supports a ways for organizations to limit which Google Apps domains users are allowed to visit. This is done by adding an HTTP header to outbound requests containing a list of allowed domains.
http://support.google.com/a/bin/answer.py?hl=en&answer=1668854#providers
24 votesWe are considering adding support for this Google App control in a future release.
-
Logging: Global live log of all activity
Please, give a way to display all available live logs together of all services in only one single window
30 votes -
Reporting: Per-Interface Bandwidth Totals
In the daily report which is sent to me by mail the IP traffic is mentioned in the first line as "Traffic Processed".
With multiple internet uplinks, VPN "interfaces", RED's, and Wireless AP's, it would be great if you could break down that total and show me some interface summaries for this!
30 votes -
Networking: Summarize DHCP Leases with a Total
When the DHCP server is configured with a large scope - say a capability of a range of 200+ leases. then it can be very difficult to determine how many leases are currently active, especially when leases that have already expired are still shown in the table. One has to manually count the entries in the table. It would be wonderful if a counter was available at the top of the lease table showing the number of current active leases.
7 votes -
Authentication: Use Wireless Credentials for other UTM modules
Passing the authentication credentials from 802.1X WPAx enterprise authentication to other UTM modules would enable seamless SSO for wirelessly connected devices and would be particularly useful for authentication of mobile devices.
38 votes -
Networking: Wildcard Hostnames for DNS Group Definitions
being able to specify a 'root' domain name, or pattern, as a network definition, that could then be used in a traffic selector for bandwidth shaping, would help greatly. content delivery networks use hundreds of hostnames, but usually stick with one 'root', example: 'something.nflximg.com' or 'something.llnwd.net' by specifying something like "*.llnwd.net' as the source, we could then limit the traffic as desired.
40 votes -
RED: Compression Support for Tunnels
Please implement data compression ability for RED Tunnels. This would allow more effective throughput using RED devices with slow internet connections - especially with slow uplink speeds, and also saving RED Bandwidth on Internet Uplink on HQ if there's for example heavy usage of good compressible content as HTTP traffic, SMB access etc.
118 votesThis feature has slipped from UTM 9 and will be added in a future version in the short-term.
-
WebAdmin: Support multiple ports (and ranges) in a single service definition
Currently for a service you can only have a range of ports or a single port. Some applications will use a range of ports in addition to a few single ports that are outside of the range, or for example 3 totally separate ports.
In the service definitions I have to create a seperate definition for each single port and each range port, then group them together. You should be able to specify any number of ports in the same service definition with commas and colons like this"2000, 4000, 3100:3200"7 votes
- Don't see your idea?