UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
Add Site-to-Site VPN Tunnel Interfaces To List Of Interfaces
Add Site-to-Site VPN interfaces to list of available interfaces or (hardware) to be used as WAN gateway to create rules and apply NAT etc...
12 votes -
WebAdmin: Notes Field
Hi, is it possible to implement a simple notes field for the dashboard? It would be nice to use it for notes like "disabled rule 10 for testing" or something else.
3 votes -
VPN: Default Keyboard layout setting (Per-User) for HTML 5 VPN
Allow configuring the default language / keyboard setting for HTML5 VPN per User in the User Portal (required by RDP Sessions). I for example always have to switch on every connection from default keyboard to swiss-german keyboard
61 votes -
Firewall Events : Filter with computer name
ADD the category "Computer name" in Firewall Events in order to filter events with computer name.
3 votes -
HA-Management-Port
Would be nice to have an HA-Management-Network-Port to access passiv-Firewall by web, ssh etc.
1 vote -
change Voucher code length and complexity
changing the length of a Voucher Code and assign which complexity the code shoud have...
3 votes -
Wireless Protection: Licencing IP Count Hotspot Mode (Voucher)
UTM Virtual Appliance - Licensing:
If you implenet a Guest WLAN using Hostspot Mode with voucher every connection attempt counts as a used IP because the DCHP server provides a valid IP.
The IP shoud only count if you also have a valid vouchercode.2 votes -
VPN: Support for Microsoft Terminal Server via HTML5 VPN
It would be nice to add/implement Remote Apps to the HTML5 Portal as well , instead of Remote Desktops Connections only
20 votes -
RED: Auto de-authorize RED devices after a configurable timeout
Automatically de-authorize a RED device if it is offline for more than X minutes. This way we can prevent someone physically taking the RED and moving it or working with it offsite.
2 votes -
REDs : Usng the 3G uplink to perform firmware updates
We have an opportunity that has about 90 remote sites and due to the cheap alternative of using 3G USB dongle for Internet access, they would like to see that the REDs device would have the ability to not just use the 3G connection as a failover link but is a primary link for all subsequent updates after initial provisioning at the HQ, Ethernet connection in those remote area is not possible.
16 votes -
Web Protection: Allow blocking Flash/ActiveX/Java Separately
Especially Flash is mostly used by many internet pages, but we want to block Java, due to the security issues!
In Version 9, you can only choose the three methods together.
13 votes -
Network connection speed display in UI
In the webadmin i can't see the uplink speed of a network card. We have different speeds on our internet uplinks and would like to see if the uplinks are 10, 100 or 1000Mbit. Contec ISC suggested the use of "ethtool eth0" on the console, but as a non-linux guy i would prefer a display in the webadmin.
Also most of the nics are on auto configure and i would like to know of the uplink speeds change, although this could be managed by setting the uplink speed to fixed and relying on a failed uplink, although this would result…
13 votes -
Firewall Violations by Interface
I would like to see a Firewall Violation report separated by interface. The current (UTM 9.0) Firewall Violation report shown in the Executive Reports combines all interfaces together. This makes it more difficult to differentiate outside-in violations from inside-out violations.
6 votes -
Stop deleting certificate when changing WebAdmin hostname
Currently if you change the Hostname of the appliance under the WebAdmin/HTTPS Certificate/Re-generate WebAdmin certificate settings, the old certificate is removed from the UTM even if it is used by Webserver Protection rules. I recommend that either the certificate is not removed or an option is given not to delete the old cert when changing the hostname. This can currently break any related web publishing rules.
1 vote -
Application Control For UTM Endpoint
Would like to see application control protection in the UTM Endpoint. To block certain files and applications form running and be alerted.
4 votes -
Wireless Protection: Give vouchers an expiration period or an expiration date
It should be possible to give hotspot vouchers an expiration period in the voucher definition so that they get a fixed expiration date when they are created.
After the expiration date the voucher should be disabled (and maybe automatically deleted) no matter if it is in use or not. The expiration date should be shown in the user portal and printed on the voucher.This is important to us because we create an amount of vouchers for our guests when they visit us. Some guests use it some not. Some vouchers lie around for an amount of time. At the…
23 votes -
Web Protection: Allow Sublinks via Override of Content Filter
Currently if a user who is authorized to unblock a site that has multiple sublinked sites embedded in the html, once the main page is unblocked the sublinks in the pages are still blocked showing the page in the browser as not complete. If a user unblocks the main site either they should have pop ups to allow access to those additional sublinks. Or the firewall will see the main site to be unblocked by the override and all sublinks with automatically be unblocked. An example to use www.ebay.com, if shopping is blocked by default and a user with…
2 votes -
Add udpxy for IPTV support
My ISP provides IPTV to the lan using udpxy in their provided solution.
It would be great to get rid of their box and have UTM getting the same behaviour.
Also this might be easier to implement than IGMP proxy (which would be great to have as well)6 votes -
SSL VPN site-to-site server fall back
Add an SSL VPN site-to-site server fall back option, for UTM with two wan interface. If the first tunnel/interface goes down, the second one is activate. It works manually. Should be automatic.
3 votes -
RED: Split Tunneling Exceptions
When the RED site goes to internet through the headquarter, when it is in Standard/Unified mode, sometimes it is needed to route the traffic through RED's own internet line for specified destinations. It is very nice to write exeptions for specified ip addresses.
4 votes
- Don't see your idea?