Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. Add Site-to-Site VPN Tunnel Interfaces To List Of Interfaces

    Add Site-to-Site VPN interfaces to list of available interfaces or (hardware) to be used as WAN gateway to create rules and apply NAT etc...

    12 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      3 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
    • WebAdmin: Notes Field

      Hi, is it possible to implement a simple notes field for the dashboard? It would be nice to use it for notes like "disabled rule 10 for testing" or something else.

      3 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
      • VPN: Default Keyboard layout setting (Per-User) for HTML 5 VPN

        Allow configuring the default language / keyboard setting for HTML5 VPN per User in the User Portal (required by RDP Sessions). I for example always have to switch on every connection from default keyboard to swiss-german keyboard

        61 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          3 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
        • Firewall Events : Filter with computer name

          ADD the category "Computer name" in Firewall Events in order to filter events with computer name.

          3 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
          • HA-Management-Port

            Would be nice to have an HA-Management-Network-Port to access passiv-Firewall by web, ssh etc.

            1 vote
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              2 comments  ·  HA/Clustering  ·  Flag idea as inappropriate…  ·  Admin →
            • change Voucher code length and complexity

              changing the length of a Voucher Code and assign which complexity the code shoud have...

              3 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
              • Wireless Protection: Licencing IP Count Hotspot Mode (Voucher)

                UTM Virtual Appliance - Licensing:
                If you implenet a Guest WLAN using Hostspot Mode with voucher every connection attempt counts as a used IP because the DCHP server provides a valid IP.
                The IP shoud only count if you also have a valid vouchercode.

                2 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                • VPN: Support for Microsoft Terminal Server via HTML5 VPN

                  It would be nice to add/implement Remote Apps to the HTML5 Portal as well , instead of Remote Desktops Connections only

                  20 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
                  • RED: Auto de-authorize RED devices after a configurable timeout

                    Automatically de-authorize a RED device if it is offline for more than X minutes. This way we can prevent someone physically taking the RED and moving it or working with it offsite.

                    2 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                    • REDs : Usng the 3G uplink to perform firmware updates

                      We have an opportunity that has about 90 remote sites and due to the cheap alternative of using 3G USB dongle for Internet access, they would like to see that the REDs device would have the ability to not just use the 3G connection as a failover link but is a primary link for all subsequent updates after initial provisioning at the HQ, Ethernet connection in those remote area is not possible.

                      16 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        Under Review  ·  0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                      • Web Protection: Allow blocking Flash/ActiveX/Java Separately

                        Especially Flash is mostly used by many internet pages, but we want to block Java, due to the security issues!

                        In Version 9, you can only choose the three methods together.

                        13 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          1 comment  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                        • Network connection speed display in UI

                          In the webadmin i can't see the uplink speed of a network card. We have different speeds on our internet uplinks and would like to see if the uplinks are 10, 100 or 1000Mbit. Contec ISC suggested the use of "ethtool eth0" on the console, but as a non-linux guy i would prefer a display in the webadmin.

                          Also most of the nics are on auto configure and i would like to know of the uplink speeds change, although this could be managed by setting the uplink speed to fixed and relying on a failed uplink, although this would result…

                          13 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                          • Firewall Violations by Interface

                            I would like to see a Firewall Violation report separated by interface. The current (UTM 9.0) Firewall Violation report shown in the Executive Reports combines all interfaces together. This makes it more difficult to differentiate outside-in violations from inside-out violations.

                            6 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
                            • Stop deleting certificate when changing WebAdmin hostname

                              Currently if you change the Hostname of the appliance under the WebAdmin/HTTPS Certificate/Re-generate WebAdmin certificate settings, the old certificate is removed from the UTM even if it is used by Webserver Protection rules. I recommend that either the certificate is not removed or an option is given not to delete the old cert when changing the hostname. This can currently break any related web publishing rules.

                              1 vote
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                              • Application Control For UTM Endpoint

                                Would like to see application control protection in the UTM Endpoint. To block certain files and applications form running and be alerted.

                                4 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                • Wireless Protection: Give vouchers an expiration period or an expiration date

                                  It should be possible to give hotspot vouchers an expiration period in the voucher definition so that they get a fixed expiration date when they are created.
                                  After the expiration date the voucher should be disabled (and maybe automatically deleted) no matter if it is in use or not. The expiration date should be shown in the user portal and printed on the voucher.

                                  This is important to us because we create an amount of vouchers for our guests when they visit us. Some guests use it some not. Some vouchers lie around for an amount of time. At the…

                                  23 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    2 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Web Protection: Allow Sublinks via Override of Content Filter

                                    Currently if a user who is authorized to unblock a site that has multiple sublinked sites embedded in the html, once the main page is unblocked the sublinks in the pages are still blocked showing the page in the browser as not complete. If a user unblocks the main site either they should have pop ups to allow access to those additional sublinks. Or the firewall will see the main site to be unblocked by the override and all sublinks with automatically be unblocked. An example to use www.ebay.com, if shopping is blocked by default and a user with…

                                    2 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Add udpxy for IPTV support

                                      My ISP provides IPTV to the lan using udpxy in their provided solution.
                                      It would be great to get rid of their box and have UTM getting the same behaviour.
                                      Also this might be easier to implement than IGMP proxy (which would be great to have as well)

                                      6 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                                      • SSL VPN site-to-site server fall back

                                        Add an SSL VPN site-to-site server fall back option, for UTM with two wan interface. If the first tunnel/interface goes down, the second one is activate. It works manually. Should be automatic.

                                        3 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
                                        • RED: Split Tunneling Exceptions

                                          When the RED site goes to internet through the headquarter, when it is in Standard/Unified mode, sometimes it is needed to route the traffic through RED's own internet line for specified destinations. It is very nice to write exeptions for specified ip addresses.

                                          4 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                                          1 2 5 6 7 8 10 12 13 14 15 59 60
                                          • Don't see your idea?

                                          Feedback and Knowledge Base