Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. Add menu item (and command-line utility) to export all SEC configuration

    - Add menu item (and command-line utility) to export all SEC configuration (groups, policies, update managers, subscription selections) to a flat file. (Preferably a human-readable version as well incase we want to use an old config as a guide when creating a new one.) Add another menu item to restore configuration (selectively) from such a file.

    It will greatly reduce the size of backups (since DB backups won't be required) and make disaster recovery and SEC machine migration far easier.

    1 vote
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
    • Wireless Protection: MAC-Filter based on vendor

      There are several customers who want to allow wireless access only to specific vendors. So it would be great when the MAC filter on a WiFi would only check the first six characters in the list (for example: Kyocera 00:14:60).

      1 vote
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
      • Support for HUAWEI E3531 3G USB UMTS Stick

        Add Huawei E3531 USB 3G Dongle to the compatible list

        35 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          5 comments  ·  Operating System  ·  Flag idea as inappropriate…  ·  Admin →
        • Allow network range object in SSL VPN

          Network range object is not yet supported in the SSL VPN configuration.It will be great if can add this feature too.

          1 vote
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
          • SMTP - Allow use of regular expressions within Exceptions

            We are currently allowed to add exceptions using host network, sender, or recipient. It would be great to be able to trigger an exception based on regular expression as well. My example is this, I had a user try to send an attachment that was flagged for Data Protection due to the content in his attachment. His attachment contained no PPI, but was flagged anyway due to the format of some of his invoice numbers. It would be great if I could allow a user to skip data protection based on a keyword inserted into a message if the user…

            1 vote
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • Add the ability to limit outgoing emails (Relay Host, not User)

              We are using the relay host feature. If a Mailserver or a Client of the Mailserver is compromised there should be a LImit to configure at the UTM to prevent flooding of the SMTP Spool and /var/storage Partition. I suggest a Parameter configurable to set a Limit of Mails per allowed relay host ip.
              I saw in the Support Forum, that many users had this problem.
              There's no possibilty in the WebGUI to bulk erase lot's of Mails in Mail Manager. If a System is spooling more than apx. 10000 Mails the UTM should be able to block at the…

              3 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
              • iOS and Android user authentication clients

                Cyberoam (a Sophos owned UTM) have client authentication apps for non-domain devices such as tablets to authenticate with an authentication service such as AD.

                1 vote
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
                • Quarantine release HTTP Port

                  Ability to change the Quarantine release HTTP port to a port below 1024.

                  24 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                  • Websites Lists - Filter Actions

                    Currently the Websites lists in a Filter Action is only available in one Filter Action. When you remove the Websites List it cannot be created with the same name across any of the filter actions.

                    Ideally you should be able to totally remove a Websites List as well as assign the exact same Websites List (with all the same Websites and any future changes) to multiple Filter Actions. I would suggest this has significant benefit to large business; more specifically education. Schools want to be able to add a Website list to all students for block/allow but still keep individual…

                    9 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
                    • Web Protection: Browser authentication without popups

                      The UTM should avoid open a popup that keeps the user authenticated. This kind of action is always blocked by the main browsers in their default configuration.

                      The system should intercept the request, ask for user+pass, and show the "authenticated as" screen only. It may try to open the requested website in a popup or through a target _blank link, but the main screen should stay opened with the logout button always available.

                      Today the current method doesn't work on a large setup when a customer can't control how their users' browsers are configured.

                      3 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                      • 50 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          7 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
                        • Web Warn Action - prompt on every visit

                          I really like the new Warn action introduced in 9.2. However I think it would be great if there was an option to be able to warn the user on every visit to a site.

                          A working example is we want to warn users when accessing cloud storage sites. It will display a custom disclaimer written by our compliance team telling them what they can and can't do on the site if they proceed.

                          Currently it warns the user on the first visit only and never again. Should the user go against what is in disclaimer, they could claim they…

                          1 vote
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                          • S/MIME Certificate History

                            Currently it is only possible to add one s/mime certificate to an internal user. If this certificate expires I have to replace this certificate with a new one. I have to replace this certificate exact on these expiration date. If I replace the certificate before expiration I can be possible that I receive encrypted emails but I can encrypt the mails because the certificate is replaced. If I replace the certificate after expiration the signature and encryption is wrong. So my Suggestion is to add a Certificate history for internal users to solve this issue.

                            3 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                            • system auto update in email appliance

                              this is the request from Platinum customer. They would like to be able to disable the auto update in Configuration > System > Updates, so they will have more control on the system version.

                              1 vote
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                              • Please add Imation IronKey Secure USB Device to supported secure devices for it to be recognized by the device control policy

                                Please add Imation IronKey Secure USB Device to supported secure devices for it to be recognized by the device control policy

                                1 vote
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                                • NAT and PAT features for RED devices on external interface, if RED device using static IP address

                                  NAT and PAT for RED device on external interface, if RED device using static IP address

                                  1 vote
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                                  • DHCP client

                                    It would be great if DHCP Client for WAN interface could be configured with Advanced paremeter such as "vendor-class-identifier" for example.

                                    4 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                                    • UTM endpoint Agent package

                                      in v9.3, the full installer is no longer available, only the slim installer is there. customers asked to put that option back just like the previous firmware version.

                                      1 vote
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Web Protection: Configurable ports full transparent web filtering - HTTP and HTTPS

                                        Would be useful for example to use this feature for web filtering in front of an existing web proxy that has already been configured for other port than 80 (e.g. 8080) without changing for all the clients/applications the proxy settings (e.g. from 8080 to 80).

                                        5 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Make the notification editable and fix the typo in the "Notification of potentional leak of data"

                                          I just setup a new UTM and enabled SPX encryption. The sender receives a notification with a subject of "Notification of potentional leak of data". First off, the word in the subject is misspelled. Users are slamming my department for this "mistake". Secondly, the title of the notification sounds so ominous and negative to the end user. Everyone is worried they are doing something wrong when the action is completely legitimate. I would love to have the ability to customize this notification or just simply turn it off. With the notification turned off the sender still receives the email that…

                                          1 vote
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            1 comment  ·  Notifications  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base