Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. filtering on word

    The filtering and blocking of a specific word regardless of the site being allowed. if the specific page contains that word it needs to be blocked.

    IE: VIAGRA

    14 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
    • DANE

      DNS-based Authentication of Named Entities (DANE) is a procedure for the security SSL/TLS connections with the help of DNA entries, again by
      DNSSEC are protected.

      9 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
      • add a reverse FTP proxy to WebServer Protection

        Hi, please add a reverse FTP proxy with A/V scanning to WebServer Protection.

        9 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          0 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
        • Set backup run time

          With the automatic backups currently you cannot specify the time that the backup runs.
          Could this be added to standardise when the backups are run as they currently run at random times between UTM's.

          6 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            1 comment  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
          • Admin override of web filtering

            On the web filtering "blocked content" page there should be a button for an admin to log in and allow access/download the page or file being blocked.

            7 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              1 comment  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • Bradford Integration

              Hello,

              We have many customers who are experiencing issues with the integration between Bradford and Sophos.

              To be able to run a Sophos scan they are required to have admin priveledges and this is not an option for all users.

              Bradford have requested we also raise a case with you after contacting them, To pursue your co-operation with them to work together and sort out a fix for this issue.

              Regards,

              Jordan Richmond

              Khipu Networks.

              6 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
              • Ability to Export Private keys in 9.201 and above

                Prior to the release of 9.201 you were able to download both the public and private key of internal users under mail encryption. As of 9.201 you can't, the option was removed. I have had 2 examples to date that I would need the ability to download the private key.

                1. Need it for use in a 3rd part software. A client that used encryption used PGP desktop and encrypted the email and attachments that were then attached to an email and sent off. The firewall can not decrypt this type of email and therefore it came through undecrypted. We…

                16 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                • MPTCP (MultiPath TCP) / WAN Bonding / Multilining

                  Please Implementate MPTCP (MultiPath TCP) with working VPN over Multiple Lines and additional Backup lines

                  35 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                  • Add an option on application control rule to execute either before or after web filter

                    By default application control rules are executed after web filtering and once a URL is blocked by webfiltering, application control is no longer executed. It would be nice if we can specify whether an application control rule is executed before or after web filtering. This would be useful if you want to let's say block all media streaming sites except Youtube. So all I have to do is create a web filtering rule to block media streaming category and create a application control rule to allow YouTube and have it execute before web filtering. This way I don't have to…

                    4 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                    • Port forwarding/NAT configuration wizard

                      Currently, it is a time consuming nightmare for an admin, especially one new to Sophos, to configure port forwards. Doing something as simple as opening Port 80 for a web server, that would also be accessible from the LAN, is needlessly complicated. It might be nice to have powerful features in the GUI, but something should be done to make this common task more intuitive. On an old Linksys router, this is an intuitive, 3 minute task. I'm assuming most end users are not configuring port forwards every day, which means they are not experts, and it needs to be…

                      38 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        3 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
                      • Direct Yubikey Support in OTP-Module

                        Hi there,

                        it would be great if the Yubikey (www.yubico.com) could be directly supported in OTP-Module of the Sophos UTM.

                        I know that all TOTP-Token (also the Yubikey) are supported. But you need a helper program to generate the TOTP with Yubikey because it doesn't have an internal clock.

                        It would be easier (for the enduser) if the Yubikey would be directly supported (For example, by authenticating through the Yubicloud like several Radius Servers do)

                        So the user would only need to press the button and the key (that Needs to be validated with the Yubicloud or through…

                        15 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          1 comment  ·  Flag idea as inappropriate…  ·  Admin →
                        • Provide a DC Authentication Agent

                          Have an agent which polls Active Directory Domain Controllers for user logon events to determine which user is logged onto each machine. This would allow for all users on the domain to be authenticated without requiring any settings on their machines. There would need to be an option to exclude logon events for service accounts.

                          6 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
                          • spx portal should not use webadmin certificate

                            When answering an E-Mail through the SPX Portal an certificate error occurs. And it seems that the WebAdmin certificate is used.
                            It would be better when you could upload an custom certificate

                            6 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                            • FTP SITE CHANGE

                              changing the way the FTP site works

                              Essentially as the .md file in the FTP directory is from the same FTP site, it doesn't mean or validate anything (e.g. cannot be relied upon to validate the trustworthiness of the file). Reason being if the site is spoofed (e.g. via DNS) then we cannot validate the identity of the remote server, given it is clear-text FTP (no mechanism to validate the site's identity, such as via SSL/TLS). Further, if the site has been compromised, an attacker merely has to place the MD5 hash there for the malicious ISO file they replaced.

                              21 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
                              • Kensington physical lock for Accesspoints AP30

                                Protect your AP from theft with a physical cable like you can with notebooks This is one way to secure this small device better

                                9 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                • New report for iPad amount of space

                                  adding a report for checking the amount of space on all device enroled.(iPad but Android too)

                                  10 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    1 comment  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
                                  • UTM WAF - Custom HEADER

                                    Add the ability to add custom HTTP Headers while processing HTTP requests through the WAF

                                    The idea will allow me to "copy" header data
                                    e.g.: X-My-Custom-Header: $x-forwarded-proto

                                    Use case:
                                    When running a server behind 2 layered AWS ELB the first x-forwarded-proto header is overwritten by the 2nd layer, that mean that the application server cant see the original user requested protocol

                                    Lahav Savir @ Emind Cloud Expert

                                    5 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Please add all-inc.com as a dynamic dns provider

                                      Please add all-inc.com as a dynamic dns provider.

                                      9 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        2 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                                      • RED LAN Interface up/down when Tunnel up/down

                                        For monitoring purposes it would be very helpful to reflect the RED tunnel status up/down in its assigned LAN interface:
                                        Then a simple ping check (e.g. by nagios) could prove whether the RED is reachable or not.

                                        20 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                                        • WAF: Filtering IP-Adresses for an network interface

                                          WAF only let us chosse an network interface for the virtuel server to communicate to the Internet. No further filtering, e.g. a Firewall Rule for defined IP-Adresses that can connect to the network interface, ist possible.

                                          3 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            1 comment  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base