UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
wildcards
ES5000, no facility to exclude subdomains from policy using wildcards. ie. Be able to exclude gsx addresseses from being encrypted if the policy for SPX encryption is based on subject CONFIDENTIAL, At the moment only domains can be excluded not subdomains.
Vote
1 vote -
In SMC 3.0 - GUI reporting on device types and activation dates
Company and Contact Information
Company: Gosford City Council
Contact: Elwyn Williams / Matt Roberts
Sophos Partner (if applicable):Sophos Product Information
Sophos Product: Mobile Control
Version in Production:3Feature Request Summary
How will this new feature address your business requirements?: Enable us to view takeup of device types on mobile management over time – reporting such as showing current device types, and a report on activation date perhaps
Can you also report on installed applications on all devices? – determine if anyone using an inappropriate application.
How would you rate the importance of this feature?; 1 = Critical, 5 =…2 votes -
Accommodate RobCopy with SAV use
Company and Contact Information
Company: Ausco Modular Pty Ltd (Parent Company: Algeco Scotsman)
Contact: David Wedrat - +61 7 3864 7862 / +61 434 601 401
Sophos Partner (if applicable): N/ASophos Product Information
Sophos Product: Sophos Anti-Virus
Version in Production: 10.2.7Feature Request Summary
How will this new feature address your business requirements?: Bug Fix
How would you rate the importance of this feature?; 1 – Robocopy is VITAL to our business.2 votes -
Create a Noninteractive network bootable AV Scanner
Company and Contact Information
Company: ESH Group
Contact: Ashley Hill
Sophos Partner (if applicable):Sophos Product Information
Sophos Product:SBAV ( or adaption of Sophos Endpoint Protection )
Version in Production:10.2Feature Request Summary
How will this new feature address your business requirements?:· A noninteractive network ( or PXE ) bootable AV scanner would give enterprises the ability to regularly perform a company wide scan of the network from a trusted operating system to provide confidence all known threats are detected and removed as modern malware regularly can only be detected and removed from safe mode.
· The ability to…
2 votes -
enable timeframe reporting for traffic and network protection
In order to enable drill-down on peaks in the usage graphs, enable time-frame reporting (so that the cause of a spike in packet filter blocks, or traffic, or emails processed, can be easily investigated.)
This is currently only possible per-day in the log searches, no narrower timeframes are possible.
Extending this to being able to drag-select a section of a report graph and then 'drill-down' to the underlying data would be really helpful, I think.
Tracking down what has been happening as quickly as possible and reacting accordingly is the idea.2 votes -
allow restricting access to authenticated smtp proxy to certain networks
Enable restricting Authenticated SMTP Proxy to certain networks.
It would be useful to be able to restrict access to the Authenticated SMTP Proxy to certain (trusted, or less-untrusted) networks.3 votes -
safesearch
Advanced partner would like a feature request for the Sophos Web Appliances, which was in direct result to a conversation with an existing customer within the education sector.
Currently, the SafeSearch feature is a global option, allowing you to turn it on or off for all users.
Could we please:
* Give the Administrators the option to turn this on or off per policy (Using Additional Policy Controls)
Or
* Give the Administrators the option to remove certain sites from this safe search. IE, exclude YouTube but allow all other sites to be used with the SafeSearch facility turned on.
2 votes -
1 vote
-
puremessage for UNIX log events are logged with a resolution of down-to-the-one-second mark
MTA (postfix) is configured for high-resolution timestamps,
and the order of events is important.
Because puremessage rounds up/down to the nearest second, when we look at our aggregated logs,
the order of events that should be:
incoming mail to MTA
blocklist check
mail passed to puremessage
puremessage passes (non-spam) mail back out to MTA
MTA forwards mail on to next hop
Actually appears as this sequence of events:
incoming mail to MTA
blocklist check
puremessage passes (non-spam) mail back out to MTA
MTA forwards mail on to next hop
mail passed to puremessage1 vote -
web security, application control schedule, much needed. I think it needs to be done immediately.
web security, application control schedule, much needed. I think it needs to be done immediately.
16 votes -
Synchronise UTM DNS with external DNS system, such as Amazon Route 53
Support the ability to "import" and "synchronise" entries from a public facing DNS, such as Amazon Route 53 into the Sophos UTM so that devices internal to the network doesn't have to reference the public facing DNS to resolve email, HTTP or HTTPS servers that are hosted internally. For example, if I give you my Amazon credentials, Sophos can "scan" all the entries for all domains, find those that reference the IP addresses of the Sophos device and create entries for them. If we add another entry later on to Amazon Route 53 to deal with another web server, Sophos…
1 vote -
email appliance - quarantine feature
In the quarantined messages summary email that is sent to users, provide a configuration option to turn off the inclusion of the mailto: link alongside each quarantined message listed. The reason for this is that customers don’t have an email client configured on student computers and clicking the mailto link brings up the Outlook configuration wizard which we don’t want. We would prefer that the summary email simply informs the user and provides them with a link to the portal where they can decide if they want to release the message/s.
1 vote -
global webadmin preferences
when working with sum/acc SSO its not possible to change the user preferences (tab is missing). its also missing when logging in as AD user which is not explicitly added to "Allowed Administrators" (e.g. when using AD-Groups).
i would like to set this preferences (items per page, browser title, ...) globally.
14 votes -
Wireless Protection: Granular Customization of Vouchers
To be able to pass on more information to the voucher's recipient it would be very helpful to be able to edit the layout of the voucher or at least have two separate (HTML) text fields for the Hotspot's homepage and the voucher itself.
At this build (9.003-15) you can only have one text which can be HTML and displays correctly at the Hotspot's homepage, but without any layout (plain-text like without formatting) when "printing" the Voucher's (PDF). In most situations where the connection procedure to WiFi (eg. company or hotel WLAN) is not seamless - when SSID and encryption…52 votes -
Auto pop log messages when doing updates etc.
When you choose to install an update the system just does it there is no feedback to say are you sure, especially when the system is likely to reboot after an update, for enterprise class use with the UTM 120+ then this could be a critical piece of equipment, my other request (main request) would be to have information about what is happening when tasks take longer than a few seconds (like updates), popup the up2date love log window to show the progress and actually tell the user when its done or have some sort of progress bar, a box…
1 vote -
Add "Wetransfer" to Application Control > File Transfer
I see many services under "application control" > "file transfer", 110 actually, but besides services like YouSendIt I miss Wetransfer.
Can you please add it?
1 vote -
Ability to change the admin port for the WSA GUI. Alternatively to be able to restrict the source IP’s that have access to it.
Customer's email:
Further to the feature request below to change the Admin Console port, is there any way that I can restrict the IP addresses that can connect to the Admin portal? This would give me the security required.I do not see anything in the Web Interface that would allow me to restrict who is able to request the admin portal, but is there anything you can do 'under the hood' that would restrict which IP addresses can connect?
I simply cannot allow public machines to be able to request the Admin Console
2 votes -
clean up time out error in SEC
SEC has an ability to check if the virus still presents in endpoint machines before attempting to clean up the virus from the console.
This feature will prevent clean up time out error in SEC.
1 vote -
AstaroOS: vmxnet3 network module support
These appliances currently use the "flexible" vmware network driver. This creates much greater latency than the vmxnet3 driver from VMware. Substituting these drivers is possible with your Sophos UTM product and it has greatly increased performance.
4 votes -
Whitelist for encrypted attachments
I'm using the UTM9 soft appliance as an SMTP proxy, but I'm having trouble configuring this w/ regards to incoming Emails with encrypted attachments (like password-protected zip-files). Basically, what I want to do is:
-default action for encrypted attachments should be quarantine
-define a whitelist for sender addresses allowed to send plain text Emails with encrypted attachmentsProblem is, even though I defined a whitelist and skipped the "Email Encryption" check for it, emails w/ encrypted attachments coming from the senders I whitelisted are still getting quarantined. The only way I found so far to get those Emails through is…
1 vote
- Don't see your idea?