UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
Mail Security: Show Deferred Mails in Mail Manager/UserPortal (eg. Greylisted)
If a incoming Mail is delayed by Grey listing, this is not viewable in the Mail Manager. This is a Problem in Environments where End users really use the End User Portal for tracking their Mail.
In the End it has to be reviewed by the Admin again because you can only find out these Mails in the smtp-proxy Logfile.69 votes -
Mail Security: Configurable Parameters for Retries
I would suggest to implement a "maximum-transmission-attempts" counter that bounces the mail if sending has *successfully* begun and has been aborted more then ... lets say 10 times.
21 votes -
Pushing Routes to SSL Clients with custom Metric
It would be helpful to define which routes are pushed to the SSL clients AND define the desired Metric to the route. I's needed when clients open the tunnel in the internal network and you don't want the traffic to go through the tunnel instead of the local NIC.
5 votes -
Definitions: Change Definition "Types"
When you add a Network or Service definition, you have to give it a type. For example Host (that you have to supply an IP) or DNS Host (that you have to supply a dns to be resolved). Since you create a definition of a specific type, you can`t change it afterwards so if you have many rules relying on that definition and you need to change a static IP (of type host) to a dynamic dns host (type of DNS Host) for example, you`ll have to create a new definition first, check where the old definition was used and…
3 votes -
Networking: Configurable MTU for HA-Interface
several times we had the problem with MTU setting on HA interface. In an datacenter environment there is no possibility to link HA interfaces with direct cabling. So we have to implement a VLAN between locations of both ASGs. From this point we had problems with bigger ASG appliances, because they set MTU per default to 2000, which needs support of jumbo frames on switches, what we cannot provide.
We solved this via the command line but after some up2dates it resets to 2000 on some updates.
If we could set MTU manually on HA interfaces (on all other interfaces…27 votes -
Network: VLAN as Additional Address
It would be nice to be able to add a VLAN as an additional address on an existing interface that is already in use.
33 votes -
Web Security support for domain suffix search
The proxy doesn't seem to be able to apply any default DNS domain suffixes when doing a lookup. So if a user supplies a short DNS name in the URL, the proxy fails to find the page. Granted, this is only an issue if the proxy is used for internal sites, but I have seen many cases where this has been true now.
4 votes -
Reporting: Reports by User Agent
It would be nice to sort reports/statistics by User Agents.
1. You'll be able to only look at real users - Software Update Agents wont be displayed
2. You have the chance to find unwanted Devices in an easy way
Maybe it will make sense to add this also to the filters section. even if I know that you can fake your Browser Agent - as I do exactly now ;-)8 votes -
SSL VPN: Client Installation Options
It would be nice if you could pass options to the SSL VPN Client installer, such as
auth-nocache etc....17 votes -
QoS inside a bridged network
Please make QoS through a bridge work, that we can guarantee or limit bandwidth for applications.
5 votes -
Mail Protection: Multidrop POP3 Support
Some isp's offer multidrop pop3 accounts. Basically one acount downloads all the messages from the pop3 server
3 votes -
19 votes
-
MailSecurity: Require encryption/signature
Using a special marker mail should be disallowed if encryption/signature are not possible.
This should result in an NDR - "mail not send - encryption not possible"18 votes -
9 votes
-
Mail Protection: Non-delivery report for blocked Outgoing messages
In my opinion its useful to receive a Non Delivery report for outgoing sended emails. Blocked file extensions like .exe or .bat will block ANY directions of mails (extern to intern and also intern to extern).
These messages will be quarantined however internal users will not receive any information about that like an NDR. He belief, that the mail was delivered correctly.
44 votes -
Authentication: Routing Authentication per Domain
It's important to have a chance in big customers the chance to route authentication process in base of domain name. it would an improvement about what there is already available. Example: users@gabriele.com will be authenticated by radius on server1; if authentication fail, users@gabriele.com will be authenticated by Active directory on server2. ecc.
Very efficient in big environment.
47 votes -
Add GB English as a Language Option
Can we have an English GB setting in this version please, so that the dates in the reports are shown the correct way round and words are spelled correctly like Organisational.
(I know there are more yanks out there than us brits, but we did invent the english language)
6 votes -
Stricter Control over Relaying Allowances
Currently Email Relay checks for allowed users and Host based, in both cases the user name or IP address can be spoofed or hijacked by a spambot, it would be great to have more granular checks such as that the user allowed to relay should send with the same account and as well limit maximum number of emails per sender.
4 votes -
Scan Dropbox files
Implement a Dropbox (https://www.dropbox.com/ and similar) filtering and scanning functionality for those that use this type of exchanging files.
9 votes -
Mail Security: Increase Database Retention for SMTP to 1 Year
Current SMTP database log only allows 30 days retention. Many organizations will have a one-year retention policy.
7 votes
- Don't see your idea?