Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. Mail Security: Show Deferred Mails in Mail Manager/UserPortal (eg. Greylisted)

    If a incoming Mail is delayed by Grey listing, this is not viewable in the Mail Manager. This is a Problem in Environments where End users really use the End User Portal for tracking their Mail.
    In the End it has to be reviewed by the Admin again because you can only find out these Mails in the smtp-proxy Logfile.

    69 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      3 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
    • Mail Security: Configurable Parameters for Retries

      I would suggest to implement a "maximum-transmission-attempts" counter that bounces the mail if sending has *successfully* begun and has been aborted more then ... lets say 10 times.

      21 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        9 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
      • Pushing Routes to SSL Clients with custom Metric

        It would be helpful to define which routes are pushed to the SSL clients AND define the desired Metric to the route. I's needed when clients open the tunnel in the internal network and you don't want the traffic to go through the tunnel instead of the local NIC.

        5 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
        • Definitions: Change Definition "Types"

          When you add a Network or Service definition, you have to give it a type. For example Host (that you have to supply an IP) or DNS Host (that you have to supply a dns to be resolved). Since you create a definition of a specific type, you can`t change it afterwards so if you have many rules relying on that definition and you need to change a static IP (of type host) to a dynamic dns host (type of DNS Host) for example, you`ll have to create a new definition first, check where the old definition was used and…

          3 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
          • Networking: Configurable MTU for HA-Interface

            several times we had the problem with MTU setting on HA interface. In an datacenter environment there is no possibility to link HA interfaces with direct cabling. So we have to implement a VLAN between locations of both ASGs. From this point we had problems with bigger ASG appliances, because they set MTU per default to 2000, which needs support of jumbo frames on switches, what we cannot provide.
            We solved this via the command line but after some up2dates it resets to 2000 on some updates.
            If we could set MTU manually on HA interfaces (on all other interfaces…

            27 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              3 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
            • Network: VLAN as Additional Address

              It would be nice to be able to add a VLAN as an additional address on an existing interface that is already in use.

              33 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                1 comment  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
              • Web Security support for domain suffix search

                The proxy doesn't seem to be able to apply any default DNS domain suffixes when doing a lookup. So if a user supplies a short DNS name in the URL, the proxy fails to find the page. Granted, this is only an issue if the proxy is used for internal sites, but I have seen many cases where this has been true now.

                4 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  1 comment  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                • Reporting: Reports by User Agent

                  It would be nice to sort reports/statistics by User Agents.

                  1. You'll be able to only look at real users - Software Update Agents wont be displayed
                  2. You have the chance to find unwanted Devices in an easy way
                  Maybe it will make sense to add this also to the filters section. even if I know that you can fake your Browser Agent - as I do exactly now ;-)

                  8 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
                  • SSL VPN: Client Installation Options

                    It would be nice if you could pass options to the SSL VPN Client installer, such as
                    auth-nocache etc....

                    17 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      1 comment  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
                    • QoS inside a bridged network

                      Please make QoS through a bridge work, that we can guarantee or limit bandwidth for applications.

                      5 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                      • Mail Protection: Multidrop POP3 Support

                        Some isp's offer multidrop pop3 accounts. Basically one acount downloads all the messages from the pop3 server

                        3 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          1 comment  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                        • 19 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            3 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
                          • MailSecurity: Require encryption/signature

                            Using a special marker mail should be disallowed if encryption/signature are not possible.
                            This should result in an NDR - "mail not send - encryption not possible"

                            18 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              2 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                            • 9 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                1 comment  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                              • Mail Protection: Non-delivery report for blocked Outgoing messages

                                In my opinion its useful to receive a Non Delivery report for outgoing sended emails. Blocked file extensions like .exe or .bat will block ANY directions of mails (extern to intern and also intern to extern).

                                These messages will be quarantined however internal users will not receive any information about that like an NDR. He belief, that the mail was delivered correctly.

                                44 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  4 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                • Authentication: Routing Authentication per Domain

                                  It's important to have a chance in big customers the chance to route authentication process in base of domain name. it would an improvement about what there is already available. Example: users@gabriele.com will be authenticated by radius on server1; if authentication fail, users@gabriele.com will be authenticated by Active directory on server2. ecc.

                                  Very efficient in big environment.

                                  47 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    2 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Add GB English as a Language Option

                                    Can we have an English GB setting in this version please, so that the dates in the reports are shown the correct way round and words are spelled correctly like Organisational.

                                    (I know there are more yanks out there than us brits, but we did invent the english language)

                                    6 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Stricter Control over Relaying Allowances

                                      Currently Email Relay checks for allowed users and Host based, in both cases the user name or IP address can be spoofed or hijacked by a spambot, it would be great to have more granular checks such as that the user allowed to relay should send with the same account and as well limit maximum number of emails per sender.

                                      4 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Scan Dropbox files

                                        Implement a Dropbox (https://www.dropbox.com/ and similar) filtering and scanning functionality for those that use this type of exchanging files.

                                        9 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Mail Security: Increase Database Retention for SMTP to 1 Year

                                          Current SMTP database log only allows 30 days retention. Many organizations will have a one-year retention policy.

                                          7 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base