UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
1 vote
-
puremessage for UNIX log events are logged with a resolution of down-to-the-one-second mark
MTA (postfix) is configured for high-resolution timestamps,
and the order of events is important.
Because puremessage rounds up/down to the nearest second, when we look at our aggregated logs,
the order of events that should be:
incoming mail to MTA
blocklist check
mail passed to puremessage
puremessage passes (non-spam) mail back out to MTA
MTA forwards mail on to next hop
Actually appears as this sequence of events:
incoming mail to MTA
blocklist check
puremessage passes (non-spam) mail back out to MTA
MTA forwards mail on to next hop
mail passed to puremessage1 vote -
web security, application control schedule, much needed. I think it needs to be done immediately.
web security, application control schedule, much needed. I think it needs to be done immediately.
16 votes -
Synchronise UTM DNS with external DNS system, such as Amazon Route 53
Support the ability to "import" and "synchronise" entries from a public facing DNS, such as Amazon Route 53 into the Sophos UTM so that devices internal to the network doesn't have to reference the public facing DNS to resolve email, HTTP or HTTPS servers that are hosted internally. For example, if I give you my Amazon credentials, Sophos can "scan" all the entries for all domains, find those that reference the IP addresses of the Sophos device and create entries for them. If we add another entry later on to Amazon Route 53 to deal with another web server, Sophos…
1 vote -
email appliance - quarantine feature
In the quarantined messages summary email that is sent to users, provide a configuration option to turn off the inclusion of the mailto: link alongside each quarantined message listed. The reason for this is that customers don’t have an email client configured on student computers and clicking the mailto link brings up the Outlook configuration wizard which we don’t want. We would prefer that the summary email simply informs the user and provides them with a link to the portal where they can decide if they want to release the message/s.
1 vote -
global webadmin preferences
when working with sum/acc SSO its not possible to change the user preferences (tab is missing). its also missing when logging in as AD user which is not explicitly added to "Allowed Administrators" (e.g. when using AD-Groups).
i would like to set this preferences (items per page, browser title, ...) globally.
14 votes -
Wireless Protection: Granular Customization of Vouchers
To be able to pass on more information to the voucher's recipient it would be very helpful to be able to edit the layout of the voucher or at least have two separate (HTML) text fields for the Hotspot's homepage and the voucher itself.
At this build (9.003-15) you can only have one text which can be HTML and displays correctly at the Hotspot's homepage, but without any layout (plain-text like without formatting) when "printing" the Voucher's (PDF). In most situations where the connection procedure to WiFi (eg. company or hotel WLAN) is not seamless - when SSID and encryption…52 votes -
Auto pop log messages when doing updates etc.
When you choose to install an update the system just does it there is no feedback to say are you sure, especially when the system is likely to reboot after an update, for enterprise class use with the UTM 120+ then this could be a critical piece of equipment, my other request (main request) would be to have information about what is happening when tasks take longer than a few seconds (like updates), popup the up2date love log window to show the progress and actually tell the user when its done or have some sort of progress bar, a box…
1 vote -
Add "Wetransfer" to Application Control > File Transfer
I see many services under "application control" > "file transfer", 110 actually, but besides services like YouSendIt I miss Wetransfer.
Can you please add it?
1 vote -
Ability to change the admin port for the WSA GUI. Alternatively to be able to restrict the source IP’s that have access to it.
Customer's email:
Further to the feature request below to change the Admin Console port, is there any way that I can restrict the IP addresses that can connect to the Admin portal? This would give me the security required.I do not see anything in the Web Interface that would allow me to restrict who is able to request the admin portal, but is there anything you can do 'under the hood' that would restrict which IP addresses can connect?
I simply cannot allow public machines to be able to request the Admin Console
2 votes -
clean up time out error in SEC
SEC has an ability to check if the virus still presents in endpoint machines before attempting to clean up the virus from the console.
This feature will prevent clean up time out error in SEC.
1 vote -
AstaroOS: vmxnet3 network module support
These appliances currently use the "flexible" vmware network driver. This creates much greater latency than the vmxnet3 driver from VMware. Substituting these drivers is possible with your Sophos UTM product and it has greatly increased performance.
4 votes -
Whitelist for encrypted attachments
I'm using the UTM9 soft appliance as an SMTP proxy, but I'm having trouble configuring this w/ regards to incoming Emails with encrypted attachments (like password-protected zip-files). Basically, what I want to do is:
-default action for encrypted attachments should be quarantine
-define a whitelist for sender addresses allowed to send plain text Emails with encrypted attachmentsProblem is, even though I defined a whitelist and skipped the "Email Encryption" check for it, emails w/ encrypted attachments coming from the senders I whitelisted are still getting quarantined. The only way I found so far to get those Emails through is…
1 vote -
Add Managed Computers to a "Computer Group" via context menu.
I'm missing the the conext menu for all listed computers on "Managed Computers" to group the into "Computer Groups". Would saving lot's of time.
3 votes -
Mail manager: alert when incoming mails are blocked in the spool
When spooled incoming mails have not been sent to the mail server after a certain number of attempts, alert the administrator (by email) so he can download them if needed (for example with the current bug where the firewall do not send the end of certain emails to the mail server). Otherwise, there is no way to be alerted of such a pb.
3 votes -
Enterprise console to show scanning status on endpoint computers
Customer wants enterprise console to show that the scanning is happening on the endpoint machine.
For example if a customer forces a scan on the endpoint he wants to know if it is successfully running the scan, if its failing to run the scan
2 votes -
IPS: Protect against rdp attack
Need to protect against RDP attacks trying to exploit Terminal Servers. Should be able to recognize repeated attempts to login to an RDP session and failing. I see constant attacks from all over the eastern hemisphere and I have customers that actually have people that need to login from some countries there so GeoBlocking doesn't help...
7 votes -
Create a new feature for automatic DynDNS updates after failover
We have our Astaro 425 configured to fail over to a secondary internet circuit (CenturyLink) when the primary one (Time Warner) fails. Since we have over 25 different external host IP addresses that would need new IP address assignments when failed over to the new circuit we created a CURL script to update all of our DynNet DNS records. Since the CURL utility is already included in the Astaro Linux OS a simple command could be issued as follows: "curl -k -K /home/login/cl_curl_input.txt" to change our DNS records over to our CenturyLink internet public IP addresses after the CenturyLink interface…
1 vote -
Allow Red to operate in "gateway only" mode on the remote network.
RED would be connected to the remote network using only a single LAN connection. RED would DHCP an address on the network and use the single interface as a gateway for traffic to the UTM as well as to establish the tunnel between the RED and UTM. Allows a drop in RED device at remote location with no reconfiguration of the network required.
3 votes -
install the Sophos firewall without re-deploying Sophos endpoint security software
install the Sophos firewall without re-deploying Sophos endpoint security software as Sophos Patch agent
1 vote
- Don't see your idea?