Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. 1 vote
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
    • puremessage for UNIX log events are logged with a resolution of down-to-the-one-second mark

      MTA (postfix) is configured for high-resolution timestamps,
      and the order of events is important.
      Because puremessage rounds up/down to the nearest second, when we look at our aggregated logs,
      the order of events that should be:
      incoming mail to MTA
      blocklist check
      mail passed to puremessage
      puremessage passes (non-spam) mail back out to MTA
      MTA forwards mail on to next hop
      Actually appears as this sequence of events:
      incoming mail to MTA
      blocklist check
      puremessage passes (non-spam) mail back out to MTA
      MTA forwards mail on to next hop
      mail passed to puremessage

      1 vote
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Flag idea as inappropriate…  ·  Admin →
      • web security, application control schedule, much needed. I think it needs to be done immediately.

        web security, application control schedule, much needed. I think it needs to be done immediately.

        16 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          0 comments  ·  Application Control  ·  Flag idea as inappropriate…  ·  Admin →
        • Synchronise UTM DNS with external DNS system, such as Amazon Route 53

          Support the ability to "import" and "synchronise" entries from a public facing DNS, such as Amazon Route 53 into the Sophos UTM so that devices internal to the network doesn't have to reference the public facing DNS to resolve email, HTTP or HTTPS servers that are hosted internally. For example, if I give you my Amazon credentials, Sophos can "scan" all the entries for all domains, find those that reference the IP addresses of the Sophos device and create entries for them. If we add another entry later on to Amazon Route 53 to deal with another web server, Sophos…

          1 vote
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
          • email appliance - quarantine feature

            In the quarantined messages summary email that is sent to users, provide a configuration option to turn off the inclusion of the mailto: link alongside each quarantined message listed. The reason for this is that customers don’t have an email client configured on student computers and clicking the mailto link brings up the Outlook configuration wizard which we don’t want. We would prefer that the summary email simply informs the user and provides them with a link to the portal where they can decide if they want to release the message/s.

            1 vote
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • global webadmin preferences

              when working with sum/acc SSO its not possible to change the user preferences (tab is missing). its also missing when logging in as AD user which is not explicitly added to "Allowed Administrators" (e.g. when using AD-Groups).

              i would like to set this preferences (items per page, browser title, ...) globally.

              14 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
              • Wireless Protection: Granular Customization of Vouchers

                To be able to pass on more information to the voucher's recipient it would be very helpful to be able to edit the layout of the voucher or at least have two separate (HTML) text fields for the Hotspot's homepage and the voucher itself.
                At this build (9.003-15) you can only have one text which can be HTML and displays correctly at the Hotspot's homepage, but without any layout (plain-text like without formatting) when "printing" the Voucher's (PDF). In most situations where the connection procedure to WiFi (eg. company or hotel WLAN) is not seamless - when SSID and encryption…

                52 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  1 comment  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                • Auto pop log messages when doing updates etc.

                  When you choose to install an update the system just does it there is no feedback to say are you sure, especially when the system is likely to reboot after an update, for enterprise class use with the UTM 120+ then this could be a critical piece of equipment, my other request (main request) would be to have information about what is happening when tasks take longer than a few seconds (like updates), popup the up2date love log window to show the progress and actually tell the user when its done or have some sort of progress bar, a box…

                  1 vote
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
                  • Add "Wetransfer" to Application Control > File Transfer

                    I see many services under "application control" > "file transfer", 110 actually, but besides services like YouSendIt I miss Wetransfer.

                    Can you please add it?

                    1 vote
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Application Control  ·  Flag idea as inappropriate…  ·  Admin →
                    • Ability to change the admin port for the WSA GUI. Alternatively to be able to restrict the source IP’s that have access to it.

                      Customer's email:
                      Further to the feature request below to change the Admin Console port, is there any way that I can restrict the IP addresses that can connect to the Admin portal? This would give me the security required.

                      I do not see anything in the Web Interface that would allow me to restrict who is able to request the admin portal, but is there anything you can do 'under the hood' that would restrict which IP addresses can connect?

                      I simply cannot allow public machines to be able to request the Admin Console

                      2 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                      • clean up time out error in SEC

                        SEC has an ability to check if the virus still presents in endpoint machines before attempting to clean up the virus from the console.

                        This feature will prevent clean up time out error in SEC.

                        1 vote
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                        • AstaroOS: vmxnet3 network module support

                          These appliances currently use the "flexible" vmware network driver. This creates much greater latency than the vmxnet3 driver from VMware. Substituting these drivers is possible with your Sophos UTM product and it has greatly increased performance.

                          4 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  AstaroOS  ·  Flag idea as inappropriate…  ·  Admin →
                          • Whitelist for encrypted attachments

                            I'm using the UTM9 soft appliance as an SMTP proxy, but I'm having trouble configuring this w/ regards to incoming Emails with encrypted attachments (like password-protected zip-files). Basically, what I want to do is:

                            -default action for encrypted attachments should be quarantine
                            -define a whitelist for sender addresses allowed to send plain text Emails with encrypted attachments

                            Problem is, even though I defined a whitelist and skipped the "Email Encryption" check for it, emails w/ encrypted attachments coming from the senders I whitelisted are still getting quarantined. The only way I found so far to get those Emails through is…

                            1 vote
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                            • Add Managed Computers to a "Computer Group" via context menu.

                              I'm missing the the conext menu for all listed computers on "Managed Computers" to group the into "Computer Groups". Would saving lot's of time.

                              3 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
                              • Mail manager: alert when incoming mails are blocked in the spool

                                When spooled incoming mails have not been sent to the mail server after a certain number of attempts, alert the administrator (by email) so he can download them if needed (for example with the current bug where the firewall do not send the end of certain emails to the mail server). Otherwise, there is no way to be alerted of such a pb.

                                3 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                • Enterprise console to show scanning status on endpoint computers

                                  Customer wants enterprise console to show that the scanning is happening on the endpoint machine.

                                  For example if a customer forces a scan on the endpoint he wants to know if it is successfully running the scan, if its failing to run the scan

                                  2 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                                  • IPS: Protect against rdp attack

                                    Need to protect against RDP attacks trying to exploit Terminal Servers. Should be able to recognize repeated attempts to login to an RDP session and failing. I see constant attacks from all over the eastern hemisphere and I have customers that actually have people that need to login from some countries there so GeoBlocking doesn't help...

                                    7 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Create a new feature for automatic DynDNS updates after failover

                                      We have our Astaro 425 configured to fail over to a secondary internet circuit (CenturyLink) when the primary one (Time Warner) fails. Since we have over 25 different external host IP addresses that would need new IP address assignments when failed over to the new circuit we created a CURL script to update all of our DynNet DNS records. Since the CURL utility is already included in the Astaro Linux OS a simple command could be issued as follows: "curl -k -K /home/login/cl_curl_input.txt" to change our DNS records over to our CenturyLink internet public IP addresses after the CenturyLink interface…

                                      1 vote
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  HA/Clustering  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Allow Red to operate in "gateway only" mode on the remote network.

                                        RED would be connected to the remote network using only a single LAN connection. RED would DHCP an address on the network and use the single interface as a gateway for traffic to the UTM as well as to establish the tunnel between the RED and UTM. Allows a drop in RED device at remote location with no reconfiguration of the network required.

                                        3 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                                        • install the Sophos firewall without re-deploying Sophos endpoint security software

                                          install the Sophos firewall without re-deploying Sophos endpoint security software as Sophos Patch agent

                                          1 vote
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base