Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. We currently have an FTP site that our cusomers connect to send files

    We currently have an FTP site on our network that our cusomers upload files for our review. We would like the files to be scanned for viruses.

    4 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
    • add U2F authentication to UTM and SUM

      The protocols and hardware already exist. See https://fidoalliance.org

      1 vote
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
      • Ability to Export Private keys in 9.201 and above

        Prior to the release of 9.201 you were able to download both the public and private key of internal users under mail encryption. As of 9.201 you can't, the option was removed. I have had 2 examples to date that I would need the ability to download the private key.

        1. Need it for use in a 3rd part software. A client that used encryption used PGP desktop and encrypted the email and attachments that were then attached to an email and sent off. The firewall can not decrypt this type of email and therefore it came through undecrypted. We…

        37 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          1 comment  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
        • Allow Admins to schedule the pattern updates

          Schedule Pattern Updates to run at a specific time, e.g. during a service window weekly at 3:00AM

          4 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Operating System  ·  Flag idea as inappropriate…  ·  Admin →
          • add smtp on port 587 by default to the e-mail messaging group

            I have to add this port to a lot of networks although it is a standard SMTP port... It would be handy should it be in the default e-mail messaging group.

            3 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • Add a spam score for domain age

              A lot of the spam that is getting through our current mail filtering is coming from .US domains that are less than an hour old (definitely less than a day). Since blacklisting works when something is known to be bad, this class of spam is harder to hit as the domains are still wearing diapers.

              Any chance of having a score that checked the domain registration date? If it were weighted high on our system, I would've been spared seeing my last dozen spammy offers for car insurance, russian brides and bogus gift cards from Amazon, JC Penny(their spelling, not…

              3 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                2 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
              • Add optional PIN entry field for two-factor authentication

                There are really two big issues I have with the two factor authentication implementation. The first is that no where in the setup for the user is there any information or instruction as how to use two factor authentication. Every other two factor authentication that I have used has had a separate box for putting in the random code. I only learned about how to properly use two factor authentication after calling support and being informed that I needed to append the randomly generated code to the end of my password to which I say "Really! and you arn't going…

                35 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  5 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
                • Add a Cancel button to the "Reporting Direction" screen.

                  Often times I click on something in a Reporting screen just to see if the breakdown is potentially interesting, but then I want to cancel out and keep browsing. Currently this isn't possible because the Reporting Direction screen requires you to pick another report. Please add a Cancel button to this screen!

                  3 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
                  • Allow users to define a starting screen

                    Please allow users to define a starting screen on WebAdmin, with the ability for an Admin to set it for them. My HR users only use the Reporting screens, and usually just Web Protection. It would be nice if their accounts could be set to take them directly to the Web Protection reports screen when they login.

                    1 vote
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
                    • Show MAC addresses during install

                      During installation of UTM it would be handy to see which device has which MAC address so you can make the correct choise for the internal network;

                      3 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Operating System  ·  Flag idea as inappropriate…  ·  Admin →
                      • Update dyndns hostname with the public IP address used by RED to connect to UTM

                        UTM already shows in the main RED tab the IP addresses used by the RED devices do connect to the UTM. It would be great if this IP address could be used to update a dyndns host name and thus allow monitoring if the internet link of the remote side of the tunnel, when dynamically assigned IP are used on the remote side. Today, on a dropped RED connection, there is no way to know if the problem is with the remote internet link or the tunnel between sites.

                        15 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                        • DHCP on RED

                          I think it would be great if we have an option to move the DHCP server for RED networks from the UTM to the RED device. This would allow normal LAN access (e.g. file and print sharing) at the remote site even with a disconnected or outage on your uplink.

                          69 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            4 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                          • authentication

                            I believe we should be able to specify which authentication server to use for each login method.
                            It should not fallback to any other servers not specified.

                            2 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
                            • WAF Reverse Proxy with authentication: add authenticated username in http header

                              If WAF authentication is selected to be done by the UTM, the username of the authenticated user should be added in the http request header sent to the backend web server. Im addition the groups should be added in another header attribute. That would be a function comparable to IBM Webseal and it's http hread iv-user and iv-groups.

                              For security, this feature should be combined with mutual https authentication, i.e. adding a https client certificated by the UTM to prevent modification of the http request header between UTM and backend.

                              1 vote
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
                              • Allow to disable the tray icon from the UTM console

                                I don't want the end users to touch or interact with the endpoint protection in any way. For this I usually disable the icon and balloons modifying the endpoint configuration file.

                                It would be very convenient to disable this icon from the UTM console, to avoid having to login in the endpoints and modify that file manually.

                                3 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                • SPX Encryption: Every sender should receive the saved password if they all mail one recipient

                                  If multiple senders write mails to one recipient, every sender should receive the generated password per mail, not just the first.

                                  3 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Allow strict RDNS checks in the Anti-Spam module to be bypassed by an exception rule

                                    Allow strict RDNS checks in the Anti-Spam module to be bypassed by an exception rule
                                    See case previously logged with Sophos support [#4752249]

                                    1 vote
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Monitor memory usage for each process

                                      I've seen to much systems with excessive memory usage.
                                      When there is a memory leak, or for example a massive usage of swap,
                                      this often isn't noticed before a customer problem arises.

                                      Create a baseline of memory usage by process.
                                      When a user changes configuration options,
                                      or after an upgrade the process goes behond a treshold,
                                      it should automatically be noticed.

                                      Of course, this could be used also for physical, swap cpu and disk

                                      1 vote
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Operating System  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Information about which link is up and down on SNMP

                                        In the current version, Sophos UTM send notification about uplink up and dow by e-mail and snmp. On e-mail, come specified which link is down, but in snmp traps no. It will be really cool, if in snmp trap information contain the information about which link is down or up.

                                        4 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          1 comment  ·  Notifications  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Built-in UPS for UTM/RED

                                          Some industrial and small form factor PCs are now being offered with an on-board UPS so that no extra hardware is needed. Building this into the smaller UTM appliances and the RED would help to make the devices even easier to deploy and manage.

                                          4 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Appliance Hardware  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base