Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. add a wildcard for a folder in the exclusion list of On Access Scanning

    Give the ability to add a wildcard for a folder in the exclusion list of On Access Scanning, the inability to do this is impacting on business critical applications

    1 vote
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Flag idea as inappropriate…  ·  Admin →
    • here should be a possibility to change the length and complexity of the password of the day. e.g. By using Braille device

      here should be a possibility to change the length and complexity of the password of the day.
      e.g. By using Braille device

      1 vote
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
      • DNS Request Routing By Interface

        Hey Everyone,

        My corp has the same dns externally as externally (abc.com internal and abc.com external). We are using the protected wifi with an employee zone that does not have or need access to the internal network. But when those devices are using the utm as their DNS they inherently have access to the internal DNS. With this many services like outlook any where attempts routing to the internal network because it detects the internal DNS. So i would like to ask for DNS Request routing and have an option to select the interface that applies to. So i would…

        5 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          1 comment  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
        • Add Action to Availability Group when Group set to unresolved

          Description:
          - Two sites connected to Internet
          - Site-to-Site (S2S) IPsec tunnel established
          - Private Point-to-Point (P2P) Link (NOT uplink) with better bandwidth introduced on a separate interface
          - Static route defined to use Private Point-to-Point Link to connect to remote site

          Problem:
          Need to shutdown Site-to-Site VPN to force traffic to use static route over Private Point-to-Point Link (not uplink)

          Required:
          Use P2P line as a preferred route between sites when P2P line is active
          Use VPN S2S when P2P down
          Automatic failover from P2P to VPN and back to P2P when line is active

          Available solution:
          Making the…

          6 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            1 comment  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
          • Notify users about ActiveDirectory password expiration on WAF Reverse authentication form

            Users logging on via the reverse authentication form Feature should be able to Change their Password from here - or be notified about an expiring/expired Password.

            6 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
            • SNAT HTTP/HTTPS Proxy Traffic

              SNAT HTTP/HTTPS Proxy Traffic

              I would like to suggest a feature which will enable me route my outbound HTTP/HTTPS traffic with SNAT with content filtering policy enforcement. i.e. without exception.

              4 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                1 comment  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
              • Provide a method to transfer some settings (Ie Mail Protection Settings) from one UTM to another UTM.

                Provide a method to transfer some settings (Ie Mail Protection Settings) from one UTM to another UTM. At this time the only supported method is to Restore the entire configuration from backup. I would like to be able to restore only a portion of the config and retain any existing settings on the target UTM

                3 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                • 1 vote
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                  • Add a recipient verification static whitelist

                    In the Email Protection module, it would help some customers to have the option to use a static recipient verification whitelist.

                    Whilst the ability to integrate with Active Directory or with the SMTP callout is a way of doing very little daily configuration on the appliance, some customers would prefer to take as much unnecessary load away from the underlying mail host. For security reasons, some customers also might not want their mail security appliance integrated with Active Directory.

                    Wikipedia quotes many sources which highlight a vast array of security issues/concerns with using callout verification protecting underlying infrastructure:
                    http://en.wikipedia.org/wiki/Callback_verification

                    3 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                    • Fix the Country Blocking Exceptions to allow the exceptions to work properly

                      When I want to allow only specific hosts or DNS names from a specific country, it should allow that and actually work.

                      So if I block all of Russia, I should be able to explictly allow items for a specific business I interact with therebyt either IP or DNS host name. The system says it allows this now, but it doesn't fully work.

                      I may also only want to allow email traffic (port 25) for one company but not allow other port traffic.

                      This is opened as a support case as well, but support technician said to open a feature…

                      3 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                      • Create a search tool that checks all logs, so I don't have to search each log individually to see what component is blocking something

                        Create a search tool that checks all logs, so I don't have to search each log individually to see what component is blocking something

                        1 vote
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
                        • H.323 Proxy

                          Built-in H.323 gatekeeper (ie GNU Gatekeeper) to simplify voice and videocalls routing.

                          3 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                          • snmp

                            There's no interface comments shown on IF-MIB::ifAlias (empty). Needs the interface comment (description) for my SNMP monitoring software.

                            3 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  SNMP Monitoring  ·  Flag idea as inappropriate…  ·  Admin →
                            • quarantine submit to sophos UTM

                              Submit to Sophos Labs for quarantine messages in mailmanager.

                              3 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                              • ATP Recent Threads Overview in SUM

                                It is possible to manage the Advanced Threat Protection over SUM4.

                                But except of the CRIT-861-notification or checking the UTM, there is no way to see what UTMs had recent events.
                                i think it would make things easier if there was a overview about that threats in either the Configuration>ATP section or in the Monitoring>Threats section.

                                6 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Notifications  ·  Flag idea as inappropriate…  ·  Admin →
                                • Add access controls for RED "Listening" Service

                                  As a Sophos Partner, I'm increasingly getting hammered by clients who have to subject themselves to audits in order to do business. Therefore I am asking that Sophos add access controls to the RED listening service. I am requesting that the RED service on the UTM be configured to use any arbitrary IP address on any of the WAN interfaces, and only allow connections from RED devices from known IPs. Here's why:

                                  I have clients who fail PCI compliance audits because of the self signed IP. I know that the 1 CA trust model is better, but the auditors my…

                                  4 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    1 comment  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Automatic SPX encryption option

                                    Please add an option of SPX encryption execute when there is attached file.

                                    1 vote
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • MailSecurity: certificate download via LDAP/OCSP for S/MIME

                                      it should be possible to automatically download S/MIME certificates from LDAP and encrypt outgoing mails. Also it should be possible to enable OCSP for CRLs.
                                      Thanks.

                                      6 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Notification when switching from Active to Standby interface

                                        When UTM have Standby interface, and Internet on Active WAN interface lost, will be interesting have Email and SNMP notification to Admin and Monitoring tool.

                                        1 vote
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Notifications  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Output Interpreter

                                          I'm missing the "Output interpreter" which you can find on Cisco homepage. Cisco is providing this feature on their homepage. The Output interpreter can interpret the log which you have from the router and much more.

                                          1 vote
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
                                          • Don't see your idea?

                                          Feedback and Knowledge Base