Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. 3 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
    • HTTPS Exceptions should be possible over over User Agent from the HTTP Request

      HTTPS Exceptions should be possible over over User Agent from the Request. For Excample Teamviewer Traffic. In the Log you can see the following User Agent:

      ua="Mozilla/4.0 (compatible; MSIE 6.0; DynGate)

      Exceptions for HTTPS Scan should be possible over these User Agent.

      1 vote
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
      • Please insert a clear button in live logs

        When changing the filter in an open live log, the screen stays full of old, unfiltered entries. A clear button would help a lot.

        7 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          1 comment  ·  Flag idea as inappropriate…  ·  Admin →
        • OSPF routes filtering

          Just simple OSPF routes filtering, lets decide what you want to have in OSPF :)

          1 vote
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
          • Introduce many-to-many NAT

            Because of isps retsricting the number of sessions per ip we NEED many-to-many NAT (like sonicwall, cisco and others have since many years)

            3 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • AP10 compatible for Mesh Networks

              Actually only the AP50 can be setup for mesh networks but most of home users and customers use the AP10 e.g. in smaller offices. It should be possible to make the AP10 available for the mesh network.

              3 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
              • Application Control

                Deskshare is missing

                3 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Application Control  ·  Flag idea as inappropriate…  ·  Admin →
                • Email Protection: Filtering blocked Attachments

                  The Email Protection is forwarding mails with blocked attachments (filetype or mime type) directly to the quarantine and the user gets only max. two quarantine-mails/information about this blocked mails. This could be a problem with the delay in (for example) judgment ares or court of justices. How about filtering out the blocked attachments in a separate quarantine mail and forwarding the rest of the mail, including allowed attachments to the mailserver/user? The user could be informed about a blocked attachment in the quarantine. So we separate the area of blocked antivirus mails with blocked attachments.

                  4 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    1 comment  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                  • SSO authentication apple's open directory in transparent mode and proper documentation

                    SSO authentication apple's open directory. For it to work in transparent mode without the need to use a proxy. Have all of this work with Safari as it does not work at all right now. Have some proper documentation for the macintosh system.

                    3 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
                    • ADD rollout of wireless profiles & settings by SUM

                      actually it is not possible to deploy wireless settings through SUM

                      this should be added!

                      including: Wireless Networks, Accesspoint Groups, HotSpots, Vouchers & Profiles

                      13 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        2 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                      • Networking: Automatic Gratuitous ARP when HA changes

                        When there is changes at HA/Clustering side there should be an option to automatically send Gratuitous ARP to a configurable router (by default can be the default route for a given network).

                        We have a big issue since years about that, as we have a bunch of IPs registered into our active/active cluster (more than 350 IPs) when a change occures at HA side more than half of our IPs are no more accessible for hours if we don't do anything...

                        So when we have an alert about this we need to run this sort of script:

                        for f in…

                        3 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  HA/Clustering  ·  Flag idea as inappropriate…  ·  Admin →
                        • RED: Connection with more than one UTM

                          Would be great to be able to use 1 RED device (RED10, RED50) with more than one UTM at a time to be able to connect to 2 Office/DataCenter with only 1 RED device..

                          2 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                          • SmartHost routing by Sender Domain or Target Domain

                            Normal Email Servers like exchange 2010 and 2013 and sendmail allow configurations where specific "from: domains" and or to: domains can be routed via a specific smart-host while all other traffic flows directly to the target.

                            This flexibility is often used for HIPA compliant encryption or military contractor communications. If the smart host logic is on the email server; then that server cannot use the astaro email security for the targeted domains. In such cases smart host authentication is almost universally used.

                            In order to make server side smarthost targeting work in a UTM protected environment; the targeted smarthost servers…

                            5 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              1 comment  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                            • Change management approval feature (similar to Check Point SmartWorkflow)

                              Implement Change Management approvals inside the firewall UI interface (or SUM). Would help a lot in compliance and managing changes and approving them as a Security Administrator / Security Manager.

                              1 vote
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                              • Support 802.1P QOS Protocol

                                Need the support of 802.1P QOS Protocol for the SDSL EFM (Orange)
                                The SDSL don't work without this protocol.

                                6 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                                • 3 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                                  • allow the UTM Endpoint to apply Web Protection policies according to the logged on user when full Web Control is used for PC's off the LAN

                                    Can the UTM Endpoint fetch and apply Web Protection policies according to the logged on user. At present we still have to use another product to filter web usage when laptops are used outside the network with more than one user.

                                    1 vote
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • User Portal Whitelist and Blacklist directly from the Mail Log

                                      It would be great if the User Portal would allow users to add to the whitelist and blacklist in their profile directly from the Mail Log on a per line item basis. This would eliminate users having to mouse-highlight/copy/paste and would also eliminate having to continually change modes.

                                      1 vote
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Allow RED to access the internet line when the Main UTM line is disconnected

                                        This added mode could mean no disruption to the branch operations in case the UTM is down due to internet issues and cannot be up soon enough. Once the RED detected the UTM is up, it will establish connection and all traffic can be channel to the UTM once again.

                                        62 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          1 comment  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Data path for config

                                          Use data path for config files that follows Windows Design requierements, e.g. C:\ProgramData\sophos or even better user Profile path.
                                          common places show informations for all Computer users.
                                          Next Problem: %programdir% is write protected for users. To config or change a connection administrator right are rewquired wihich a user should never have! Serious security issue.

                                          13 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            1 comment  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
                                          1 2 6 8 10 81 82
                                          • Don't see your idea?

                                          Feedback and Knowledge Base