Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. Allow to disable the tray icon from the UTM console

    I don't want the end users to touch or interact with the endpoint protection in any way. For this I usually disable the icon and balloons modifying the endpoint configuration file.

    It would be very convenient to disable this icon from the UTM console, to avoid having to login in the endpoints and modify that file manually.

    3 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
    • SPX Encryption: Every sender should receive the saved password if they all mail one recipient

      If multiple senders write mails to one recipient, every sender should receive the generated password per mail, not just the first.

      3 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
      • Allow strict RDNS checks in the Anti-Spam module to be bypassed by an exception rule

        Allow strict RDNS checks in the Anti-Spam module to be bypassed by an exception rule
        See case previously logged with Sophos support [#4752249]

        1 vote
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
        • Monitor memory usage for each process

          I've seen to much systems with excessive memory usage.
          When there is a memory leak, or for example a massive usage of swap,
          this often isn't noticed before a customer problem arises.

          Create a baseline of memory usage by process.
          When a user changes configuration options,
          or after an upgrade the process goes behond a treshold,
          it should automatically be noticed.

          Of course, this could be used also for physical, swap cpu and disk

          1 vote
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Operating System  ·  Flag idea as inappropriate…  ·  Admin →
          • Built-in UPS for UTM/RED

            Some industrial and small form factor PCs are now being offered with an on-board UPS so that no extra hardware is needed. Building this into the smaller UTM appliances and the RED would help to make the devices even easier to deploy and manage.

            4 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Appliance Hardware  ·  Flag idea as inappropriate…  ·  Admin →
            • Log of traffic based on outgoing interface

              Create a menu showing the kind and amount of traffic based on incoming/outgoing interface in a scenario with more uplink interfaces

              1 vote
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
              • 3 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                • web application firewall rewrite rules

                  - Change the Rewrite from domain.de/ to domain.de/index.php with site path routing activated.
                  - WAF rewrite rules for files like *.php or *.xml

                  3 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
                  • Set a default language/keyboard setting for user portal remote access via HTMLv5 - having to change from US to UK everytime

                    Can you set a default language/keyboard setting for user portal remote access via HTMLv5 - having to change from US to UK everytime is very annoying and confusing for users

                    1 vote
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                    • Direct Yubikey Support in OTP-Module

                      Hi there,

                      it would be great if the Yubikey (www.yubico.com) could be directly supported in OTP-Module of the Sophos UTM.

                      I know that all TOTP-Token (also the Yubikey) are supported. But you need a helper program to generate the TOTP with Yubikey because it doesn't have an internal clock.

                      It would be easier (for the enduser) if the Yubikey would be directly supported (For example, by authenticating through the Yubicloud like several Radius Servers do)

                      So the user would only need to press the button and the key (that Needs to be validated with the Yubicloud or through…

                      35 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        1 comment  ·  Flag idea as inappropriate…  ·  Admin →
                      • Add optional PIN entry field for two-factor authentication

                        There are really two big issues I have with the two factor authentication implementation. The first is that no where in the setup for the user is there any information or instruction as how to use two factor authentication. Every other two factor authentication that I have used has had a separate box for putting in the random code. I only learned about how to properly use two factor authentication after calling support and being informed that I needed to append the randomly generated code to the end of my password to which I say "Really! and you arn't going…

                        30 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          5 comments  ·  Authentication  ·  Flag idea as inappropriate…  ·  Admin →
                        • Use Splunk for all of your reporting of logs

                          Index any machine data regardless of format or location--logs, clickstream data, configurations, sensor data, traps and alerts, change events, the output of diagnostic commands, data from APIs and message queues, and even multi-line logs from custom applications. With no predefined schema, data can be indexed from virtually any source, format or location. Then it's available for troubleshooting, security incident investigations, network monitoring, compliance reporting, business analytics and other valuables uses. I'm sure a deal could be worked out with them, you get 500mb/day of indexing for free

                          1 vote
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
                          • Add IPv4 and IPv6 selection to DynDNS

                            When adding a dyndns provider, there is no way to specify the IPV4 or IPV6 address of an interface. This is a legacy carry over as one interface traditionally could only have one DHCP IP address, but this is no longer true.

                            Having a choice would allow us to create two different dyndns entries to update A and AAAA records.

                            3 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
                            • In MDM to block users from deleting apps

                              Today the restriction on avoiding users from deleting apps can't be controlled from Sophos MDM (today this requires Apple Configurator that can only run on Apple computers).
                              Without this restriction users can actually delete the Sophos Control app as well as any other app on the device.

                              1 vote
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
                              • RED 10 Support for Vodafone Surfstick K5150 LTE

                                current version of LTE Surfstick version - not listest as supported LTE/UMTS device

                                9 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                                • DHCP on RED

                                  I think it would be great if we have an option to move the DHCP server for RED networks from the UTM to the RED device. This would allow normal LAN access (e.g. file and print sharing) at the remote site even with a disconnected or outage on your uplink.

                                  59 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    2 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Unencrypted Hotspot Auth

                                    When using authentication over the WLAN Hotspot option the added Username and Password for the logon are not send encrypted.
                                    Other users in the WLAN can simple read out all passwords with Wireshark.

                                    0 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Websites Lists - Filter Actions

                                      Currently the Websites lists in a Filter Action is only available in one Filter Action. When you remove the Websites List it cannot be created with the same name across any of the filter actions.

                                      Ideally you should be able to totally remove a Websites List as well as assign the exact same Websites List (with all the same Websites and any future changes) to multiple Filter Actions. I would suggest this has significant benefit to large business; more specifically education. Schools want to be able to add a Website list to all students for block/allow but still keep individual…

                                      3 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                      • add an option to enable or disable split tunneling for SSL VPN profiles

                                        SSL VPN profiles is a cool feature which allows to differentiate between e.g. admins and homeoffice users. But there is an option missing in these profiles to enable or disable split tunneling. An Admin who knows what he is doing could be allowed for split tunneling but a homeoffice user instead who would work via ssl vpn and potentially also browse to infested websites could be disallowed for split tunneling. The global way with the "any" setting for the local server address is not enough. Additionally the setting shouldn't be overrideable on client side.

                                        3 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Use SUM as Log Server/Archive

                                          It would be very helpful if I could use a SUM Server as Remote Log File Archive. With this feature I could centralize all Logs of all my UMT's. A addon feature to search in e.g. Webfilter Logs of multiple UTM's at the same time would also be very nice!
                                          And if I do complex searches or log files are very big, the load will move away from productive UTM's.

                                          Thanks in advance,
                                          Pascal

                                          36 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            1 comment  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
                                          1 2 6 8 10 95 96
                                          • Don't see your idea?

                                          Feedback and Knowledge Base