UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
Networking: Bandwidth / Traffic Quota
Add the ability for administrators to specify bandwidth limits for users and IP addresses in regards to how much they can consume during a certain time period, certain hard limit, or on a certain service/proxy.. Gives the option to control bandwidth usage on the AxG so that admins can better manage their internet connection and control overusage and heavy users, especially during certain times.
814 votes -
Networking: Full DNS Server
It would be nice if Astaro could be used as a fully-functional DNS server with backward look up zones and all.
At the moment SOHO networks with no internal DNS server are unable to perform reverse DNS and other features.473 votes -
Networking: Add IGMP proxy
Implement a simpe IGMP proxy so that IPTV at least from T-Home Entertain can be received. This is different from standard Multicast as it only to pass the asg and not dynamically communicate or register with other multicast servers
443 votes -
Networking: Add TShark (WireShark) for Packet Dumps in WebAdmin
While TCPDump is useful, TShark is much more so, especially with Layer 7 filtering being added.
Add the ability to capture and save a packet dump on a selected interface via the support section of ASG's WebAdmin
358 votes -
Networking: Granular QoS
Provide a means of applying QoS to users and sessions, so that granular controls can be applied as needed to better control traffic and bandwidth.. Fine-tunes the offering of QoS to allow for more specific environments and configurations.
302 votes -
Networking: QoS For VPN Traffic
Allow for Quality of Service rules to be created that apply to VPN traffic of roadwarrior and site-site.. Allows for better management of traffic limits and gives admins the ability to guarantee and control bandwidth across VPN's. Perhaps part of a V8 Revamp of QoS?
297 votes -
Networking: Local Radius Server on ASG
Cause small offices (planning offices, Laywers, etc.) are not using a windows server AD but like to use WLAN (cause there´s no cabeling needed) a local radius server would be helpful (i.e. available on Linksys Routers with TinyPEAP or via DD-WRT) to authentificate the users with a central security. So a local user database is still on the ASG. Why not implement an optional radius server instead of pointing to a local one on a windows server?
219 votes -
Multipath: Allow WAN1 to burst to WAN2
Astaro must have the ability to allow traffic to burst over to a second WAN link when the primary WAN link is saturated or reaches a defined maximum of traffic amount in a day/week/month. We currently have options to failover traffic depending on source, destination, and interface. What we need is another category for bandwidth utilization.
193 votes -
Networking: Integrated Wake on LAN Service
Add the wake on lan functionality. Provide the possibility to create a table (INTERFACE | MAC ADDRESS | DESCRIPTION ) where we can store the mac address of hosts to wake up. Also, the wake up command can be scheduled or manually executed.
150 votes -
Networking: Multiple bridge support
Many SMBs have outposts that do not have the perfect infrastructure to install servers there.
So for several reasons (Security and Maintenance) we would like to install their dedicated servers in the HQ but appearing still as LAN devices.Pretending bandwith is not an issue we would like to use RED to connect the outpost clients to the servers in the HQ.
To keep the network simple we need the possibility to configurer more than one bridge interface in ASG
The servers appear to be in the clients local network, but are protected and seperated behind Astaro Gateway.Example:
RED-Interface.1…133 votes -
Networking: DHCP Relay over VPN tunnel
Customers uses more and more central DHCP servers therefore we need to extend the DHCP-Relay option to also support forwarding the relay requests via an established Site-to-Site tunnel. Support a centralzied DHCP configuration scenario
99 votes -
Networking: DHCP & Dynamic DNS Updater
It would be nice to add to the DHCP and DNS the ability to register dynamically on the local DNS zone the name of the machine and IP address that have just be assigned by the DHCP server.
95 votes -
VLAN and LAN on Interface
It is useful to have LAN(default) and VLAN on the same Interface, so you can have one uplink from your switch, at this time you need 2 cables to connect your switch.
80 votes -
Network->Interfaces: Additional VLAN on pppoe / VLAN with DHCP
Create the ability to use a vlan on an interface already defined interface with pppoe. it would also be great if you could configure a vlan interface with dhcp.
i hope you understand what i mean or do you need a more detailed description?
78 votes -
Manually configurable Dynamic DNS Provider
At the moment, Astaro implemented a handful DDNS providers. It would be great if you can manually insert your own provider. For example Strato, they provide also Dynamic DNS
76 votes -
Networking: Enhanced Link Aggregation (LAG) Modes Support
Using the middleware (cc CLI) it is already possible to set link-aggregation to a different mode than the default mode 4 (802.3ad).
We would appreciate to see all other modes becoming an official part of the Web GUI:
- mode 0 (balance-rr)
- mode 1 (active/backup)
- mode 2 (balance-xor)
- mode 3 (balance-broadcast)
- mode 5 (balance-tlb)
- mode 6 (balance-alb)72 votes -
MLPPP / Bonding of DSL Lines
www.netopia.com/equipment/pdf/wp/bonding_uk.pdf
http://www.dslreports.com/forum/r21593201-Announcing-ZeroShellMLPPP-and-LinuxMLPPP-alphas
MLPPP is similar to the already existing WAN Link Balancing but still different.
68 votesThis feature is part of our UTM 9.1 release which is currently in open Beta. You can try it out yourself by visiting www.astaro.org/beta-versions/utm-9-1-public-beta/
-
Networking: IPv6 DHCP Interfaces
One of my ISPs has begun offering IPv6 addresses through DHCP to capable connected systems. This currently doesn't work with UTM as the Cable Modem (DHCP) interface type only supports IPv4 addressing.
It would be nice if a DHCP type interface could be configured which could pull an IPv6 address.
68 votes -
Networking: Tester tool for how a packet will flow through the UTM
Inject a virtual packet into the security appliance and track the flow from ingress to egress. Along the way, the packet is evaluated against flow and route lookups, ACLs, protocol inspection, NAT, and IDS
64 votes -
Networking: Site to Site GRE Tunnel Support
Support for allowing us to ditch our Cisco router by letting us setup site to site GRE Tunnels.
59 votes
- Don't see your idea?