UTM (Formerly ASG) Feature Requests
Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!
-
Network Security: Vulnerability Scanner
Implement a means whereby from the ASG you can scan networks for vulnerabilities.
258 votes -
Network Security: Automatic uPNP Support
Adding NAT rules automatically through UPnP service would be also great for home users and probably some other small companies.
214 votes -
Networking: Data Leak Prevention System (DLP)
A system that will identify, monitor, and protect data through deep content inspection. This will be a must have system to detect and prevent the unauthorized use and transmission of confidential information.
176 votes -
Network Security: Services Support for Country Blocking
the country blocking is a very good idea.
we get a lot of intrusion from china to our terminalserver. the best extension would be if we could limit it to services looks like RDP, VNC151 votes -
Network Security: Create firewall rule(s) directly from Live Log
In order to make fine tuning of our product packet filter configuration easier, we should add a way to create packet filter rules with a small wizard so that if i see any packet that i want to explicitly drop or allow i can start a mini-wizard that helps to create a matching packet filter rule by either selecting existing definition objects or offering an easy way to create new definition objects, which later than get used in the pf rule..
123 votes -
Network Security: Block Malicious/Botnet/Bad IP's using Blacklist "Service"
It would be nice if we could automatically block all traffic to/from IPs identified as malicious by lists such as DSHield or Project Honey Pot.
121 votes -
Network Security: Drag'n'Drop sort of packet filter rules
Improve the GUI to support a drag'n'drop sort of the packetfilter ruleset or also potentially other sortable list elements..
120 votes -
Network Security: Firewall Rule "Hit" Counters
Display the number of packets that match each rule in the table. So you can locate unnecessary packetfilter rules. Should be able to reset the hit counter(s) as needed, along with a tooltip to show the last time(s) of the previous few hits.
104 votes -
IPS: Per-Rule IPS Exceptions
Extended the exceptions functionality to allow for specific rules as part of an exception.
This will allow for much more granular IPS exceptions in being able to specify a rule be disable/excepted only for a certain traffic flow, like for rule 2122 from Internet to Webserver, without disabling the rule globally or by exempting the resource from IPS fully.
75 votes -
IPS: Creation of Custom Rules (Snort)
the possibility to add own snort rules would be great!
Customers can add their special rules for their special needs,
so we could be more flexible and more secure.The AxG can check the own rules via a new snort instance, if everything is fine -> add it to the ruleset.
71 votes -
Network Security: Logical "NOT" Support for Packet Filter, DNAT, etc...
It would easily save a lot of work if we had the possibility to make a mass-rule with "NOT" operators, like accepting all traffic for all directions EXCEPT for some host or network etc..
Like ACCEPT ANY ANY !Host"A"
54 votes -
Network Protection: Bind VoIP Proxy to Interface
It would be useful if the VoIP proxy was able to be assigned to a particular interface. If I have an internal VoIP server, it may not be on the same address as my default gateway, so it would be useful to assign another gateway interface instead of using policy based routing.
45 votes -
Definitions: Create objects based on "AS whois" record
It would be nice to have the ability to define network definitions by whois AS number.
eg. you could make a definition for all the Telenet public subnets by adding a Definition Telenet-subnet with a parameter AS 6848.
The AS number database is rebuilt on a daily basis, and could be synced just like the spam, antivirus and content filter databases are synced or updated.43 votes -
Network Protection: Fallback to previous IPS pattern version
Engine fallback to previous file in case of a determined engine error or bad update.
41 votes -
Network Security: Support for ARP Handler Inspection (arpon)
arpon should be added to UTM. You would need to add the ability to process the arpon.log file intelligently and escalate to the administrator accordingly.
arpon would be useful in situations where users add unauthorized equipment to the network, or ARP poisoning/spoofing is taking place.
35 votes -
Network Protection: Create firewall rules to automatically "blacklist" an "attacker."
I'd like to turn on 'reactive rules' to start dropping all traffic from source IPs that trip a threshold of IPS or PF rules.
Say someone is scanning your website for IIS vulnerabilities and trips 20 IPS rules in 1 minute (administrator defined parameters), then the UTM would create a rule at the top to block all traffic to and from the attacking source IP.
Bonus points for letting the rule dissolve after N hours as well as being able to turn this rule on for specific interfaces or subnets, You could link it to the geo-location system so that…
32 votes -
Network Protection: Bi-directional firewall rules
Create bidirectional firewall rules. For example 2 Servers need to contact each other on the same ports. Now you have to create 2 Firewall rules.
30 votes -
Networking: Masquerading (NAT) Balancing Across All Public IP's
Use all available public addresses on the WAN interface, even though the HTTP proxy is turned on. The reason for this feature is to keep users working, even if the primary WAN IP address is offline.
29 votes -
Networking: Forward Ping for Devices behind UTM
In V8 it was possible to Ping Devices behind the UTM Device, in V9 it is Disabled and could not be Enabled with a Packet filter Rule.
This function is useful for us and our Customer which has Devices behind the UTM in his own DMZ that should be monitored by Monitoring Systems etc.
24 votesWhile already possible by disabling the built-in ICMP handlers and creating your own packet filter rules for explicitly allowing such traffic, we will review the operation of this behavior and if we can refine the GUI here.
-
Networking: Block/Blacklist IP Globally
A method is needed to quickly add an IP address or range to a "Deny Access" list.
Currently you have to create a new network definition for each bad host and then drag and drop it on a group that is used to deny access. The number of entries in the network definition page can therefore get very large.
There are several possible ways of implementing this:
1. Have a "Deny Access" tab under Network Security that contains a group definition for denied hosts or IP ranges to which you can quickly add entries.
2. Add a new type of…
24 votes
- Don't see your idea?