Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  1. Intrusion Prevention - Modified Rules SID not ID

    Intrusion Prevention -> Modified Rules -> Advanced
    When adding your own "Modify Rule" It asks for the Rule ID,
    when it is really the rule SID you need to use.
    A Minor change to the wording, but I've been caught out by this several times over the years.

    1 vote
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
    • I like to have the option of been able to change the email notification display name which is hard coded. I manage few firewalls and is conf

      It would be good to be able to change the notification display name which is hard coded now. I manage few firewalls and all notifications come with the same display name "Firewall Notification System" so to identify where it is coming from I have to open the notification and check for the full email address.

      1 vote
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Flag idea as inappropriate…  ·  Admin →
      • Have the utm send WOL packets.

        In the network services area of the utm it would be nice to have a an option to program a list mac addresses of server / pcs that you would want to wake from power off state.
        Also in the dhcp server option for the dhcp server to log PCs to this database also.

        3 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
        • Server Load Balancing: Enable/Disable/Weight Real Servers via an API/Special HTTP Response Code for automatic Deployments

          We often deploy new Configurations and Software to our real servers behind about 15 SLBs. By now we always have to login to WebUI to manually rebalance the Real Servers we wan to maintain, and rebalance them back for the second half of a SLBs Real Servers.
          It would be nice to have an SSL+Login API to do it automatically using something like Capistrano or even a predefined per-SLB HTTP Response Code, the SLB knows to rebalance to 0 for specific Servers.

          18 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            1 comment  ·  Networking  ·  Flag idea as inappropriate…  ·  Admin →
          • PPoE option in RED

            Please put ASAP the PPoE option in the RED 50, DHCP/StaticIP is not enough, in my country PPoE is used by the principal broadband operator and once this option is not present and once the ADSL modem is not routed, I need keep another router between the red and adsl modem to provisionin IP to RED.

            1 vote
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
            • Improved Email Encryption

              Improve Email Encryption possibilities similar to Zertificon Z1 (refers to most ideas also)

              3 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
              • Reset a device to factory settings using a paper clip

                When a Sophos UTM device is rendered inoperable due to a software or configuration problem, provide a means to reset the device to factory settings by using a paperclip to press a reset button. Like a Airport express device or many other electronic devices, it should not be possible to press the reset button accidentally.

                When the reset button is depressed, beep several times, format the internal hard disk, install the software from an internal flash drive, or hidden recovery partition and when done, beep several times to notify the user its done.

                When the system is restored, permit the…

                3 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Appliance Hardware  ·  Flag idea as inappropriate…  ·  Admin →
                • Autoadjust IPS rules based on Network Protection rules

                  Automatically select only the applicable IPS rules and performance settings based on the network protection rules, e.g. only select HTTP Rules and HTTP performance settings if by filter only HTTP is allowed

                  1 vote
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                  • Auto enrollment on captif portail for wireless protection

                    to provide a web access for customers inside hotel or public domain with only name, surname and email adress for example.

                    4 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                    • Button to flush conntrack table

                      Button to flush the conntrack table on need

                      1 vote
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
                      • Enable repeating for AP30

                        It would be great if the AP30 also had the repeating option. The AP50 is too expensive for normal clients.

                        5 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                        • SSL VPN virtual IP via DHCP server

                          The Remote Client should get a virtual pool IP from the local DHCP Server when he is connecting via SSL VPN, instead of the UTM vitual pool IP.

                          1 vote
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
                          • Temporarily disable On-Access-Scans

                            It would be great to have the ability to disable the On-Access-Scans for a certain amount of time on the client.
                            E.g. via right click on the systray icon:
                            "Disable On-Access-Scans..."
                            "for 1 hour"
                            "until reboot"

                            This should, of course, only be possible for admins, perhaps only after entering the tamper protection password!?

                            7 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  UTM Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
                            • Allow modification of "ModSecurity: Request body (Content-Length) limit"

                              For web sites with larger uploads (e.g. ownCloud) there is currently a 128MB (134217728 byte) limit in Web Server protection, the so called request body limit in ModSecurity.
                              Please add the possibility to configure this parameter (it's "SecRequestBodyLimit" in the Apache config) to allow larger uploads to sites protected by WAF.

                              2 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                1 comment  ·  Web Server Protection  ·  Flag idea as inappropriate…  ·  Admin →
                              • IPS : configure IPS to block the hacker to hack mail id to send mail with that account

                                I am using my UTM625 as my mail gateway and I allowed some of emails to relay messages to the gateway.One of my users email has been hacked and used to sends mass amount of emails within short period of time without my IPS on my UTM stopping it.I suggest you add this feature as it, I think, is basic Spamming/DOS preventing method.

                                1 vote
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                • report on detection specifics based on how the potential threat is detected, i.e. – on-access or scheduled scans

                                  Client is looking to report on detection specifics based on how the potential threat is detected, i.e. – on-access or scheduled scans. It appear much of the pre-reqs should already be in placed as the endpoints report this data in the alerts they email out and the fields appear to exist in the database however they do not correlate properly. The field is specific is the 'ScannerType' in the ThreatEvents table. The 2XX data fields in the database do not accurately reflect anything

                                  3 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
                                  • wildcards

                                    ES5000, no facility to exclude subdomains from policy using wildcards. ie. Be able to exclude gsx addresseses from being encrypted if the policy for SPX encryption is based on subject CONFIDENTIAL, At the moment only domains can be excluded not subdomains.

                                    Vote

                                    1 vote
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • In SMC 3.0 - GUI reporting on device types and activation dates

                                      Company and Contact Information
                                      Company: Gosford City Council
                                      Contact: Elwyn Williams / Matt Roberts
                                      Sophos Partner (if applicable):

                                      Sophos Product Information
                                      Sophos Product: Mobile Control
                                      Version in Production:3

                                      Feature Request Summary
                                      How will this new feature address your business requirements?: Enable us to view takeup of device types on mobile management over time – reporting such as showing current device types, and a report on activation date perhaps
                                      Can you also report on installed applications on all devices? – determine if anyone using an inappropriate application.
                                      How would you rate the importance of this feature?; 1 = Critical, 5 =…

                                      2 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Accommodate RobCopy with SAV use

                                        Company and Contact Information
                                        Company: Ausco Modular Pty Ltd (Parent Company: Algeco Scotsman)
                                        Contact: David Wedrat - +61 7 3864 7862 / +61 434 601 401
                                        Sophos Partner (if applicable): N/A

                                        Sophos Product Information
                                        Sophos Product: Sophos Anti-Virus
                                        Version in Production: 10.2.7

                                        Feature Request Summary
                                        How will this new feature address your business requirements?: Bug Fix
                                        How would you rate the importance of this feature?; 1 – Robocopy is VITAL to our business.

                                        2 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Create a Noninteractive network bootable AV Scanner

                                          Company and Contact Information
                                          Company: ESH Group
                                          Contact: Ashley Hill
                                          Sophos Partner (if applicable):

                                          Sophos Product Information
                                          Sophos Product:SBAV ( or adaption of Sophos Endpoint Protection )
                                          Version in Production:10.2

                                          Feature Request Summary
                                          How will this new feature address your business requirements?:

                                          · A noninteractive network ( or PXE ) bootable AV scanner would give enterprises the ability to regularly perform a company wide scan of the network from a trusted operating system to provide confidence all known threats are detected and removed as modern malware regularly can only be detected and removed from safe mode.

                                          · The ability to…

                                          2 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3 4 5 6 7 8 9 10 11 59 60
                                          • Don't see your idea?

                                          Feedback and Knowledge Base