Do you recognize a good idea when you see one? We want to hear from you!
Header Image

UTM (Formerly ASG) Feature Requests

Do you have an idea for Sophos UTM? Do you recognize a good idea when you see one? We want to hear from you!

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. notification for SSL VPN connection

    UTM should send notification when someone is connecting on remote access SSL VPN

    1 vote
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  VPN  ·  Flag idea as inappropriate…  ·  Admin →
    • RED PCI Compliance Changes

      PCI Compliance will always fail on current UTMs using RED. This is due to being unable to disable SSL v3 on this as well as being unable to change the certificates used (currently weak, not using at least 2048 bit keys). Please fix!

      33 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        2 comments  ·  Remote Ethernet Device (RED)  ·  Flag idea as inappropriate…  ·  Admin →
      • Network Protection: Firewall pop-up informaton when hovering mouse

        Hi!

        When I go to Network Protection - Firewall and hover over an object I get a pop-up showing the name of the object _which is also written in the rule base_. Since the name is the thing I am hovering over I have no use of that information but what I really need is the IP address.

        As it is now I have to move frequently between Network definitions and Firewall rules / NAT or I have to open up every rule and hover over the object in the rule definition.

        Since this is time consuming and error prone…

        1 vote
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
        • Web Security: automatic upload of uncategorized websites zu the SOPHOS labs

          It would we very usefull, if the "uncategoried" Websites would automatically uploaded to SOPHOS labs or the used McAfee labs for recategorization.

          2 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
          • 1 vote
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Network Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • to display the corresponding web filter exception name in the http.log

              It would be useful if you could see the name of the correspondig web filter exeption in the http.log on the UTM.

              2 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Logging  ·  Flag idea as inappropriate…  ·  Admin →
              • Web Filter: Bypass user can only bypass certain categories

                Is it possible to define the categories that can or cannot be bypassed rather than all or nothing. This would be useful for schools/colleges who would like to enable students to bypass particular categories with a staff provided code.

                3 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                • CelleBrite

                  This is used for moving cellphone data from one phone to another. It needs to be added to the montored list to ensure we can use this without problem. Currently the androidlib.dll is removed by Sophos so we are not able to use the product

                  1 vote
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Application Control  ·  Flag idea as inappropriate…  ·  Admin →
                  • usability improvement : IDE update date in console

                    Please can you add a line in the product informations view about the last update of IDE files ?

                    7 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      0 comments  ·  Usability/GUI  ·  Flag idea as inappropriate…  ·  Admin →
                    • usability improvement : improve labels

                      Improve information labels in the local console : "virus data date" is not concerning virus identities but update date of the detection engine.
                      Translations are also concerned by that. May be the network console too.

                      7 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                      • Update the Web Filter to stop using SHA-1 as it breaks functionality for Chrome (which has depreciated it earlier this month)

                        Google has depreciated the use and consideration of SHA-1 encryption.
                        On Chrome, any site using SHA-1 encryption for HTTPS is considered unsecure.
                        This not only breaks functionality on most websites when the decrypt and scan option is enabled, it gives the appears of unsecure web browsing.

                        The Web Filter needs to be updated to use something better than just SHA-1 (like SHA-256) instead.

                        And this needs to be done IMMEDIATELy.

                        5 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                        • UTM live log to show a logged in user activity in human readable format

                          With the raw log it's difficult to follow a single logged in user activity, could there be a live log in human readable format to follow a single user web surfing activity in real time?

                          1 vote
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Web Protection  ·  Flag idea as inappropriate…  ·  Admin →
                          • Forcibly stop processes and services that are locking files and thus causing SAV to require reboots

                            Customer has requested that processes that are locking Sophos files should be forcibly stopped to remove the need for a reboot...

                            2 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                            • Enhance VPN Reporting to show services contributing to usage per user

                              The UTM weekly executive report breaks down VPN usage by user. After confirming with Sophos support, it appears there is no way to shed light on what those VPN users are doing.

                              I need a report that tells me what services VPN users are using while connected to the VPN.

                              1 vote
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Reporting  ·  Flag idea as inappropriate…  ·  Admin →
                              • add a wildcard for a folder in the exclusion list of On Access Scanning

                                Give the ability to add a wildcard for a folder in the exclusion list of On Access Scanning, the inability to do this is impacting on business critical applications

                                1 vote
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                • here should be a possibility to change the length and complexity of the password of the day. e.g. By using Braille device

                                  here should be a possibility to change the length and complexity of the password of the day.
                                  e.g. By using Braille device

                                  1 vote
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Wireless Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                  • SMTP Proxy MIME delivery status notifications

                                    Currently, the Sophos UTM OS does not support RFC 3462 MIME-type delivery status notifications. This causes issues for when Outlook clients recieve non-RFC bouncebacks from the UTM as they will not treat it as a delivery status notification, but reather as a new email and apply any inbox rules. This can lead to bounceback storms.

                                    Additionally, in an Exchange environment, bouncebacks are intercepted and reformatted for easier user readibility.

                                    3 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Provide a method to transfer some settings (Ie Mail Protection Settings) from one UTM to another UTM.

                                      Provide a method to transfer some settings (Ie Mail Protection Settings) from one UTM to another UTM. At this time the only supported method is to Restore the entire configuration from backup. I would like to be able to restore only a portion of the config and retain any existing settings on the target UTM

                                      3 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                      • 1 vote
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Management  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Add a recipient verification static whitelist

                                          In the Email Protection module, it would help some customers to have the option to use a static recipient verification whitelist.

                                          Whilst the ability to integrate with Active Directory or with the SMTP callout is a way of doing very little daily configuration on the appliance, some customers would prefer to take as much unnecessary load away from the underlying mail host. For security reasons, some customers also might not want their mail security appliance integrated with Active Directory.

                                          Wikipedia quotes many sources which highlight a vast array of security issues/concerns with using callout verification protecting underlying infrastructure:
                                          http://en.wikipedia.org/wiki/Callback_verification

                                          3 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Mail Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3 4 5 105 106
                                          • Don't see your idea?

                                          Feedback and Knowledge Base