Just attended the Sophos UTM 9.3 Webinar today and they showed us this RoadMap.
There is hopefully something to look forward to :-)

This thread was automatically locked due to age.
If you look at the UTM 9.35 branch, it does mention "improved stability""9.35, now with duct tape!" lol
any more news on where we're at with any of this ? Looking at the past 2-3 firmware updates, it seems that Sophos clearly has got the message about improving reliability and fixing bugs rather than just adding more features and breaking existing thingsIt's actually worked like this for quite some time. New features are only added for major version increments. Then the next bunch of up2dates are used to fix release bugs along with regression fixes. I'd expect 9.35 to go into beta sometime this summer. The betas can last anywhere from 2-4 months normally.
Looking at the roadmap, I didn't see any of the features on my wishlist ...
providing a mechanism to clear dhcp reservations
providing a mechanism to view active devices and monitor traffic for active devices
improving network protection so it’s easier to investigate blocked packets
improving on SSL and IPSEC
Regarding future improvements, personally I can't wait to see the new Identity Management (Layer 8) and Application Control features (from Cyberoam engine), rather than improving on 198x protocols like DHCP and DNS. Any Windows server since NT 4.0 can do a perfect DHCP/DNS job, so there is no reason for another "hot water invention" (phrase from my language...[:)]).The reason UTM cannot discriminate between ipv6 wired and wifi connections is because it's using the DUID to identify clients, which is not unique between wired and wifi (on windows pcs). Sophos blames this on the implementation of DHCP they are using. If UTM used the MAC address, like it does for ipv4, there would be no problem. Irrespective, it's broken and should be fixed. The limitation of one ipv4 wired and wireless ip address per host is due to UTM. In this era of coexisting ipv4 and ipv6, at the very least, Sophos should not be double counting licenses for people who choose to keep up with the times and use both protocols.
Looking at the Roadmap picture it is obvious that "VPN features" tag is listed for all future planned releases - 9.35, 9.4 and 9.5.
It is not clear now if it would be SSL VPN site-to-site support, but I guess that developers would not spend many hours working on PPTP or L2TP protocols, but improving on SSL and IPSEC.
I'm not looking for site to site, but rather to be able to use external vpn servers for geolocation and privacy. I realize that is not necessarily a "business" requirement, but nonetheless, it's used by a lot of people, it's been high up on the list of requested features for several years and it's supported by a lot of routers, including pfsense. In my opinion, UTM has all of the necessary infrastructure to support this feature.This is much of the reason why it has not been implemented up to this point. All UTM features added, MUST have a business requirement. Without this, no resources will be dedicated to adding a feature. This is policy.
Disabling/enabling the DHCP server in question should accomplish this.The only way to clear the dhcp lease tables is to delete the log files.
What improvement would you make in the Flow Monitor? - in the Firewall Live Log?
I don't have much use for Site-2-Site SSL, but if some large customer wants to have it interoperate with OpenVPN, I'm sure that will be on the list. I hope that the improvements are to IPsec. Sophos had a great year last year, but much business was lost because charon has not yet replaced pluto meaning there's no IKEv2, etc. Plus, I think StrongSWAN may already have stopped any work on V4.
Cheers - Bob