Though forums can get pickly, I welcome any discussion. I would rather steer this conversation towards a solution that makes you (and anyone else who reads) happy rather than have this disentigrate into a flame war.
Raw logging is realtime, there is a cron job that runs every few minutes and takes the raw log and converts them to another format for reporting and dashboard. Depending on what data you are trying to find it might be easier for Support to look at the reports rather than the raw logs. Note that if you are using Endpoint or a cluster then logging may indeed not be realtime as they need to sychronize.
It may be that for your problem, when talking to your support person, report logging was better to look at than raw logs. I know for me, raw realtimes logs have been possible. Regardless, this would only be an issue for support. Do you find that this impacts your normal operation?
Your experience with Support is not the same as mine. Do you know if you are using actual Sophos support (eg talking to a Sophos employee) or are you going through a partner or reseller?
I thought you were asking to turn off all filtering and antivirus everywhere. To turn it off for a particular site, create a Local Site List entry, tag it will Globally Allow, and set it to Trusted. Trusted sites do not get virus scanned, do not have file type blocking, and the download appears to start immediately. You effectively now allow ALL traffic through the filter for that site.
The SWA should by default scan everything except for what you tell it not to. It cannot predict which sites you will have trouble with 3rd party devices - you need to tell it which sites to turn off scanning for. Default scan, except when told ahead of time not to. This would be (IMO) sound practice.
Tom_Newton - how does Smoothwall do this? Can you turn off all scanning for a site? For a client (eg a specific computer)? Across the board?
You say that you hate the "awful" download page so you turn it off. Then you say the appliance is downloading it without telling the user what it is doing. It kinda feels like you are asking for it both ways.
The SWA must download the file and scan it before giving it to the client computer. You cannot properly scan a file until you have all of it. I don't really know any of the competitors products, but is there anyone else who does antivirus scanning on the gateway and also starts the download to the client immediately? Tom can you answer for Smoothwall - do you have "immediate" downloads?
One thing - if you are using Sophos Endpoints then all filtering and AV is done on the windows computer itself, and downloads will appear to start immediately.
If there is someone out there with a self signed cert, can't you add it on the "Certificate Validation". AFAIK this would the allow the cert even though it is improperly signed. I admit this is not my area of expertise or maybe I don't understand what you need.
I admit that I mistyped MB as GB. Give me a break - do you think I don't actually know the difference? If you fix my typo then the reply stands - 120GB is small. It sounds like you've bumped it up and your problems have been resolved.
Maybe I don't understand what you are asking for. In help under "Block Page Template"
%%user_name%%: This page element key provides the name of the user who has made the request for the blocked page, as provided by Active Directory. If Active Directory is not available, the IP address from which the request was made will be displayed instead.
%%user_ip%%: This page element key provides the IP address from which the request for the blocked page has been made.
%%sophos_block_text%%: This page element key provides the reason that a requested page has been blocked.
Are those not the variables you were asking for? They've been there for 2+ years. If those are not what you are asking for - can you explain? As I started off by saying I would rather genuinely help you rather than argue with you.
This is a debate throughout the security community and we'll have to agree to disagree on this one.
1) You can disable the appliance from scanning downloaded files from domains that you specify. I agree that you cannot disable A/V based on the source (eg don't do scanning for this laptop) or disable A/V across the board. For example it is common to set your own internal servers as Trusted. Theoretically you could set the entire .com TLD as trusted to turn of A/V and all protection - although at the point you are just getting a proxy without any security.
2) If you want, I'm willing to try to help you on this.
3) I can't comment on this. If true, then I agree it sucks although I don't know if anyone else is better. Again, are you talking to Sophos itself or a partner/reseller?