> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Benchmark

OneFirewall is a real-time threat intelligence layer that sits in front of your existing firewall — Palo Alto, Check Point, Juniper, or others — and pushes live, crowd-sourced attack data into its enforcement engine. This page compares threat intelligence capabilities across these vendors and what layering OneFirewall on top adds.

***

## The fundamental difference

Firewall vendors build their own enforcement engines, and their threat intelligence is limited to what their own customer telemetry and research labs observe. OneFirewall works differently: it draws on collective intelligence from 210+ global security centres, validates it in real time, and pushes it to your existing infrastructure.

|                             | OneFirewall                            | Palo Alto Networks                | Check Point                       | Juniper Networks                       |
| --------------------------- | -------------------------------------- | --------------------------------- | --------------------------------- | -------------------------------------- |
| **Primary function**        | Dedicated threat intelligence platform | Firewall + bundled TI             | Firewall + bundled TI             | Firewall + bundled TI                  |
| **TI product**              | World Crime Feeds (WCF)                | WildFire / AutoFocus              | ThreatCloud AI                    | SecIntel / ATP Cloud                   |
| **Intelligence model**      | Crowd-sourced Alliance (210+ members)  | Vendor telemetry (85K+ customers) | Vendor telemetry (150K+ networks) | Vendor telemetry (Juniper Threat Labs) |
| **CTA membership**          | Full member                            | Full member                       | Full member                       | Not a member                           |
| **Works with any firewall** | Yes, vendor-agnostic                   | No, Palo Alto only                | No, Check Point only              | No, Juniper only                       |
| **Deployment model**        | On-prem, cloud, hybrid                 | Cloud (SaaS)                      | Cloud (SaaS)                      | Cloud (SaaS)                           |

***

## Benchmark metrics

### Intelligence sourcing and coverage

| Metric                        | OneFirewall                                                          | Palo Alto                                      | Check Point                                            | Juniper                                             |
| ----------------------------- | -------------------------------------------------------------------- | ---------------------------------------------- | ------------------------------------------------------ | --------------------------------------------------- |
| **Intelligence sources**      | 210+ Alliance members + CTA + government agencies + security vendors | WildFire subscriber network + Unit 42 research | 150K connected networks + CP Research + external feeds | Juniper Threat Labs + ATP Cloud + third-party feeds |
| **IoC types covered**         | IPs, domains, URLs, file hashes                                      | Files, IPs, URLs, DNS                          | IPs, domains, URLs, files                              | IPs, domains, C\&C, GeoIP                           |
| **STIX 2.1 native**           | Yes                                                                  | Partial                                        | Partial                                                | No                                                  |
| **MITRE ATT\&CK mapping**     | Per-indicator                                                        | Via Cortex XSOAR                               | Via ThreatCloud Graph                                  | Limited                                             |
| **Crime score / risk rating** | 0–1000 granular score                                                | Binary (malicious/benign)                      | Confidence levels                                      | Binary (block/allow)                                |

### Enforcement speed

| Metric                      | OneFirewall                                                                   | Palo Alto                               | Check Point                       | Juniper                                |
| --------------------------- | ----------------------------------------------------------------------------- | --------------------------------------- | --------------------------------- | -------------------------------------- |
| **Time to block (new IoC)** | Under 30 seconds from first report across the Alliance                        | Minutes (WildFire cloud analysis cycle) | Near real-time (ThreatCloud push) | Near real-time (SecIntel feed refresh) |
| **Feed refresh interval**   | Continuous (5-minute EDL cycles for Check Point; real-time for the WCF Agent) | Periodic (WildFire signature updates)   | Continuous (ThreatCloud push)     | Periodic (ATP Cloud sync)              |
| **Automated enforcement**   | Yes, no analyst required                                                      | Yes, within ecosystem                   | Yes, within ecosystem             | Yes, within ecosystem                  |

### Integration

| Capability                      | OneFirewall               | Palo Alto               | Check Point               | Juniper               |
| ------------------------------- | ------------------------- | ----------------------- | ------------------------- | --------------------- |
| **Check Point integration**     | Native (SmartConsole EDL) | No                      | Built-in                  | No                    |
| **Palo Alto integration**       | Native (EDL / MineMeld)   | Built-in                | No                        | No                    |
| **Fortinet integration**        | Native (WCF Agent)        | No                      | No                        | No                    |
| **Juniper integration**         | Native (custom feed)      | No                      | No                        | Built-in              |
| **AWS WAF**                     | Yes                       | No                      | No                        | No                    |
| **GCP Cloud Armor**             | Yes                       | No                      | No                        | No                    |
| **Cisco / Sophos / Forcepoint** | Yes                       | No                      | No                        | No                    |
| **API access**                  | RESTful + STIX 2.1        | AutoFocus API           | ThreatCloud API           | ATP Cloud API         |
| **Total supported platforms**   | 16+                       | 1 (Palo Alto ecosystem) | 1 (Check Point ecosystem) | 1 (Juniper ecosystem) |

***

## What each vendor provides

### Palo Alto Networks (WildFire + AutoFocus)

WildFire analyzes files in a cloud sandbox and pushes signatures to Palo Alto firewalls. AutoFocus provides a searchable repository of threat indicators drawn from WildFire telemetry and Unit 42 research. The intelligence is locked to the Palo Alto ecosystem: it cannot enrich a non-Palo Alto firewall.

### Check Point (ThreatCloud AI)

ThreatCloud AI aggregates telemetry from 150,000+ connected networks and uses over 50 AI-powered engines to process indicators, with a strength in graph-based analysis of relationships between domains, IPs, and URLs. Like WildFire, this intelligence only feeds Check Point products.

### Juniper Networks (SecIntel)

SecIntel delivers curated feeds from Juniper Threat Labs and ATP Cloud to SRX firewalls and MX routers, covering C\&C, GeoIP, attacker IPs, and infected-host indicators. It extends enforcement to routing infrastructure but is limited to Juniper hardware, and Juniper is not a CTA member.

### OneFirewall (World Crime Feeds)

OneFirewall connects 210+ global security centres into one network. When a member detects an attack, the indicator is validated, scored with a Crime Score (0–1000), mapped to MITRE ATT\&CK, and pushed to every connected firewall in under 30 seconds, regardless of vendor.

***

## Running OneFirewall alongside a firewall vendor

OneFirewall runs on top of an existing firewall rather than replacing it.

| Scenario                                                              | Firewall alone                                         | Firewall + OneFirewall                                                      |
| --------------------------------------------------------------------- | ------------------------------------------------------ | --------------------------------------------------------------------------- |
| New ransomware staging IP detected in Brazil                          | Blocked only if your vendor's research lab has seen it | Blocked within 30 seconds across all Alliance members                       |
| Zero-day C\&C domain registered 2 hours ago                           | Depends on vendor's feed update cycle                  | Collective detection triggers an immediate block                            |
| Multi-vendor environment (e.g. Palo Alto perimeter + Fortinet branch) | Each vendor operates in its own intelligence silo      | A single intelligence feed enriches both                                    |
| Compliance audit (NIS2, DORA, ISO 27001)                              | Vendor-specific logs                                   | Unified enforcement log with timestamp, source, Crime Score, and confidence |

***

## Deployment

```
┌─────────────────────────────────────────────────┐
│              OneFirewall Alliance                │
│         210+ Global Security Centres             │
│                                                  │
│   ┌──────────┐  ┌──────────┐  ┌──────────┐     │
│   │ Member A │  │ Member B │  │ Member C │ ... │
│   └────┬─────┘  └────┬─────┘  └────┬─────┘     │
│        │              │              │           │
│        ▼              ▼              ▼           │
│   ┌──────────────────────────────────────┐      │
│   │     World Crime Feeds (WCF) Engine   │      │
│   │  Validation · Crime Score · ATT&CK   │      │
│   └──────────────┬───────────────────────┘      │
└──────────────────┼──────────────────────────────┘
                   │
        ┌──────────┼──────────────┐
        ▼          ▼              ▼
  ┌──────────┐ ┌──────────┐ ┌──────────┐
  │Palo Alto │ │Check Point│ │ Fortinet │  ... + 13 more
  │   NGFW   │ │  Quantum  │ │FortiGate │
  └──────────┘ └──────────┘ └──────────┘
       Your existing infrastructure stays in place
```

***

## FAQ

### We already have Palo Alto WildFire — why add OneFirewall?

WildFire analyzes files within the Palo Alto ecosystem. OneFirewall adds crowd-sourced IP/domain/URL intelligence from 210+ organizations outside the Palo Alto customer base, validated in real time and pushed directly to your firewall.

### Doesn't Check Point ThreatCloud already aggregate external feeds?

ThreatCloud aggregates feeds from Check Point Research and selected external sources. OneFirewall's intelligence comes from live, reciprocal sharing between 210+ security centres across industries and geographies, with each member both contributing and consuming.

### Is this a rip-and-replace?

No. OneFirewall sits on top of your existing firewall. The WCF Agent integrates with your current infrastructure — no hardware changes, no policy migration.

### What about data sovereignty?

OneFirewall shares only anonymized threat indicators. Logs, user data, and internal traffic stay on-premises.

***

<Callout type="info">
  Ready to test OneFirewall on your existing infrastructure? [Start a Proof of Value](/contact).
</Callout>
