Proof of Value (PoV) of OneFirewall Solution
Introduction
OneFirewall is a threat intelligence sharing platform. It matches network traffic against a threat intelligence database and reports actionable insights on detected threats.Objective
The Proof of Value (PoV) demonstrates OneFirewall’s ability to identify and mitigate cyber threats in an on-premises or private cloud environment. A VM running the OneFirewall platform is installed, and edge traffic logs are analyzed to detect malicious activity.Scope
-
Installation and Setup:
- Deploy a Virtual Machine with OneFirewall in the on-premises environment.
- Ensure compatibility with the existing private cloud infrastructure.
-
Traffic Logging:
- Enable logging of edge traffic to the OneFirewall VM.
- Configure the system to capture and forward relevant network traffic for analysis.
-
Threat Analysis:
- OneFirewall continuously matches incoming traffic against the threat intelligence database.
- Provide real-time insights and alerts on detected malicious actors attempting to penetrate the network perimeter.
Process
1. Preparation
- Prepare a Linux-based virtual machine (Ubuntu, Debian, Red Hat, or equivalent) with Docker and Docker Compose installed.
- Ensure the selected on-premises environment or private cloud instance meets all network and permission requirements needed for deployment.
- Provide the required access credentials (i.e. VPN, VM credentials with sudoers rights) to the OneFirewall team, who will handle the setup and configuration.
2. Installation
- OneFirewall staff deploy and configure the OneFirewall OnPrem Solution, a containerized ecosystem orchestrated via Docker Compose, under a PoV License.
- Verify network connectivity so the solution can access and process traffic logs.
- Run final installation and connectivity checks to confirm the solution is operational.
3. Configuration
- Enable logging of all edge traffic to the OneFirewall VM.
- Set up the permissions and integrations needed for traffic analysis.
4. Monitoring and Analysis
- OneFirewall monitors network traffic in real time.
- Traffic is matched against the threat intelligence database to identify and classify potential threats.
- Reports and alerts are generated from the analysis.
5. Evaluation
- Assess the volume and nature of detected threats.
- Evaluate the responsiveness and accuracy of OneFirewall in identifying and mitigating potential cyber threats.
- Gather feedback from network security personnel on the platform’s usability and effectiveness.
Deliverables
- Installation Report: Setup process and initial configuration of the OneFirewall VM.
- Traffic Analysis Report: Detected threats, including types of attacks, sources, and frequency.
- Evaluation Report: OneFirewall’s performance during the PoV, including key findings and areas for improvement.

