Skip to main content

Overview

The WCF Sensor Configuration is a pre-defined JSON file that determines how your installed setup instructs your firewall, router, or IPS device to behave. OneFirewall supports two setup types:
  • API-Based
  • Agent-Based

API-Based Setup

The simplest installation method. Covers systems such as Fortigate, Checkpoint, pfSense, and others. Select your device from the menu and enable it. The system guides you through the remaining steps during installation.

Agent-Based Setup

Applies to systems such as Checkpoint SecureXL, Sophos, Trellix, and others. To connect these with OneFirewall for real-time protection, install the WCF Agent — the bridge between your device and the OneFirewall platform. When you select a device that requires an agent, the system generates a pre-compiled JSON configuration. Review and edit this JSON before completing the integration with your device.

Step 1: Activation

  1. Log in to your OneFirewall Server instance, open the main menu on the right, and click Install Agent.
  2. Select the device you want to activate.
  3. Define the following parameters:
    • IoC Type — Choose between IP, URL, Domain, or File.
    • Cyber Crime Threshold — Set the sensitivity level at which the device starts blocking threats.
    • Sync Interval — Define how often the agent updates its IoC data.
If the selected device requires an Agent-Based setup, you are presented with the following form:

Step 2: Download Configuration

  1. Prepare a virtual machine with Docker and Docker Compose installed.
  2. Download the docker-compose.yml file from the previous step and place it on the new machine. This file contains the parameters (including your certificate) the agent needs to connect securely to your OneFirewall Server.
  3. Start the agent:

Step 3: Setup Access

  1. Navigate to the Agent Status page from the menu to see the list of installed agents.
  2. Click View & Edit on the newly installed agent to open its JSON configuration form.
  3. Scroll to the ips section of the JSON and set your own parameters. See the examples below.

Notes

Below are JSON configuration examples for each supported device.

Sophos

Checkpoint SecureXL