Skip to main content

Overview

Integrate OneFirewall Alliance (OFA) threat feeds with ForcePoint Web Security / URL Filtering. This enables real-time policy enforcement based on live threat data for:
  • Malicious IPs
  • Malicious URLs

Compatibility

Compatible with ForcePoint Web Security / URL Filtering version 8.5.x.

Prerequisites

  • A valid OneFirewall Alliance account.
  • ForcePoint running 8.5.x.
  • Console access.
  • Internet access from the gateway to OneFirewall’s feed URLs.
  • HTTPS inspection must allow outbound connections to threat feed URLs, if required by policy.

Step 1: Generate API Token

  1. Log into your OneFirewall Alliance dashboard.
  2. Go to the API Access section.
  3. Click Generate JWT Token.
  4. Save the token securely — it authenticates feed requests.

Step 2: Configure IP Address List and URL List

Configure the external feeds

Install Docker and Docker Compose

Prepare your deployment directory

  1. Download the WCF Agent Docker image into this folder.
  2. Obtain your config.json from OneFirewall’s Install Agent page.
  3. Place config.json in ~/wcf-agent/onefirewall/config.

Create docker-compose.yml

Contact the OneFirewall support team for access to download the WCF Agent binary image.

Launch the agent

Notes

  • OneFirewall uses JWT-based Bearer Authentication.
  • Feeds refresh automatically and are optimized for ForcePoint Web Security / URL Filtering integration.
  • All feed types can be used simultaneously, in different rules or combined policies.