Overview
This guide explains how to integrate OneFirewall Alliance (OFA) Threat Feeds with ForcePoint Web Security / URL Filtering. You can enforce threat intelligence feeds for the following categories:- ✅ Malicious IPs
- ✅ Malicious URLs
Supported ForcePoint Versions
OneFirewall threat feeds are compatible with Forcepoint Web Security / URL Filtering Version 8.5.xPrerequisites
- ✅ A valid OneFirewall Alliance account.
- ✅ Forcepoint running 8.5.x.
- ✅ Ability to operate in the console.
- ✅ Internet access from the gateway to reach OneFirewall’s feed URLs.
- ✅ HTTPS inspection must allow outbound connections to threat feed URLs (if required by policy).
Step 1: Generate API Token
- Log into your OneFirewall Alliance dashboard.
- Go to the API Access section.
- Click Generate JWT Token.
- Save the token securely — this will be used to authenticate feed requests.


Step 2: Configure IP Address List and URL List
For each threat type, follow these general steps:Configure the External Feeds

Install Docker & Docker Compose
Prepare Your Deployment Directory
- Download the WCF Agent Docker image into this folder.
- Obtain your config.json from OneFirewall’s Install Agent page.
- Place config.json in ~/wcf-agent/onefirewall/config.
Create docker-compose.yml
Contact OneFirewall support team with access to download WCF Agent binary image
Launch the Agent
Notes
- OneFirewall uses JWT-based Bearer Authentication.
- Feeds are auto-refreshable and optimized for ForcePoint Web Security / URL filtering integration.
- All feed types can be used simultaneously in different rules or combined policies.