Overview
This guide describes how to integrate OneFirewall Alliance (OFA) Threat Feeds into a FortiGate Security Fabric using External Dynamic Lists (EDLs). The integration enables automatic enforcement of security rules based on live threat intelligence from OneFirewall, covering both inbound and outbound traffic.Prerequisites
- Custom Bearer token authentication used by OneFirewall’s API requires FortiOS 6.2.3 or higher.
- Devices running FortiOS prior to 6.2.3 can only ingest unauthenticated feeds, which is incompatible with OneFirewall’s authenticated feed.
- FortiOS 6.4 or 7.x is recommended: secure external connectors with headers, feed auto-refreshing, integration with inbound/outbound policies, and GUI-based management and logging.
Step 1: Generate API Token
- Log into your OneFirewall Alliance profile.
- Navigate to the API Access section.
- Generate a JWT token.
- Save this token securely — it will be used for authenticating feed requests.


Step 2: Configure FortiGate External Connector
- Access your FortiGate device.
- Go to
Security Fabric>External Connectors. - Click Create New > Select IP Address Threat Feed.
- Configure the feed.
- Set update interval as needed (e.g., every 15 minutes).
- Save the connector.


Step 3: Create Security Policies
Apply the OFA threat intelligence through security policies.



