Overview
This guide describes how to integrate OneFirewall Alliance (OFA) Threat Feeds into Sophos Firewall using External Dynamic Lists (EDLs). The integration enables automatic enforcement of security rules based on live threat intelligence from OneFirewall, covering both inbound and outbound traffic.Prerequisites
- Sophos Firewall 20.0+.
- A VM with the latest Ubuntu LTS, Docker, and Docker Compose, to host the WCF Agent.
Step 1: Generate the Agent Configuration
- Log into your OneFirewall Alliance profile.
- Navigate to the Install Agent section.
- Select Sophos from the dropdown menu and fill in the Sophos API information (URL, user, password). Start with a tolerant score threshold (e.g. 200) — this can be changed later from the agent-status page at runtime.
- Save the generated
config.jsonsecurely — it will be used to authenticate feed requests.

Step 2: Install the WCF Agent
- Contact [email protected] for the installation file (this step will be integrated into the portal in a future release).
- Create a
wcf-agentfolder in a filesystem path of your choice. - Unpack the installation file and follow the instructions in the
READMEfile. Place the downloadedconfig.jsonin theonefirewall/configfolder.
Step 3: Create Security Policies
The Sophos API is the address URL of the Sophos Firewall Dashboard, e.g.192.168.1.1:443.
The agent creates blacklists — external dynamic lists containing the IP threats from OneFirewall — named as shown in the screenshots below.
Once started, configure Inbound/Outbound firewall rules and criteria on the Sophos firewall as shown:



