5 minDocker deployment
UDP 514Syslog inbound
HTTPSAlliance connection
MultiFirewall support
Under the Hood

Three services, one Docker Compose file

Each ONE-F3D-Agent instance bundles a WCF Agent, an nginx feed server, and a fluentbit-adapter for syslog ingestion — syncing to your OneFirewall Solution server over HTTPS.

$ docker compose logs -f
✓ f3d-agent   Running
✓ feed-server Running on :8080
✓ syslog-rx   Listening UDP :514
What Each Word Means

Feed. Defend. Detect. Not just a name.

Feed

The nginx feed server and fluentbit-adapter pull live Alliance threat intelligence down to the agent and push your own syslog observations back up — a two-way feed that keeps both sides current without a manual export step.

Defend

The bundled WCF Agent takes that intelligence and writes enforcement rules directly into the firewalls it's paired with, so the defence is applied automatically at the edge rather than queued for a human to action.

Detect

The syslog-rx service listens on UDP 514 and scores inbound traffic against the live Crime Score database in real time, flagging malicious activity the moment it's seen rather than on the next batch cycle.

Questions Before You Deploy

What a sysadmin actually asks

What happens if the agent loses internet access?

Detection and enforcement continue to run on the last threat feed the agent had — it fails closed on the rules already loaded, not open. Syslog ingestion keeps buffering locally and syncs once connectivity returns.

Can we run more than one agent?

Yes — most multi-site deployments run one ONE-F3D-Agent per location, each syncing independently to the same OneFirewall Solution server, so a threat seen at one site reaches every other site's agent.

Does it need a public IP or inbound internet access?

No. The only outbound requirement is TCP 443 to the Alliance. Syslog and feed-server traffic (UDP 514, TCP 443/8080) stay inside your own network — nothing needs to be exposed to the public internet for the agent to work.

System Requirements

Minimum vs. recommended

Minimum
  • 2 vCPU
  • 4 GB RAM
  • 20 GB disk
  • Docker + Docker Compose
Recommended
  • 4 vCPU
  • 8 GB RAM
  • 50 GB disk
  • Debian / Ubuntu LTS

Network: inbound UDP 514 (syslog), inbound TCP 443/8080 (feeds), outbound TCP 443 to the Alliance.

Deploy your F3D Agent today.

Five minutes from zero to live threat enforcement.

Talk to Our Engineering Team