Feed. Defend. Detect. All from one agent.
The ONE-F3D Agent is your on-premises security orchestration hub — ingesting syslog from your SIEM, pushing live Alliance threat feeds to your firewalls, and detecting malicious traffic in real time, all with a 5-minute Docker deployment.
Three services, one Docker Compose file
Each ONE-F3D-Agent instance bundles a WCF Agent, an nginx feed server, and a fluentbit-adapter for syslog ingestion — syncing to your OneFirewall Solution server over HTTPS.
$ docker compose logs -f ✓ f3d-agent Running ✓ feed-server Running on :8080 ✓ syslog-rx Listening UDP :514
Feed. Defend. Detect. Not just a name.
Feed
The nginx feed server and fluentbit-adapter pull live Alliance threat intelligence down to the agent and push your own syslog observations back up — a two-way feed that keeps both sides current without a manual export step.
Defend
The bundled WCF Agent takes that intelligence and writes enforcement rules directly into the firewalls it's paired with, so the defence is applied automatically at the edge rather than queued for a human to action.
Detect
The syslog-rx service listens on UDP 514 and scores inbound traffic against the live Crime Score database in real time, flagging malicious activity the moment it's seen rather than on the next batch cycle.
What a sysadmin actually asks
What happens if the agent loses internet access?
Detection and enforcement continue to run on the last threat feed the agent had — it fails closed on the rules already loaded, not open. Syslog ingestion keeps buffering locally and syncs once connectivity returns.
Can we run more than one agent?
Yes — most multi-site deployments run one ONE-F3D-Agent per location, each syncing independently to the same OneFirewall Solution server, so a threat seen at one site reaches every other site's agent.
Does it need a public IP or inbound internet access?
No. The only outbound requirement is TCP 443 to the Alliance. Syslog and feed-server traffic (UDP 514, TCP 443/8080) stay inside your own network — nothing needs to be exposed to the public internet for the agent to work.
Minimum vs. recommended
- 2 vCPU
- 4 GB RAM
- 20 GB disk
- Docker + Docker Compose
- 4 vCPU
- 8 GB RAM
- 50 GB disk
- Debian / Ubuntu LTS
Network: inbound UDP 514 (syslog), inbound TCP 443/8080 (feeds), outbound TCP 443 to the Alliance.
