Alliance intelligence inside Check Point.
The OneFirewall WCF Agent for Check Point pushes live Alliance threat intelligence — scored IPs, malicious domains, URLs, and file hashes — directly into your Check Point Quantum Security Gateway via SmartConsole External Feeds and EDLs.
From alliance feed to enforced policy
Generate a JWT token
Log into your OneFirewall Alliance dashboard, go to API Access, and generate a JWT Bearer token. This authenticates all feed requests from Check Point to the Alliance API.
Create indicator feeds in SmartConsole
In Check Point SmartConsole, go to Security Policies → Threat Prevention → Indicators → External Feeds. Create four feeds — one each for IP, domain, URL, and file hash — pointing at the Alliance API endpoint with your JWT Bearer token as the Authorization header. Set refresh to 5 minutes.
Define security policies
Use the created feeds as source or destination objects in your Check Point security policies. Assign enforcement actions — Drop, Reject, or Prevent — and install the policy to your Quantum Security Gateways.
What you need on the Check Point side
- Check Point Gaia OS running R80.10 or later
- SmartConsole admin access to create External Feed objects
- Outbound HTTPS (443) from the gateway to app.onefirewall.com
- A OneFirewall Alliance API token (JWT Bearer)
