Enterprise-grade CTI enforcement inside Forcepoint NGFW.
The WCF Agent bridges OneFirewall Alliance threat intelligence directly into your Forcepoint Next Generation Firewall — automated blocklists, real-time Crime Score enforcement, and STIX 2.1 indicator sync with zero manual intervention.
From alliance feed to enforced policy
CTI retrieval
The agent authenticates to the OFA platform via Bearer token and retrieves the latest IPv4 threat feed filtered by Crime Score threshold, using incremental pulls to minimise API load.
Object translation
Each qualifying IPv4 indicator is converted into a Forcepoint SMC Network Element object, with metadata tags populated from the OFA STIX bundle.
SMC policy injection
Objects are pushed to the Forcepoint Security Management Center via its REST API and added to the designated deny-list IP group, triggering a policy refresh across all managed NGFW engines.
Decay & removal
When an IP's Crime Score drops below threshold, or its OFA indicator expires, the agent removes it from the SMC group in the next sync cycle — preventing blocklist bloat.
What you need on the Forcepoint NGFW side
- Linux host (Ubuntu 20.04+ / Debian 11+ / RHEL 8+)
- Python 3.9 or later
- Forcepoint NGFW 6.8+ with SMC 6.8+, API enabled
- A dedicated IP Group for the OFA blocklist, referenced by a firewall policy rule
