≥190Default Crime Score threshold
50K+Malicious IPs blocked daily
290+Alliance member sources
0Manual interventions required
How It Works

From alliance feed to enforced policy

STEP 1

CTI retrieval

The agent authenticates to the OFA platform via Bearer token and retrieves the latest IPv4 threat feed filtered by Crime Score threshold, using incremental pulls to minimise API load.

STEP 2

Object translation

Each qualifying IPv4 indicator is converted into a Forcepoint SMC Network Element object, with metadata tags populated from the OFA STIX bundle.

STEP 3

SMC policy injection

Objects are pushed to the Forcepoint Security Management Center via its REST API and added to the designated deny-list IP group, triggering a policy refresh across all managed NGFW engines.

STEP 4

Decay & removal

When an IP's Crime Score drops below threshold, or its OFA indicator expires, the agent removes it from the SMC group in the next sync cycle — preventing blocklist bloat.

Requirements

What you need on the Forcepoint NGFW side

  • Linux host (Ubuntu 20.04+ / Debian 11+ / RHEL 8+)
  • Python 3.9 or later
  • Forcepoint NGFW 6.8+ with SMC 6.8+, API enabled
  • A dedicated IP Group for the OFA blocklist, referenced by a firewall policy rule

Ready to feed Forcepoint NGFW from the alliance?

Our integration team will walk you through setup on a live call.

Request Integration Access