EDLExternal Dynamic Lists
5minAuto-refresh interval
RESTFortiOS API
≥190Recommended Crime Score threshold
How It Works

From alliance feed to enforced policy

STEP 1

Generate a JWT token

From the OneFirewall dashboard, go to Install Agent → FortiGate → Generate JWT Token. This authenticates your FortiGate External Connector requests to the Alliance API feed URLs.

STEP 2

Configure external connectors

In FortiOS, navigate to Security Fabric → External Connectors → Add New. Select "Threat Feed" type, enter the Alliance IP feed URL, add your JWT Bearer token as an HTTP header, and set the refresh interval to 5 minutes.

STEP 3

Apply in firewall policies

Use the External Connector as a source or destination address object in your firewall policies. FortiGate will automatically refresh and enforce against the live Alliance feed, blocking malicious IPs in real time.

Requirements

What you need on the FortiGate side

  • FortiOS with External Connector support
  • Security Fabric admin access
  • Outbound HTTPS (443) to app.onefirewall.com
  • A OneFirewall Alliance API token (JWT Bearer)

Ready to feed FortiGate from the alliance?

Our integration team will walk you through setup on a live call.

Request Integration Access