Alliance intelligence inside FortiGate.
The OneFirewall WCF Agent for FortiGate delivers live Alliance threat intelligence directly into Fortinet FortiOS via External Dynamic Lists (EDLs) — automatically creating and updating dynamic address groups for real-time policy enforcement.
From alliance feed to enforced policy
Generate a JWT token
From the OneFirewall dashboard, go to Install Agent → FortiGate → Generate JWT Token. This authenticates your FortiGate External Connector requests to the Alliance API feed URLs.
Configure external connectors
In FortiOS, navigate to Security Fabric → External Connectors → Add New. Select "Threat Feed" type, enter the Alliance IP feed URL, add your JWT Bearer token as an HTTP header, and set the refresh interval to 5 minutes.
Apply in firewall policies
Use the External Connector as a source or destination address object in your firewall policies. FortiGate will automatically refresh and enforce against the live Alliance feed, blocking malicious IPs in real time.
What you need on the FortiGate side
- FortiOS with External Connector support
- Security Fabric admin access
- Outbound HTTPS (443) to app.onefirewall.com
- A OneFirewall Alliance API token (JWT Bearer)
