<200msSync latency
10K+Blocked IPs / day
HWSecureXL accelerated
290+Alliance members
How It Works

From alliance feed to enforced policy

STEP 1

Intelligence aggregation

The OneFirewall API continuously aggregates malicious IPv4 reports from 290+ Alliance members worldwide, assigning a dynamic Crime Score (0–1000) to every observed IP.

STEP 2

Score-based filtering

The WCF Agent polls the OneFirewall API on a configurable interval (default: 5 minutes). Only IPs exceeding your defined Crime Score threshold (default: 190) are selected for enforcement.

STEP 3

SecureXL SAM table injection

Qualifying IPs are pushed into the Check Point SAM (Suspicious Activity Monitor) table via the fw samp API, and SecureXL accelerates the block at the kernel bypass layer.

STEP 4

Automated drop

Traffic from blocked IPs is dropped at hardware speed before policy lookup. When a Crime Score decays below threshold, the WCF Agent automatically removes the block.

Requirements

What you need on the Check Point SecureXL side

  • Check Point Gaia OS R80.40, R81, R81.10, R81.20 or R82
  • Python 3.8+ available on the management server
  • A OneFirewall API token
  • Outbound HTTPS (443) from management to app.onefirewall.com
  • SecureXL enabled on the target gateway (default in R80+)

Ready to accelerate blocking with SecureXL?

Our integration team will walk you through setup on a live call.

Request Integration Access