Hardware-accelerated blocking, straight from the alliance.
Automatically push Crime Score intelligence from 290+ Alliance members into your Check Point SecureXL gateway for hardware-accelerated blocking under 200ms.
From alliance feed to enforced policy
Intelligence aggregation
The OneFirewall API continuously aggregates malicious IPv4 reports from 290+ Alliance members worldwide, assigning a dynamic Crime Score (0–1000) to every observed IP.
Score-based filtering
The WCF Agent polls the OneFirewall API on a configurable interval (default: 5 minutes). Only IPs exceeding your defined Crime Score threshold (default: 190) are selected for enforcement.
SecureXL SAM table injection
Qualifying IPs are pushed into the Check Point SAM (Suspicious Activity Monitor) table via the fw samp API, and SecureXL accelerates the block at the kernel bypass layer.
Automated drop
Traffic from blocked IPs is dropped at hardware speed before policy lookup. When a Crime Score decays below threshold, the WCF Agent automatically removes the block.
What you need on the Check Point SecureXL side
- Check Point Gaia OS R80.40, R81, R81.10, R81.20 or R82
- Python 3.8+ available on the management server
- A OneFirewall API token
- Outbound HTTPS (443) from management to app.onefirewall.com
- SecureXL enabled on the target gateway (default in R80+)
