Admin Guide
Read the "how it works" first
Getting Started
Cloud SaaS or self-hosted server? You can run your Knocknoc server either as a managed cloud inst...
Deployment
Running the Knocknoc server: SaaS or self-hosted, database, high availability and licensing.
SaaS deployment
Knocknoc can host and operate your server as a managed cloud instance. Use the Instances page to ...
Server installation (on premise)
On a Linux host as Root, execute the below command to setup and install your Knocknoc server. You...
Licensing Knocknoc
Knocknoc licensing and pricing can be found on the Knocknoc website. Once you have obtained your ...
Agent installation
The Orchestration Agent runs on a server to control network access for users on their behalf. Thi...
Settings
The Settings page is where administrators configure how Knocknoc behaves across the whole deploym...
BYO PostgreSQL
Knocknoc server v8.5+ installs with a local installation of PostgreSQL by default. However, you m...
Agent as a Reverse Proxy
The orchestration agent can be configured to reverse-proxy traffic, simply by enabling this mode ...
High availability
A Knocknoc deployment has three parts: the Server (web app), its Database (PostgreSQL), and one o...
Knocknoc server behind HAProxy
Running Knocknoc behind HAProxy could be a great option for people with existing HAProxy deployme...
Knocknoc client (scriptable login)
To gain access to underlying networks and systems, end-users log in to Knocknoc interactively vi...
Knocknoc iOS & Android App
Closed beta. The Knocknoc mobile app is currently available to beta testers only and is not yet p...
Knocs
Setting up a Knoc: how access is granted and revoked, and the settings that shape each grant.
Knocs
A Knoc is the access rule your users see. It says who can request access to a resource and under ...
Grant and revoke process
What triggers a grant or revoke The granting and revoking of access by Knocknoc occurs on a numbe...
Click to grant/revoke
For additional security and temporal access control, Knocs support a "click to grant" and "click ...
TOTP per Knoc
For additional security and identity verification, Knocs support a "Require TOTP code when access...
Grant duration
Users are assigned a default "grant period" (in minutes), either within Knocknoc for local users,...
Redirecting Users
Knocknoc supports a couple of ways to redirect users to and from Knocknoc, which can be useful fo...
Additional client IP addresses
Capturing additional client IP addresses A client may exhibit behavior where multiple IP addresse...
VPNs, internal addresses and access
You may want to limit the ability to access a Knoc, depending on where your user is logging in to...
Manual Access
Default deny is the best way to live. However sometimes you need to manually grant access for a n...
Blocked Grants
Knocknoc can refuse a grant when the connection doesn't meet the rules set for a Knoc. The grant ...
LOOTOTL - Last One Out Turn Off The Lights
Knocknoc keeps a track of source IP addresses and tries to be kind to users that share IPs. Think...
Integrations
An integration is a firewall, proxy, cloud platform or on-host enforcement point your agents act ...
Integrations Overview
An integration is one firewall, proxy, cloud platform or on-host enforcement point, plus the agen...
IPSet (Linux Netfilter/IPTables)
Linux comes equipped with a built-in native firewall which Knocknoc orchestrates via "IPSets". IP...
Allowlist (EDLs)
The Allowlist backend makes a list of active IP address grants available via the Knocknoc server ...
Allowlist/EDL access
Allowlists or External Dynamic Lists (EDLs) served from Knocknoc require a secret for access, alo...
Windows Firewall
Microsoft Windows comes equipped with a built-in native firewall which Knocknoc orchestrates to p...
PF (Packet Filter)
Knocknoc integrates with the PF packet filter to dynamically control network access on a host tha...
Fortinet
Knocknoc orchestrates Fortinet FortiGate firewalls - directly or via FortiManager - to dynamicall...
Palo Alto
Knocknoc integrates with Palo Alto firewalls and the Panorama management system to dynamically gr...
Palo Alto
Knocknoc orchestrates Palo Alto firewalls - directly or via Panorama - to dynamically control net...
SonicWall
The SonicWall can be orchestrated in three ways, Actively (API call from an Orchestration Agent t...
Check Point
Knocknoc controls access on Check Point gateways in one of two ways. In Active mode the Knocknoc ...
F5 Networks
Knocknoc can orchestrate F5 Networks BigIP and related devices via two mechanisms, including iRul...
Cisco (SFMC/Firepower)
The Cisco Secure Firewall Management Console (formerly known as Firepower) integration allows Kn...
Sophos (SFOS/XGS)
The Sophos SFOS/XGS based devices provide advanced firewall and UTM capabilities. This replaces t...
Microsoft Azure NSG
Overview This integration allows for IP addresses to be dynamically managed within Azure Network ...
Microsoft Entra (Named Location)
Knocknoc integrates with Microsoft Entra ID (formerly Azure AD) to dynamically control which IPs ...
Okta
Knocknoc integrates with Okta to dynamically control which IPs are allowed to access apps protect...
AWS (EC2) Security Groups
Knocknoc can orchestrate Amazon AWS Security Groups, which essentially provide network level fire...
Google Cloud Platform (GCP)
Knocknoc integrates with Google Cloud Platform to dynamically control network access via VPC Fire...
AWS WAF Ipset
Below is a concise guide for a sysadmin (or developer) to set up and configure AWS WAF with a cus...
Cloudflare IP lists
Knocknoc can orchestrate Cloudflare IP lists to provide dynamic IP network allowlisting inbound t...
DigitalOcean Firewalls
Knocknoc can orchestrate DigitalOcean Cloud Firewalls to provide dynamic IP network allowlisting ...
Fastly
Knocknoc integrates with Fastly to control which source IPs an edge service lets through. The int...
Knocknoc Reverse Proxy
The Knocknoc orchestration Agent - which is deployed alongside managed infrastructure (not on des...
HAProxy
HAProxy is a fantastic reverse proxy with a massive amount of features. Knocknoc has supported HA...
HAProxy + KAT
Sometimes IP address restrictions or IP-based allowlisting is not enough, think: airport lounge, ...
Nginx
Knocknoc can drive an nginx server's allow/deny list directly from the agent, without a wrapper s...
Traefik
Knocknoc protects services behind Traefik with the Knocknoc Traefik plugin. The plugin is a middl...
Apache Webserver
Apache 2.4 and above have slightly different ACL syntax, so this page covers how you can use Knoc...
IPsets with UFW
This is an example that lets you use UFW (https://wiki.ubuntu.com/UncomplicatedFirewall) and IPse...
IPsets with Shorewall
This is an example that lets you use Shorewall https://shorewall.org/index.html and IPsets to dyn...
Firewalld
IPsets with firewalld On RHEL-family hosts — and any distribution that uses firewalld as its fir...
nftables
Knocknoc integrates with nftables to dynamically control network access on a Linux host. When a u...
OPNsense
Knocknoc integrates with OPNsense by managing the contents of a pre-existing firewall alias via t...
pfSense
Knocknoc integrates with pfSense to dynamically control network access. The Knocknoc agent maint...
MikroTik
Knocknoc integrates with MikroTik RouterOS to dynamically control network access. The Knocknoc ag...
Proxmox VE
Knocknoc integrates with Proxmox VE to dynamically control network access using the built-in Prox...
Kemp LoadMaster
Knocknoc integrates with the Kemp LoadMaster to dynamically control network access. Knocknoc dyna...
Cisco Meraki
Knocknoc integrates with Cisco Meraki to dynamically control which source IPs are allowed through...
Juniper SRX
Passive, Active or a combination Passive - Knocknoc's Allowlist feature provides a passive integr...
Sophos (UTM)
The Sophos UTM device provides firewall and UTM capabilities. Note that this series of devices is...
Custom Script
The "Custom Script" Knoc type is simply a script the agent can execute directly on the Agent mach...
Agents
Installing and registering Knocknoc agents, which apply access changes on your firewalls, proxies...
Linux Agent Installation
On a Linux host as Root, execute the below command to setup and install a Knocknoc Agent. You wil...
Windows Agent Installation
On a Windows machine as an Admin, download and install the Orchestration Agent. It will install a...
OpenBSD Agent Installation
The Knocknoc OpenBSD Agent is orchestration software for managing just-in-time network access. It...
Agent registration
API keys can be created to allow just-in-time orchestration Agent registration, which is suitable...
Knocker - a cli helper
The Knocker utility is a command-line tool for managing various backends or server features with ...
Identities
Managing the people and groups who use Knocknoc, including administrators, users and the groups t...
Sessions
The Sessions tab under Identities is the first thing you see when you open Identities in the admi...
Admins
Admins in Knocknoc can log in to /admin on their Knocknoc server, however they can't be granted A...
Create users
Users sign in and get access to your infrastructure through the Knocs and groups assigned to them...
Create groups
Groups in Knocknoc map users to Knocs, and a user can belong to multiple groups. To create a grou...
Agentic Access and Companions
Knocknoc normally grants access to the single IP a user authenticates from. Agentic Access and Co...
Session limits and disconnecting sessions
Each Knocknoc user has a limit on how many things can be signed in and holding access at the same...
Manage user sessions
Invalidating sessions from the admin portal You can sign users or admins out in bulk from the adm...
Trust Engine
How the Trust Engine works and how to use it.
Trust Engine Overview
The Trust Engine sets conditions on network access. For each Knoc you pick which facts about a co...
How trust decisions are made
This page covers the mechanics behind a policy. It explains when access is instant and when it wa...
Troubleshooting
"IP intelligence is degraded" A banner at the top of the admin pages reads IP intelligence is deg...
SIEM events
The Trust Engine raises these events, delivered through the GELF log destination configured under...
Legacy Knocs
Before the Trust Engine, each Knoc carried its own list of allowed source addresses and an option...
Blocked Address Lists
Note: Blocked address lists are a premium add-on. Your Knocknoc license must include them before ...
Authentication
A guide on configuring the various authentication methods for Knocknoc
Local Authentication (MFA included)
Knocknoc supports local users in addition to SAML/LDAP. Simply add a user, with a username and pa...
SAML
SAML is an in-depth topic, however it represents the best option for securing users, and providin...
Entra ID (SSO, Azure AD)
Single Sign On using Entra is simple, follow the guide below to configure Knocknoc User and/or Ad...
OKTA
The following example assumes your Knocknoc instance is located at https://demo.knoc.cloud. Where...
G Suite (Google)
G Suite can be set up as an Identity Provider if you have G Suite Business Starter or above plan....
CyberArk
CyberArk integrates with Knocknoc via the "Web Apps" component, passing through SAML assertions. ...
Authentik
In this example our authentik instance is hosted at https://auth.example.com/ and is running vers...
1Kosmos
Configure 1Kosmos as a SAML identity provider (IdP) for Knocknoc. Once connected, your users auth...
Ping Identity
Ping Identity SSO Configure PingOne as a SAML identity provider (IdP) for Knocknoc. Users authent...
Keycloak
Keycloak supports multiple authentication realms, so you must first select the appropriate realm ...
Jumpcloud
The following example assumes your Knocknoc instance is located at https://demo.knoc.cloud. Where...
ADFS
The following example assumes your Knocknoc instance is located at https://your-knocknoc.cloud/. ...
LDAP
Knocknoc can authenticate users to an LDAP server like Active Directory, by attempting to bind as...
LDAP troubleshooting tips
The Knocknoc server will need to be able to contact your LDAP server on port 389 or 636. This is ...
API Keys
Knocknoc offers an API for various inbound integrations, from authentication through user-session...
Troubleshooting
What can go wrong, will. Debugging tips, error codes and fixes for common issues.
Logs
Logging is important - we love logging. Because of this, we have included an easy to find, follow...
Debugging & log levels
Things go wrong from time to time, the best way to understand more detail is to increase the log ...
Break Glass
Default deny is a wonderful thing, the best place to be - except when you lock yourself out. Than...
Time for NTP
NTP It's important that ALL the servers within the Knocknoc cluster and agents are synchronized a...
HAProxy tips and tricks
Checking to see if an ACL is present in HAProxy For when you aren't sure if the whole process is ...
Error Codes
Agent Error Codes Palo Alto 200000 - Target Firewall Not Connected to Panorama 200050 - Username ...
Maintenance
Keeping Knocknoc up to date, with guidance on upgrades, backups and database maintenance.
Updates and upgrades
The Knocknoc software is managed by your operating system, as such updates can be managed within ...
Channels and Beta
If you're after the very latest features or changes, and you know what you're doing - below is ho...
Package Repository Key expired
Debian distros (Ubuntu etc) If you are getting this error: Failed to fetch https://packages.knock...
Backups
This document outlines database and application level backups which may be considered ahead of ch...
Moving from SQLite to PostgreSQL
If you installed Knocknoc Server before version 8.5 (September 2025), your instance is likely usi...
PostgreSQL replication and failover
You can run the Knocknoc database on a pair of PostgreSQL servers. If one server fails, you switc...