Blocked Address Lists
Note: Blocked address lists are a premium add-on. Your Knocknoc license must include them before you can add or change a list.
A blocked address list is a list of IP addresses and ranges that you want Knocknoc to treat as malicious. You give Knocknoc the URL of the list and it fetches it on a schedule you choose. You can use a list you already maintain, or one your threat intelligence vendor publishes.
You manage lists under Admin > Trust Engine > Threat intelligence > Blocked address lists.
How a list decides access
Knocknoc treats an address on one of your lists as malicious, in the same way as an address your threat intelligence provider reports. A list doesn't refuse anyone by itself. The Malicious addresses restriction in each Knoc's trust policy decides what happens:
| Malicious addresses response | What happens to a user connecting from a listed address |
|---|---|
| Block | The grant is refused. |
| Challenge | The user is asked to confirm who they are before the grant goes through. |
| Observe | The grant goes through, and the match is recorded under Activity. |
| Off | The grant goes through. |
The same list can refuse access to one Knoc and only be recorded for another, depending on the Knoc's trust policy.
Adding a list
- Go to Admin > Trust Engine > Threat intelligence.
- Under Blocked address lists, click Add list.
- Enter a Name. The name appears under Activity next to any address the list refused, so choose one your team will recognise. Each list needs a different name.
- Enter the Address of the list, as an
httporhttpsURL. - If the list needs authentication, enter a Token. Knocknoc sends it as a bearer token. The token is stored and never shown again. To change it later, enter a new one.
- Choose how often to Fetch the list: every 5 minutes, 15 minutes, hour, 6 hours or day.
- Leave Fetch and enforce this list ticked, and save.
A deployment can have up to 10 lists.
List format
A list is a plain text file:
- one IP address or CIDR range per line, IPv4 or IPv6, such as
203.0.113.7or198.51.100.0/24 - lines starting with
#or;are comments - anything after the address on a line is ignored
Knocknoc skips any line that isn't an address or range and shows how many it skipped. A list that starts with a title or a licence header works as it is.
A list can be up to 8 MB.
A list hosted on your own network
The Knocknoc server fetches the list from inside your network. If the list's URL points at a private, loopback or carrier-grade NAT address (for example a 10. address, localhost or a 100.64. address), the dialog says so. You must tick This list is hosted on a local network address and should be fetched from there before it will save.
If you enter a hostname that resolves to a local address, Knocknoc catches it on the first fetch. The list's card says it is on a local network address. Edit the list and tick the confirmation to fix it.
How a list is kept up to date
Knocknoc fetches each list on the schedule you chose. Click Fetch now on the list's card to fetch it straight away.
Knocknoc treats these fetches as failures:
- A fetch that fails. Knocknoc keeps enforcing the addresses from the last successful fetch, and the card shows the error. A list that can't be reached hasn't said that its addresses are safe.
- A list that comes back empty. Knocknoc keeps the previous addresses, because an error page that returns successfully contains no addresses. Installing it would stop blocking everything the list covered.
- A list that covers every address (
0.0.0.0/0,::/0or::ffff:0:0/96). Knocknoc rejects the whole fetch, because such a list would lock every user out of every Knoc that reads it.
A list that keeps failing is retried at most every 15 minutes, whatever schedule you set.
In a multi-server deployment one server fetches each list and the others use what it stored.
The list card
Each list has a card showing its status:
| Status | Meaning |
|---|---|
| Working | The last fetch succeeded, and the list's addresses are being enforced. |
| Not fetched yet | The list is saved but hasn't been fetched. |
| Last fetch failed | The last fetch failed. The addresses from the last successful fetch are still being enforced. |
| Off | The list isn't being fetched, and its addresses aren't treated as malicious. |
| Not fetching | Your license no longer includes blocked address lists. The list isn't being fetched, but the addresses already fetched are still being enforced. |
The card also shows the list's URL, when it was last fetched, how often it's fetched, whether a token is saved and how many addresses are on it.
Download gives you the addresses Knocknoc is currently enforcing from the list, one per line. This is what Knocknoc actually holds rather than what the publisher sent, which makes it the file to check when you want to know whether an address is on the list.
Turning a list off or deleting it
To stop using a list for a while, edit it and untick Fetch and enforce this list. Knocknoc stops fetching it and its addresses are no longer treated as malicious. The addresses stay stored. When you switch the list back on they're enforced again straight away, and the next fetch brings them up to date.
To remove a list, click Delete on its card. Its addresses stop being treated as malicious straight away.
Turning off or deleting a list doesn't affect access that has already been granted.
If your license lapses
If your license stops including blocked address lists, Knocknoc stops fetching your lists and you can no longer add or change them. The page shows a notice saying so, and each card reads Not fetching.
The addresses already fetched keep being enforced. A lapsed renewal doesn't quietly reopen access to addresses you had blocked. When your license includes lists again, fetching and editing resume.
Seeing what a list refused
When a list decides a grant, Knocknoc names the list in the finding. Under Admin > Trust Engine > Activity, the row reads, for example, "The address is on your Corporate deny blocked address list". This tells you the address came from your own list and not from your threat intelligence provider.
A grant that a list refused is shown as blocked in the Knoc's grant history, and an administrator can override it in the same way as any other blocked grant. See Blocked Grants.