Skip to main content

Getting Started

Cloud SaaS or self-hosted server?

You can run your Knocknoc server either as a managed cloud instance (we host it) or self-host it.

Should you deploy a cloud or self-hosted instance of Knocknoc? The answer will depend on a few factors.

For example, if you want to integrate an LDAP authentication source that is not on the internet, then of course you need self-hosted. A self-hosted Knocknoc server may also suit you better for various security segmentation scenarios, or even Knocknoc on internal networks, which is great for SCADA or ICS systems.

Our cloud SaaS servers are deployable in under a minute, with DNS records and inbound rules all configured for you ready to go.

Spin up a cloud instance fast via the licensing portal

For self-hosted servers, here is the self-hosted install guide

Licensing

Knocknoc licensing is based on the number of users.

Cloud SaaS instances manage licensing for you - this is the quickest way to get going.

If you are self-hosting, you will need to have a license to install the server, noting you can get 1 free single license for home/DIY use, or lab environments. There is no limit on the amount of groups, backends, agents or ACLs configured. SAML support is also included out of the box!

Orchestration Agents

The agents perform the backend work of updating ACLs, so you need at least one unless you are using Passive firewall orchestration. This can run on the same server as Knocknoc if you so desire. 

Backends and ACLs

Backends and ACLs work hand-in-hand to provide a pathway for your fine-tuned group access. Here are the guides for currently supported backends. When a user authenticates to Knocknoc, grants are applied through ACLs to permit their access.

Groups and Authentication

While users can be created either locally or through SSO (Single Sign On) like SAML (recommended) or LDAP, groups are created locally in the admin portal. A group maps users to ACLs, providing fine-grained control over the resources they have access to.

Read more in the authentication guides and the group setup guide.

Test it out!

The first time you log in, take a look at how Knocknoc works and feels like magic. We can't wait for you to enjoy using Knocknoc every day.

Monitor and Manage

Knocknoc can stream metrics using GELF, and can supply regular exports of user activity. It also has an audit trail function, so you can see exactly what resources which users had access to when. Security teams looking to track fine-grained access to network resources can export to CSV as required.