Skip to main content

Legacy Knocs

Before the Trust Engine, each Knoc carried its own list of allowed source addresses and an optional GreyNoise setting. That mode still exists as Legacy, so nothing changed under you when you upgraded.

What Legacy means

A Legacy Knoc decides access from its own Enable Knoc for users connecting from list and its Block if GreyNoise identifies as malicious checkbox, exactly as before. A Legacy Knoc with an empty list is unrestricted.

On a Knoc's edit page, if it has its own IP rules or is already on Legacy, Legacy appears as a choice after the policies. Picking a policy instead supersedes those settings. They are kept rather than deleted, so switching back to Legacy restores them. A new Knoc cannot be created on Legacy.

How upgrades migrate

On upgrade, every Knoc that had no source-address list and no GreyNoise blocking of its own moves onto the Standard policy, so the Trust Engine starts working without you visiting each Knoc. A Knoc whose list actually gated something is left exactly as it was, on Legacy.

Because Standard's provider-backed conditions allow access when they cannot reach a source, nothing decides differently until you connect a threat source.

If you have a Knoc whose address list only ever matched its opened addresses by coincidence, review it after upgrading, since a policy checks the connecting address rather than the addresses the Knoc opens.