Skip to main content

Trust Engine Overview

The Trust Engine sets conditions on network access. For each Knoc you pick which facts about a connection matter, such as its country, whether it is inside your known networks, whether it uses a VPN, proxy or Tor, and whether the address is on a threat list. For each one you choose whether to allow, observe, challenge, or block.

Save these as a trust policy and attach it to as many Knocs as you like; each Knoc follows one policy. Every connection to a Knoc is checked against its policy. Manage policies under Admin > Trust Engine.

Policies

A policy is a named set of conditions, under Admin > Trust Engine > Policies. You start with three, editable and deletable like any other.

Policy What it does
Passive Checks nothing. The Knoc's own settings decide access.
Standard Observes VPNs, proxies and Tor. Blocks malicious addresses.
Strict Challenges VPNs and proxies. Blocks Tor and malicious addresses.

The VPN, proxy and Tor signals are Coming soon and not evaluated yet, so Standard and Strict act only on malicious addresses today. None of the three restricts by location until you list approved countries or networks.

Add your own, up to eight in total. Reorder with the up and down arrows, and mark one as the default for new Knocs with Make default (a separate setting from list order; with none marked, the first in the list is used).

Saving shows what will change for every Knoc using the policy. When the rules change, you can end the sessions still holding access those Knocs granted, so those users sign in again under the new rules; otherwise their access runs until it ends. A policy cannot be deleted while a Knoc uses it.

On a plan without the IP-intelligence sources, Standard and Strict are stored but enforce nothing until your license covers them. Passive and the country condition work on every plan. For how existing Knocs move onto a policy when you upgrade, see Legacy Knocs.

What you can check

A policy holds these conditions. Set a response on each.

  • Country. The connection comes from outside the countries or regions you allow. Answered from the IP database bundled with Knocknoc, so it needs no external service and works on every plan.
  • Known networks. The connection comes from outside the network ranges you list, such as your office ranges or corporate VPN. Enter them in CIDR form, IPv4 or IPv6, and a bare address becomes a single host. Paid plans.
  • VPNs, proxies and Tor. The connection arrives over a commercial VPN, a residential proxy, or a Tor exit node. Coming soon, not evaluated yet.
  • Malicious addresses. The address is on a threat list, either the threat-intelligence source you connect or one of your own blocked-address lists.

Responses

Response What happens
Off The condition is not checked.
Observe Access continues. The finding is recorded and raised to your SIEM.
Challenge The user confirms who they are before access continues.
Block Access is refused and recorded.

If several conditions match one connection, the strictest response wins. Every match is still recorded.

Challenge

A challenge can ask the user to prove who they are, tighten the access, or both. Its settings fall in two groups.

  • Account sign-in. Require the user to sign in again, and set how long one confirmation counts for, whether every matching request or after 1, 8 or 24 hours.
  • Access limits. Require a click even on a Knoc that grants automatically, and cap how long the access lasts.

A challenge must turn on at least one of these. The user sees Verification needed with a Verify button; confirming delivers the access they asked for.

Connecting a threat source

The malicious-address condition needs a source. Set one under Admin > Trust Engine > Threat intelligence.

  • Threat-intelligence key. Connect GreyNoise to have addresses checked against its reputation data. Your Knocknoc license may already include a key, in which case it works with nothing to set up. A key you enter yourself is checked with the provider when you save.
  • Blocked-address lists. Point Knocknoc at a URL of addresses (IPs or CIDR ranges) to treat as malicious. They are fetched on a schedule you choose and need no key, so a list works on its own. They can also name private addresses, which a threat-intelligence source cannot.

Either source satisfies the malicious-address condition.

Attaching a policy to a Knoc

On a Knoc's edit page, and in the create wizard, Trust engine policy is a row of buttons, one per policy. Choose one and the page shows what it does. A new Knoc starts on the policy marked Default for new Knocs, or the first in the list.

The policy on the page is the whole story for that Knoc. The rules that apply are the ones you can see, with nothing deciding access from anywhere else. Knocs carried over from before the Trust Engine can stay on their own per-Knoc rules; see Legacy Knocs.

Activity

Admin > Trust Engine > Activity shows what your policies decided, including who connected, from where, which Knoc and policy, and the outcome. Filter by outcome or policy, or search for a user, address or Knoc. Each row links to the person's identity and the sign-in session, and opens to show the checks behind the decision.

Every governed Knoc records one finding per sign-in, whether or not anything matched, so you can see that a control is working rather than silently doing nothing. Findings are kept for 30 days, or your log-retention window if that is shorter.

Overriding a block

To let a refused connection through, open the Knoc, find the blocked attempt in its grant history, and select Grant anyway. The dialog shows which policy refused it and what matched, and asks for a comment. The comment is required and is written to the audit log with your name.


For the mechanics behind these decisions, see How trust decisions are made. For provider and list problems, see Troubleshooting. For SIEM integration, see SIEM events.