Skip to main content

v26.08

Knocknoc 26.08 is a focused release. It adds Fastly ACL and native nftables enforcement, improves Palo Alto visibility, sharpens operational diagnostics for administrators, and clears up smaller user-experience issues. Much of the team spent August at Black Hat, BSides and DEFCON in Las Vegas while work continued on larger changes in the background. 26.09 is taking shape, and we look forward to sharing it soon.

What's new

  • Fastly ACL support. Grant and revoke access at the Fastly edge by managing IP entries in an existing Fastly ACL, applied to the live service version at once. Fastly guide
  • Native nftables enforcement. Manage native nftables named sets as a Linux backend, a modern alternative to IPSet, with IPv4 and IPv6 support. nftables guide
  • Clearer Palo Alto and Panorama diagnostics. Operator-issued grants are attributed in Panorama, and PAN-OS errors now name the actual cause.

Plus admin quality-of-life improvements, dependency updates and reliability fixes.

Fastly ACL support

Grant and revoke access at the Fastly edge by managing IP entries in an existing Fastly ACL. Changes apply to the active service version immediately, with no new service version to publish and no separate IP feed to host.

nftables enforcement

Manage native nftables named sets as a Linux enforcement backend, a modern alternative to IPSet on current systems, with both IPv4 and IPv6 access. Setup includes discovered-set suggestions, inline validation, connection testing, and guidance for common configuration problems. The agent can provision default sets and run on nftables-only hosts without IPSet.

Admin quality-of-life

  • Post-login waiting-room redirects. Each Knoc can wait for access to become active before sending the user to its destination. This is usually 30 to 200ms depending on the control layer, and some slower backends benefit from it.
  • Faster admin filtering. Search controls now sit directly above the tables they filter. The Knocs and API keys pages add filters for their most useful operational fields, and filter state is kept in the page URL.
  • Rejected agent diagnostics. The Agents page records connection attempts the server rejects, explains the likely cause and next step, and lets you copy or mute each one instead of searching the logs.
  • Session management. End all active sessions for a user or administrator from their identity page, without ending your own session.
  • Network context. Hover or tap the current IP after login to see its country, continent, ASN, network owner and domain. Private addresses are identified separately.
  • Inactive-user review. The Identities page highlights local users who have never signed in or have not signed in for 90 days, with activity and expiry filters for reviewing stale access.
  • Knoc icons in the table. The admin Knocs table now shows Knoc icons, making longer lists easier to scan.

Palo Alto and Panorama

  • Manual admin grants attributed. Access granted manually by an administrator is marked in Panorama's User-ID table as the operating admin, so operator-issued access is easy to tell from a normal user grant.
  • More useful diagnostics. PAN-OS configuration errors now distinguish missing permissions, invalid virtual systems, disconnected Panorama targets, capacity limits, busy devices and timeouts.

Reliability, security and maintenance

  • Dependency updates, including Golang.
  • HAProxy backend events are handled and reported more reliably.

How do I upgrade?

Upgrade the Knocknoc Server and Agents through your operating system's package manager as usual. See the updates and upgrades guide.

Released 31 August 2026.