Skip to main content

v26.08

Knocknoc 26.08 is a focused release. It adds Fastly ACL and native nftables enforcement, improves Palo Alto visibility, improves administrators operational diagnostics, and resolves smaller user experience issues. In August much of the team were in Las Vegas for Black Hat, BSides and DEFCON, while work continued on several larger product improvements in the background. 26.09 is taking shape behind the scenes, with several larger changes lining up, and we look forward to sharing them soon!

Fastly ACL Support

Knocknoc can now grant and revoke access at the Fastly edge by managing IP entries in an existing Fastly ACL. Changes apply to the active service version immediately, without publishing a new service version or hosting a separate IP feed.

nftables support uplift

Knocknoc can now manage native nftables named sets as a Linux enforcement backend. This provides a modern alternative to IPSet on current Linux systems and supports both IPv4 and IPv6 access.
The setup experience includes discovered-set suggestions, inline validation, connection testing, and guidance for common configuration problems. The agent can also provision default sets and run on nftables-only hosts without requiring IPSet.

Admin and user experience

  • Post-login waiting-room redirects: each Knoc can wait for access to become active before automatically sending the user to its destination, whilst this is typically 30ms-200ms depending on the control layer, some slower backends benefit from this being configured.
  • Faster admin filtering: search controls now sit directly above the tables they filter. The Knocs and API keys pages also include filters for their most useful operational fields, and filter state is retained in the page URL.
  • Rejected agent diagnostics: the Agents page now records connection attempts the server rejects, explains the likely cause and next step, and lets administrators copy or mute each diagnostic instead of searching through repeated log entries.
  • Session management: end all active sessions for a specific user or administrator directly from their identity page, without ending the current administrator's own session.
  • Network context: hover over or tap the current IP address after login to see its country, continent, ASN, network owner, and domain. Private addresses are identified separately.
  • Inactive-user review: the Identities page highlights local users who have never signed in or have not signed in for 90 days, with new activity and expiry filters to help administrators review stale access.
  • Knoc icons are now shown in the admin Knocs table, making larger lists easier to scan.

Palo Alto and Panorama improvements

  • Manual Admin grants now attributed: access granted manually by an administrator is marked in Panorama's User-ID table as the operating admin, making it easier to distinguish operator-issued access from normal user grants.
  • More useful diagnostics: PAN-OS configuration errors now distinguish missing permissions, invalid virtual systems, disconnected Panorama targets, capacity limits, busy devices, and timeouts.

Reliability, security and maintenance

  • Various libraries have been updated, including Golang.
  • HAProxy backend events are handled and reported more reliably.

How do I upgrade?

Upgrade the Knocknoc Server and Agents through your operating system's package manager as usual. See the updates and upgrades guide for instructions.

Release date: 31st August 2026