Skip to main content

v26.09

Our biggest release yet. Months of work behind the scenes, now ready. This release gives you more control over who gets network access, fewer connection settings to maintain, and support for the identity providers your organization actually has.

What's new

  • Trust Engine. A successful login now gets a connection check before network access opens. Detect residential proxies, commercial VPNs, Tor and known malicious IPs, then observe, challenge or block by policy. Stolen credentials arriving from a blocked connection do not open access. Trust Engine guide
  • Integrations. Configure a firewall, proxy or cloud connection once and reuse it across Knocs. Rotate credentials in one place. Integrations guide
  • Multiple identity providers. Offer several SAML providers on one deployment, with distinct accounts and provider-scoped groups. Authentication guide

Plus a round of admin quality-of-life improvements, security fixes and dependency updates.

Trust Engine

A valid login is a good start. A valid login arriving through a residential proxy deserves a few follow-up questions. The Trust Engine decides what happens next, per user and per destination, before network access opens.

  • Write a policy. Choose the conditions that matter and attach it to the Knocs it governs. Start with the supplied Passive, Standard and Strict policies, or create your own. Policies are reusable.
  • Decide what deserves attention. Respond to connections from outside your approved countries or networks, over residential proxies, commercial VPNs or Tor, or from addresses reported malicious by GreyNoise or your own blocked-address lists.
  • Observe, challenge or block. Observe records and lets access continue. Challenge asks for another sign-in, a click, or a shorter access window. Block refuses. The strictest matching response wins.
  • See why. The new Activity view shows who connected, from where, which Knoc and policy applied, and what happened. History keeps the rules that applied at the time, so a later edit does not rewrite yesterday's explanation. Admins can override a refused grant with an audited reason.

Read the Trust Engine guide

Integrations

Until now, each Knoc carried its own copy of the connection details for the system behind it. Ten Knocs on one firewall meant ten copies. Integrations hold that connection once.

  • One connection, many Knocs. Reuse an integration, its agent and credentials, when creating a Knoc. Each Knoc still defines the access it provides.
  • See them in one place. Browse the firewalls, cloud services and reverse proxies your Knocs use. Search, filter and group.
  • Activity per integration. Which Knocs use it, who has been connecting, grant volumes, wait times and failures. Follow a problem from an access path back to the system enforcing it.
  • A clearer setup experience. The rebuilt Knoc wizard offers existing integrations, helps configure new ones, and diagrams how the server, agent and resource fit together. Connection checks catch setup problems early.
  • Find duplicates. Ask your agents to identify matching connections, then merge them into shared integrations while keeping their Knoc assignments.

Read the Integrations guide

Multiple identity providers

Offer several SAML identity providers on one Knocknoc deployment. Useful for partner access, multiple organizations, or an acquisition that left you with two directories.

  • Each provider gets its own named sign-in button and SAML configuration.
  • Accounts stay distinct between providers, even when usernames match. SAML and dynamic groups can be scoped to selected providers.
  • Existing groups stay scoped to the original provider on upgrade.

Additional identity providers require an Enterprise license. You can configure up to five alongside the original provider. Read the Authentication guide

Admin quality-of-life

  • Identities in one place. Sessions, users, admins, groups and delegated access now sit under a single Identities section.
  • Refused agents. The portal shows agents being turned away, why, and how to fix them, with an indicator in the sidebar.
  • Consistent admin pages. Search with filters on the Knocs, API keys and audit log pages, an auto-focused search box, exact timestamps on hover, and live "last seen" ages.
  • Faster Knoc setup. Category suggestions, source restrictions that accept network ranges (CIDR), and Fortinet vsys autofill.
  • Clearer troubleshooting. Grant and revoke errors name the Knoc, ACL and address involved, the Support view has copy buttons, and Knocknoc warns when GELF log forwarding is set up without encryption.

How do I upgrade?

Update the Knocknoc Server and orchestration Agents using the usual operating-system package or installer process. See the updates and upgrades guide.

After upgrading, visit Integrations > Find duplicates to consolidate repeated connections. Update the relevant agents first so they can compare their configurations.

Existing Knocs keep their legacy access controls until you assign a trust policy. Assigning a policy replaces those per-Knoc source restrictions and GreyNoise settings for access decisions; selecting Legacy restores them.

As always, you choose when your Server and Agents update.