Skip to main content

v26.09

Our biggest release yet,yet. bringingMonths togetherof capabilities we’ve been working onwork behind the scenesscenes, fornow months.ready. WeThis wantedrelease gives you more control over who gets network access, fewer connection settings to getmaintain, themand right. Now they’re ready.

Introducing never-before-seen capability: just-in-time, user-attributed trust assessmentsupport for the specificidentity destination being requested, before network access opens. Alongside it, Integrations lets you configure firewall, proxy and cloud connections once, reuse them acrossproviders your Knocs,organization andactually manage credentials in one place.
has.

What's new

  • Integrations:Trust configure once, reuse across Knocs.Engine. Share firewall, proxy and cloud connections, rotate credentials in one place, and trace access problems back to the integration involved. Less copying and pasting. Fewer opportunities to update nine out of ten configurations.
Trust Engine: aA successful login stillnow gets a connection check. Just-in-time, user-attributed trust assessment for the destination being requestedcheck before network access opens. Detect residential proxies, commercial VPNs, Tor exit nodes and known malicious IPs, then observe, challenge or block accordingby topolicy. your policies. If someone signs in with stolenStolen credentials arriving from a blocked connection yourdo policy blocks, that successful login won’tnot open networkaccess. access.Trust Engine guide Integrations. Configure a firewall, proxy or cloud connection once and reuse it across Knocs. Rotate credentials in one place. Integrations guide Multiple identity providers: bring your organizations together.providers. Offer several SAML providers on one Knocknoc deployment, with distinct accounts and provider-scoped groups. YourAuthentication directory migration can proceed at its own, apparently geological, pace.guide

TherePlus area alsoround improvementsof toadmin setup,quality-of-life activity reporting and troubleshooting, plusimprovements, security fixes and dependency updates.

Introducing

Trust Intergrations

Engine

ConfigureA valid login is a firewallgood connectionstart. once.A Usevalid login arriving through a residential proxy deserves a few follow-up questions. The Trust Engine decides what happens next, per user and per destination, before network access opens.

    Write a policy. Choose the conditions that matter and attach it acrossto the Knocs it governs. Start with the supplied Passive, Standard and Strict policies, or create your Knocs.own. RotatePolicies itsare credentialsreusable. inDecide onewhat place.deserves

    attention.
     Respond to connections from outside your approved countries or networks, over residential proxies, commercial VPNs or Tor, or from addresses reported malicious by GreyNoise or your own blocked-address lists. Observe, challenge or block. Observe records and lets access continue. Challenge asks for another sign-in, a click, or a shorter access window. Block refuses. The strictest matching response wins. See why. The new Activity view shows who connected, from where, which Knoc and policy applied, and what happened. History keeps the rules that applied at the time, so a later edit does not rewrite yesterday's explanation. Admins can override a refused grant with an audited reason.

    Read the Trust Engine guide

    Integrations

    Until now, each Knoc carried its own copy of the connection details for the system behind it. If tenTen Knocs usedon theone same firewall, thatfirewall meant ten places holding its settings.copies. Integrations bringshold those connections together so multiple Knocs can share the samethat connection details.

    Your next password rotation should involve considerably less copying, pasting and quiet swearing.
    once.

    • One connection, many Knocs. Reuse an existingintegration, integrationits agent and credentials, when creating a Knoc, including its agent and credentials.Knoc. Each Knoc still defines the access it provides.
    • See your integrationsthem in one place. Browse the firewalls, cloud services and reverse proxies your Knocs use, including firewalls running directly on your servers.use. Search, filter and group them to find what you need.group.
    • Activity per integration. See whichWhich Knocs use anit, integration,who who'shas been accessing them,connecting, grant volumes, average wait times and failures. Follow a problem from an access path back to the system enforcing it.
    • A clearer setup experience. The rebuilt Knoc wizard offers existing integrations as you go,integrations, helps configure new ones, and shows diagrams of how the server, agent and protected resource fit together. Handy when the person who knows how it all fits together is on leave. Connection checks help catch setup problems before you finish.early.
    • BringFind existing configurations together.duplicates. The Find duplicates tool asksAsk your agents to identify matching connections, then lets you merge them into shared integrations while retainingkeeping their Knoc assignments. It also identifies agents that need updating before they can compare configurations.

    Introducing the Trust Engine

    A valid login is a good start. A valid login arriving through a residential proxy may deserve a few follow-up questions. The Trust Engine gives you control over what happens next, before network access opens.

    These decisions are tied to the user and the destination they’re requesting. The same connection can warrant different controls for an everyday application and a sensitive admin service.

    Create a named policy, choose the conditions that matter, and attach it to the Knocs it should govern. Start with the supplied Passive, Standard and Strict policies, or create your own. Policies are reusable, so you can apply the same rules across several access paths and manage them together.

    Decide what deserves attention

    Policies can respond to connections from: 

      Outside your approved countries or continents. Outside your known IPv4 or IPv6 networks, such as office ranges or your corporate VPN. Residential proxy networks, recognised commercial VPN providers or Tor exit nodes. Addresses reported as malicious by GreyNoise, or found on your configured blocked-address lists.

      Location checks can useRead the IPIntegrations database bundled with Knocknoc. IPinfo supplies anonymising-network intelligence, while GreyNoise supplies threat intelligence. The Sources page brings provider setup, key validation and service status together. You can use your own provider keys, or keys supplied through your Knocknoc licence where included.
      guide

      Observe Challenge or Block

      Each condition has its own response:

        Observe: let access continue and record what the policy found. Useful when introducing a control and understanding its impact before enforcing it. Challenge: request another sign-in, require a click for access, shorten the access window, or combine those controls. Block: refuse access and record the reason.

        Observe is a good place to start if you'd prefer to discover a policy's impact somewhere other than the help-desk queue.
        If several conditions match, the strictest response applies. You can also leave individual checks off.
        For example, you could observe commercial VPN use on an everyday application, require another sign-in and a 15-minute access window for a sensitive admin service, and block known malicious addresses on both. We think that's pretty magical, and we think you will too.

        See why a decision was made

        The new Activity view shows who connected, from where, which Knoc and policy were involved, and what happened. Open a finding to see the checks behind it. The same information is available in session details and relevant blocked-grant records.

        History keeps the policy details that applied at the time, so changing a rule later doesn't rewrite yesterday's explanation. Useful when "nothing changed" turns out to mean "nothing changed that I remember". Challenges show whether the user has verified, and administrators can override a refused grant with a required, audited reason.

        Users get clearer feedback too: a verification prompt when they need to act, a connection-checking state while a required lookup finishes, and a visible access limit when a policy shortens their grant.

        Control how you roll it

        Choose a default policy for new Knocs and assign policies to existing ones as needed. When saving policy changes, review their impact and choose whether to end affected sessions so users sign in under the new rules. Existing access otherwise continues until it ends.

        Country restrictions are available on the free plan; other restrictions require a paid plan, with provider-backed checks needing the relevant intelligence source. External blocked-address feeds are available as an add-on.

        One more thing. More than one

        Multiple identity provider

        providers

        You can now offerOffer several user SAML identity providers on the sameone Knocknoc deployment. Useful for partner access, multiple organisations,organizations, or thatan acquisition whichthat left you with two directories and a very optimistic migration timeline.
        directories.

        • Each provider gets its own named sign-in button and SAML configuration.
        • Accounts remainstay distinct between providers, even when usernames match. SAML and dynamic groups can be scoped to selected providers.
        • Existing groups remainstay scoped to the original provider on upgrade.

        Additional user identity providers require an Enterprise licence.license. You can configure up to five alongside the original provider. Read the Authentication guide

        Other

        Admin Improvements

        quality-of-life

        We've

        alsoIdentities improvedin integrationone reliability,place. madeSessions, troubleshootingusers, cleareradmins, groups and polisheddelegated access now sit under a single Identities section. Refused agents. The portal shows agents being turned away, why, and how to fix them, with an indicator in the sidebar. Consistent admin experience.pages. ThisSearch releasewith includesfilters securityon fixesthe Knocs, API keys and dependencyaudit updateslog too.pages,

        an auto-focused search box, exact timestamps on hover, and live "last seen" ages.

        Faster Knoc setup. Category suggestions, source restrictions that accept network ranges (CIDR), and Fortinet vsys autofill. Clearer troubleshooting. Grant and revoke errors name the Knoc, ACL and address involved, the Support view has copy buttons, and Knocknoc warns when GELF log forwarding is set up without encryption.

        How do I upgrade?

        UpgradeUpdate the Knocknoc Server and orchestration Agents throughusing yourthe operatingusual system'soperating-system package manageror asinstaller usual.process. See the updates and upgrades guide.

        After upgrading, visit Integrations > Find duplicates to consolidate repeated connections. Update the relevant agents first so they can compare their configurations.

        Existing Knocs keep their legacy access controls until you assign a trust policy. Assigning a policy replaces those per-Knoc source restrictions and GreyNoise settings for instructions.
        access decisions; selecting Legacy restores them.

        ReleaseAs date:always, 29thyou Septemberchoose 2026when your Server and Agents update.