Recently Updated Pages
Local Authentication (MFA included)
Knocknoc supports local users in addition to SAML/LDAP. Simply add a user, with a username and p...
IPSet (Linux Netfilter/IPTables)
IPSets are a powerful and highly efficient way of making a dynamic firewall on a normal Linux mac...
Agent installation
On a Linux host as Root, execute the below command to setup and install a Knocknoc Agent. You wil...
Getting Started
Cloud SaaS or self-hosted server? You can run your Knocknoc server either as a managed cloud ins...
Server installation (on premise)
On a Linux host as Root, execute the below command to setup and install your Knocknoc server. You...
Moving from SQLite to PostgreSQL
If you installed Knocknoc Server before version 7.7, your instance is likely using a local SQLite...
SaaS deployment
Simply go to: https://licensing.knocknoc.io and follow the prompts! To create a SaaS Server in...
Updates and upgrades
The Knocknoc software is managed by your operating system, as such updates can be managed within ...
SAML with EntraID (Azure AD)
The following example assumes your Knocknoc instance is located at https://demo.knoc.cloud. Where...
v8.5
Knocknoc 8.5 Knocknoc 8.5 delivers key improvements in usability, integrations, and security, ...
High availability
The Knocknoc Server can be deployed in various ways to match your high-availability needs and dep...
Knocknoc Reverse Proxy
The Knocknoc orchestration Agent - which is deployed alongside managed infrastructure (not on des...
HAProxy + KAT
Sometimes IP address restrictions or IP-based allowlisting is not enough, think: airport lounge, ...
Palo Alto
Passive, Active or a combination Passive - Knocknoc's Allowlist features provides a passive inte...
AWS (EC2) Security Groups
Knocknoc can orchestrate Amazon AWS Security Groups, which essentially provide network level fire...
Fortigate Address Groups (Fortinet)
The FortiOS integration allows Knocknoc to dynamically add and remove user's source IP from a na...
SAML for the Admin Interface
SAML for the admin interface is the same as SAML for the user base with a few very small alterati...
Package Repository Key expired
Debian distros (Ubuntu etc) If you are getting the this error: Failed to fetch https://packages...
Agent as a Reverse Proxy
The orchestration agent can be configured to reverse-proxy traffic, simply by enabling this mode ...
BYO PostgreSQL
Knocknoc server v8.5+ installs with a local installation of PostgreSQL by default. However, you m...