Recently Updated Pages
SSH
Use case: Eliminating SSH attack surface in a distributed environment A large distributed enterp...
VPN and ransomware
Use case: Removing VPN ransomware risk from stolen credentials A mid-size business relied on Int...
Use cases (overview)
Knocknoc use cases Knocknoc is extremely versatile and can enable just in time network access co...
User Guide
Welcome to the Knocknoc User Guide. This will cover basic operations including logging in, loggin...
v7.6
Knocknoc 7.6 Knocknoc 7.6 continues the theme of user-experience improvements, this time for end...
v7.0
Announcing Knocknoc 7.0 We’re excited to introduce Knocknoc 7.0, a landmark release packed wit...
v7.5
Knocknoc 7.5 🚀 Knocknoc 7.5 marks a major milestone in our journey to redefine secure network a...
v5.0
Current version of Knocknoc server is: 5.0.62, released on Mon, 12 Feb 2024 Current version of k...
v6.0
We're excited to announce the release of Knocknoc 6, a major leap forward in attack surface reduc...
Grant duration (access period override)
Users are assigned a default "grant period" (in minutes), either within Knocknoc for local users,...
Allowlist/EDL access
Allowlists or External Dynamic Lists (EDLs) served from Knocknoc require an API key for access, i...
Manage user sessions
User sessions can be terminated using the API. This is handy for integration with revocation syst...
LOOTOTL - Last One Out Turn Off The Lights
Knocknoc keeps a track of the IPs and tries to be kind to users that share IPs. This means that i...
Additional client IP addresses
Capturing additional client IP addresses A client may exhibit behaviour where multiple IP addres...
AWS WAF Ipset
Below is a concise guide for a sysadmin (or developer) to set up and configure AWS WAF with a cus...
Apache Webserver
Apache 2.4 and above have slightly different ACL syntax, so this page covers how you can use Knoc...
Nginx
Nginx support via script was added in knocknoc-agent version 1.0.30. This allows for flexible ACL...
Mikrotik RouterOS
The scripting backend can be used for MikroTik RouterOS config updates as well. Here is a sample ...
IPsets with UFW
This is an example that lets you use UFW (https://wiki.ubuntu.com/UncomplicatedFirewall) and IPse...
AWS (EC2) Security Groups
Knocknoc can easily connect to AWS using common utilities and IAM credentials, and update the all...