Recently Updated Pages
v6.0
We're excited to announce the release of Knocknoc 6, a major leap forward in attack surface reduc...
Grant duration (access period override)
Users are assigned a default "grant period" (in minutes), either within Knocknoc for local users,...
Allowlist/EDL access
Allowlists or External Dynamic Lists (EDLs) served from Knocknoc require an API key for access, i...
Manage user sessions
User sessions can be terminated using the API. This is handy for integration with revocation syst...
LOOTOTL - Last One Out Turn Off The Lights
Knocknoc keeps a track of the IPs and tries to be kind to users that share IPs. This means that i...
Additional client IP addresses
Capturing additional client IP addresses A client may exhibit behaviour where multiple IP addres...
AWS WAF Ipset
Below is a concise guide for a sysadmin (or developer) to set up and configure AWS WAF with a cus...
Apache Webserver
Apache 2.4 and above have slightly different ACL syntax, so this page covers how you can use Knoc...
Nginx
Nginx support via script was added in knocknoc-agent version 1.0.30. This allows for flexible ACL...
Mikrotik RouterOS
The scripting backend can be used for MikroTik RouterOS config updates as well. Here is a sample ...
Allowlist (EDLs)
The Allowlist backend makes a list of active IP address grants available via the Knocknoc server ...
SAML
SAML is an in-depth topic, however it represents the best option for securing users, and providin...
SAML with CyberArk
CyberArk integrates with Knocknoc via the "Web Apps" component, passing through SAML assertions. ...
Debugging & log levels
Things go wrong from time to time, the best way to understand more detail is to increase the log ...
Cisco (SFMC/Firepower)
The Cisco Secure Firewall Management Console (formerly known as Firepower) integration allows Kn...
Microsoft Entra
Overview This integration is designed to manage named locations in Microsoft Azure Conditional A...
FortiOS, FortiProxy, Palo Alto, or SSL VPN
Protect your existing Fortigate or Palo assets from direct internet or internal exposure by intro...
Juniper SRX
Passive, Active or a combination Passive - Knocknoc's Allowlist features provides a passive inte...
SAML with OKTA
The following example assumes your Knocknoc instance is located at https://demo.knoc.cloud. Where...
Firewall Manager access (IT MSP)
An IT managed services provider maintained multiple Fortinet firewalls on behalf of customers, of...