Advanced Search
Search Results
53 total results found
Knocknoc Reverse Proxy
The Knocknoc orchestration Agent - which is deployed alongside managed infrastructure (not on desktops) - can be converted to an in-line reverse proxy, providing access control at layer-7 (HTTP/HTTPs) or layer-3 for TCP, linked to Knocknoc. This allows the cen...
High availability
A Knocknoc deployment has three parts: the Server (web app), its Database (PostgreSQL), and one or more Orchestration Agents. How you run the first two decides your availability. The Agents are resilient by design (see below). One thing makes Knocknoc forgivin...
SonicWall
The SonicWall can be orchestrated in three ways, Actively (API call from an Orchestration Agent to the Firewall), Passively via SonicWalls DEAG polling capability, or a combination known as Passive+, where a DEAG is used with an active force-download-now call ...
Windows Firewall
Microsoft Windows comes equipped with a built-in native firewall which Knocknoc orchestrates to provide just-in-time network access control, effectively removing always-on attack surface for your Windows Servers. Ports and services like RDP become invisible, p...
Windows Servers
Windows Servers and RDP/WinRM - removing pre-auth attack surface A mid-sized business uses RDP and WinRM to manage a Windows fleet of servers, however wasn't comfortable with always-on network exposure of these ports/protocols - even to internal management net...
Break Glass
Default deny is a wonderful thing, the best place to be - except when you lock yourself out. Thankfully Knocknoc has a break-glass control if you need. Follow these steps to add a 20 minute access path, it requires Admin access. Log in to your Admin cons...
Cloudflare IP lists
Knocknoc can orchestrate Cloudflare IP lists to provide dynamic IP network allowlisting inbound to Cloudflare, should you use this to protect web or other assets. These IP lists are managed at the Account level, allowing use across the Cloudflare filtering ser...
v26.01
Knocknoc 26.01 Knocknoc 26.01 sharpens the Palo Alto experience for both administrators and end-users, introducing a much simpler configuration option and stronger safeguards. It also adds Cloudflare support, improves multi-node deployments, and delivers broa...
Channels and Beta
If you're after the very latest features or changes, and you know what you're doing - below is how to change from the main release channel, to the Beta channel. This does mean you're running Beta code, YMMV, and while you can move from Beta back to Main, it's ...
Backups
Like all technology, backing up configuration files and data is paramount, in the case of Knocknoc the Server and Agent locations to capture are found below. Server Data resides in two locations; disk and database. For Linux, the default installation locati...
v26.02
Knocknoc 26.02 Knocknoc 26.02 is a platform-expansion release with a security spine: we’ve pushed deep into legacy UNIX, added new firewall + cloud backends, and strengthened the agent identity + grant verification model - all while making the UI feel sharper,...
v26.03
Knocknoc 26.03 Knocknoc 26.03 is a major usability-and-operations release focused on making day-to-day access clearer and easier to understand - for both end-users requesting access and administrators running the platform. A far stronger operational experience...
v26.04
Knocknoc 26.04 Knocknoc 26.04.1 is a size-optimized release focused on expanding deployment flexibility, improving firewall and cloud integration options, refining installation workflows, and shipping some small bug fixes. This release introduces Google GCP or...
1Kosmos
Configure 1Kosmos as a SAML identity provider (IdP) for Knocknoc. Once connected, your users authenticate against 1Kosmos — including its biometric and passwordless factors — and Knocknoc maps their group membership to access entitlements. This example assumes...
Ping Identity
Ping Identity SSO Configure PingOne as a SAML identity provider (IdP) for Knocknoc. Users authenticate against Ping, and Knocknoc maps their group membership to access entitlements. This example assumes your Knocknoc instance is at https://<tenant>.knoc.cloud....
Firewalld
IPsets with firewalld On RHEL-family hosts — and any distribution that uses firewalld as its firewall front-end — Knocknoc does not talk to firewalld directly. As with the main IPSet backend, Knocknoc orchestrates the kernel's native IPSets, and firewalld simp...
F5 Networks
Knocknoc can orchestrate F5 Networks BigIP and related devices via two mechanisms, including iRules "Data group List" and the AFM. Typically iRules are used as they can be deployed across both high-end F5 devices and lower/smaller deployments. The iRules can r...