Advanced Search
Search Results
302 total results found
Allowlist (EDLs)
The Allowlist backend makes a list of active IP address grants available via the Knocknoc server API. This allows integration with appliances or clients that can be configured to poll a URL without the need for a Knocknoc agent to be deployed. This is sometime...
ADFS
The following example assumes your Knocknoc instance is located at https://your-knocknoc.cloud/. Wherever you see that, please substitute it for your own instance URL. Knocknoc SAML config Log in to the Knocknoc admin interface (e.g., https://your-knocknoc.c...
Keycloak
Keycloak supports multiple authentication realms, so you must first select the appropriate realm for your organization. Do not make any of the below changes in the Keycloak/master realm. In this example our realm is called "Acme" and Keycloak is hosted at http...
v7.5
Knocknoc 7.5 🚀 Knocknoc 7.5 marks a major milestone in our journey to redefine secure network access. This release is a comprehensive redesign of the user experience, delivering a streamlined, intuitive interface that empowers both administrators and end use...
CyberArk
CyberArk integrates with Knocknoc via the "Web Apps" component, passing through SAML assertions. Knocknoc SAML config Log in to the Knocknoc Admin interface On the Settings page configure the PublicURL (e.g., https://knocknoc.yourserver.com) Create and uploa...
How Knocknoc removes attack surface
Knocknoc enables you to remove the attack surface of systems, by enacting just-in-time network/application-based allow-listing. It can operate in a number of ways - from orchestrating network access controls (e.g., adding to firewall rules - while presenting n...
Juniper SRX
Passive, Active or a combination Passive - Knocknoc's Allowlist feature provides a passive integration with firewalls that support External Dynamic Lists (EDLs). This feature allows the firewall to pull from the Knocknoc server a list of IPs of authenticated ...
Knocker - a cli helper
The Knocker utility is a command-line tool for managing various backends or server features with ease. It provides commands for enabling, disabling, installing, uninstalling, and performing health checks for supported backends. Usage (on Agent) /opt/knocknoc-a...
Additional client IP addresses
Capturing additional client IP addresses A client may exhibit behavior where multiple IP addresses are observed as part of the authentication request. Situations such as: Internal IP addresses (e.g., 10.0.x.x / RFC1918), should the Server (or MYIP component) b...
Authentik
In this example our authentik instance is hosted at https://auth.example.com/ and is running version 2026.2.1 Our Knocknoc instance is a cloud instance with URL https://authentiktest.knoc.cloud. If you are using a cloud server, replace with your own URL, or if...
New Page
AWS WAF Ipset
Below is a concise guide for a sysadmin (or developer) to set up and configure AWS WAF with a custom HTML 403 response and integrate it with your update-aws-waf-ipset.sh script (which follows the argument order <ACTION> <ACL_NAME_OR_ID> <IP_ADDRESS>). This gui...
LOOTOTL - Last One Out Turn Off The Lights
Knocknoc keeps a track of source IP addresses and tries to be kind to users that share IPs. Think: shared office IP NAT address when using an internet-hosted Knocknoc. This means that if two users are coming from the same IP, revoking a session for the first u...
Logging
Logging is important - we love logging. Because of this, we have included an easy to find, follow and parse log output that provides an additional layer of visibility across your Knocknoc user activity, including logins, access grants, manual interactions, as ...
VPN and ransomware
Use case: Removing VPN ransomware risk from stolen credentials A mid-size business relied on internet-exposed VPN appliances to provide extranet access for staff, contractors, and business partners. Due to legacy constraints, some external users still used sin...
High security subnets and JIT network access
Use case: Dynamic just-in-time IP restrictions for high-security subnet A critical infrastructure environment needed to restrict access to specific high-security internal networks to trusted IP addresses dynamically, allowing access only for short-lived perio...
Financial services data partner, secure web upload
Use case: Trusted partners secure access to web application A financial services provider relied on periodic uploads through an internet-exposed web application. Although the application was actively maintained, it posed substantial value and risk to the organ...
Firewall Manager access (IT MSP)
An IT managed services provider maintained multiple Fortinet firewalls on behalf of customers, often responding to urgent service desk requests requiring 24/7 access. These firewalls were deployed across various locations and managed by multiple members of the...