Advanced Search
Search Results
402 total results found
Updates and upgrades
The Knocknoc software is managed by your operating system, as such updates can be managed within your patching cycle and complete control. These are applied by utilizing your relevant package management system, as below. On Debian / Ubuntu and similar variant...
Cisco (SFMC/Firepower)
The Cisco Secure Firewall Management Console (formerly known as Firepower) integration allows Knocknoc to dynamically add and remove users' source IP from a named address group. This address group can then be used in whatever Firewall rule you like, opening u...
Grant and revoke process
What triggers a grant or revoke The granting and revoking of access by Knocknoc occurs on a number of events, including: User login Interactive 'click to grant' activity Interactive 'click to revoke' activity User login/session timeout Grant timeout (device/ba...
Debugging & log levels
Things go wrong from time to time, the best way to understand more detail is to increase the log level verbosity. LogLevels can be set as "error" "warn" "info" "debug" "trace", increasing in verbosity. LogLevel = "info" # this is the default #LogLevel = "de...
v7.6
Knocknoc 7.6 Knocknoc 7.6 continues the theme of user-experience improvements, this time for end users. But don't be fooled, there's other goodies in here for you. Don't miss the Palo Alto enhancements - we now leverage the powerful Palo Alto User-ID feature y...
Microsoft Azure NSG
Overview This integration allows for IP addresses to be dynamically managed within Azure Network Security Groups (NSGs), which are used by default as the inner firewalls protecting virtual machines. Other Azure assets (PaaS etc) are managed using separate Knoc...
SaaS deployment
Knocknoc can host and operate your server as a managed cloud instance. Use the Instances page to provision it, monitor its status, and open its admin portal. Create a managed cloud instance Sign in to the Knocknoc licensing portal. Open Instances. If this is y...
User authentication
User sessions can be created using the API. This is handy for machine to machine authentication, and is where knocknoc-client authentication requests are also configured. As an Admin, create a local user, selecting API Key as the authentication method: Visit t...
Manage user sessions
Invalidating sessions from the admin portal You can sign users or admins out in bulk from the admin portal: On the Identities > Users page, Invalidate user sessions signs out every user immediately. They must authenticate again to regain access, and admin sess...
Allowlist/EDL access
Allowlists or External Dynamic Lists (EDLs) served from Knocknoc require a secret for access, along with the specific EDL URI. These secrets are automatically created when a Passive integration is established, but can be edited or expanded. As an Admin, visit ...
Agent registration
API keys can be created to allow just-in-time orchestration Agent registration, which is suitable for infrastructure-as-code or pipeline deployments whereby the Admin doesn't want to create an Agent registration key prior to deployment and registration. As an ...
Grant duration
Users are assigned a default "grant period" (in minutes), either within Knocknoc for local users, or passed as a SAML attribute through "sessionDuration". These can be overridden per-Knoc, allowing certain access paths to have shorter periods if so desired. F...
v8.0
Knocknoc 8.0 Knocknoc 8.0 delivers a powerful set of updates, enhancing validation on connecting clients beyond just source IP addresses through the introduction of Knocknoc Access Tokens for web transactions. Additionally, fine-grained per-Knoc session limits...
Knocknoc client (scriptable login)
To gain access to underlying networks and systems, end-users log in to Knocknoc interactively via the Server component. This provides registered orchestration-Agents information to perform ongoing access provisioning. If you need to script access in a non-int...
HAProxy + KAT
Sometimes IP address restrictions or IP-based allowlisting is not enough, think: airport lounge, CGNat or other large, untrusted NAT environments. That's why Knocknoc extends a reverse-proxy in an innovative way through the addition of Knocknoc Access Tokens. ...
VPNs, internal addresses and access
You may want to limit the ability to access a Knoc, depending on where your user is logging in to Knocknoc from. For example, an internal subnet should only be opened up if the user is connecting from an internal IP address range, or if they are connected to ...
v8.5
Knocknoc 8.5 Knocknoc 8.5 delivers key improvements in usability, integrations, and security, while paving the way for future growth. Security is enhanced through updated server components, Golang and library upgrades, and additional hardening measures, incl...
Redirecting Users
Knocknoc supports a couple of ways to redirect users to and from Knocknoc, which can be useful for when you want users to get where they're trying to go ASAP. Redirecting to a Referrer URL This is the most basic way to redirect users to a custom URL from the K...