Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

102 total results found

HAProxy + KAT

Admin Guide Knocs (backends)

Sometimes IP address restrictions or IP-based allowlisting is not enough, think: airport lounge, CGNat or other large, untrusted NAT environments. That's why Knocknoc extends a reverse-proxy in an innovative way through the addition of Knocknoc Access Tokens. ...

FortiManager

Admin Guide Knocs (backends)

The FortiManager is used to manage multiple Fortinet devices, including Fortigate firewalls, APs, switches and more. Utilizing Knocknoc with FortiManager local-in access controls can be applied, limiting exposure to Admin login source addresses dynamically. T...

VPNs, internal addresses and access

Admin Guide Access

You may want to limit the ability to access a Knoc, depending on where your user is logging in to Knocknoc from.  For example, an internal subnet should only be opened up if the user is connecting from an internal IP address range, or if they are connected to...

v8.5

Changelog and Roadmap

Knocknoc 8.5   Knocknoc 8.5 delivers key improvements in usability, integrations, and security, while paving the way for future growth. Security is enhanced through updated server components, Golang and library upgrades, and additional hardening measures, inc...

Auto-browse Knocs

Admin Guide Access

The auto-browse option available within the Knoc configuration, automatically forwards the user after successful login, to the Knoc should it be the only Knoc they have available to them. This can streamline the users login experience, and depending on the pr...

New Page

Admin Guide Setup guides

BYO PostgreSQL

Admin Guide Setup guides

Knocknoc server v8.5+ installs with a local installation of PostgreSQL by default. However, you may bring your own PostgreSQL instance (such as AWS RDS, Azure Database for PostgreSQL or a local cluster) by choosing to enter an alternate database connection str...

Sophos (UTM)

Admin Guide Knocs (backends)

The Sophos UTM device provides firewall and UTM capabilities. Note that this series of devices are being EOL'd by Sophos in favour of the SFOS devices (June 2026), which can also be integrated with Knocknoc following this guide. UTM Configuration Firstly c...

Sophos (SFOS/XGS)

Admin Guide Knocs (backends)

The Sophos SFOS/XGS based devices provide advance firewall and UTM capabilities. This replaces the previous UTM devices, which can be integrated here. Knocknoc manages IP addresses within a host-group, it does not edit/change firewall policies, and operates w...

Agent as a Reverse Proxy

Admin Guide Setup guides

The orchestration agent can be configured to reverse-proxy traffic, simply by enabling this mode and completing a few configuration options, you'll be on your way to controlling HTTPs or TCP attack surface, without an additional firewall or other layer beyond ...

Package Repository Key expired

Admin Guide Troubleshooting

Debian distros (Ubuntu etc) If you are getting the this error: Failed to fetch https://packages.knocknoc.io/debian/dists/bookworm/InRelease The following signatures were invalid: EXPKEYSIG E3AB5DF76BBF701F Knocknoc Support <support@knocknoc.io> You may ha...

v25.12

Changelog and Roadmap

Knocknoc 25.12 Knocknoc 25.12 is a Windows-first release focused on making Just-In-Time (JIT) access easier to deploy and operate across Windows environments. The headline upgrade is the Windows Agent now managing the local Windows Firewall for true on-host n...

Knocknoc Reverse Proxy

Admin Guide Knocs (backends)

The Knocknoc orchestration Agent - which is deployed alongside managed infrastructure (not on desktops) - can be converted to an in-line reverse proxy, providing access control at layer-7 (HTTP/HTTPs) or layer-3 for TCP, linked to Knocknoc. This allows the ce...

High availability

Admin Guide Setup guides

The Knocknoc Server can be deployed in various ways to match your high-availability needs and deployment models. Ultimately the Knocknoc solution comprises of these three components: Server Database Orchestration Agent(s) The Server (web-app) can be d...

Moving from SQLite to PostgreSQL

Admin Guide Maintenance

If you installed Knocknoc Server before version 8.5 (September 2025), your instance is likely using a local SQLite database. The Knocknoc Server now uses PostgreSQL as its primary database. This guide explains how to use the "knocker convertdb" tool, which is ...

Sonicwall

Admin Guide Knocs (backends)

The Sonicwall can be orchestrated in three ways, Actively (API call from an Orchestration Agent to the Firewall), Passively via Sonicwalls DEAG polling capability, or a combination known as Passive+, where a DEAG is utilized with an active force-download-now c...

Windows Firewall

Admin Guide Knocs (backends)

Microsoft Windows comes equipped with a built-in native firewall which Knocknoc orchestrates to provide just-in-time network access control, effectively removing always-on attack surface for your Windows Servers. Ports and services like RDP become invisible, p...

Windows Servers

Admin Guide Use cases

Windows Servers and RDP/WinRM - removing pre-auth attack surface A mid-sized business utilizes RDP and WinRM to manage a Windows fleet of servers, however wasn't comfortable with always-on network exposure of these ports/protocols - even to internal managemen...

Linux Agent Installation

Admin Guide Setup guides

On a Linux host as Root, execute the below command to setup and install a Knocknoc Agent. You will be stepped through the process. curl -sSL https://packages.knocknoc.io/setup/setup_knocknoc_agent.sh | bash The installer runs on Debian, Ubuntu, Redhat, Oracl...

Windows Agent Installation

Admin Guide Setup guides

On a Windows machine as an Admin, download and install the Orchestration Agent. It will install as a service by default. You then provide token information to connect to your Knocknoc Server for centralized management.  This is not installed by end users for ...