Advanced Search
Search Results
11 total results found
User Guide
Welcome to the Knocknoc User Guide. This will cover basic operations including logging in, logging out and troubleshooting. If you're looking for information on installing or administering Knocknoc, please check out the Admin Guide. Logging into Knocknoc Knock...
Server installation (on premise)
On a Linux host as Root, execute the below command to setup and install your Knocknoc server. You will be stepped through the process. The installer runs on Debian, Ubuntu, Redhat, Oracle and Amazon Linux. sudo curl -sSL https://packages.knocknoc.io/setup/setu...
Agent installation
The Orchestration Agent runs on a server to control network access for users on their behalf. This is not an end-user install. It operates in three modes In-line firewall orchestration. Eg: Palo Alto, Fortinet, Check Point, Azure NSG, AWS SG/WAF, Cloudflare, ....
HAProxy
HAProxy is a fantastic reverse proxy with a massive amount of features. Knocknoc has supported HAProxy for years, and integrates with it natively. HAProxy can be a little confusing at first due to its wide array of options and implementations, but for now we'l...
AWS (EC2) Security Groups
Knocknoc can orchestrate Amazon AWS Security Groups, which essentially provide network level firewalling across various asset types, including EC2 VMs, meaning just-in-time network exposure (and access) for authenticated users, tied to your IDP not to AWS IAM ...
Custom Script
The "Custom Script" Knoc type is simply a script the agent can execute directly on the Agent machine. Linux and macOS agents run shell scripts; from Knocknoc 26.06, Windows agents can also run scripts, executing them as PowerShell ( .ps1) scripts. Note: For se...
IPSet (Linux Netfilter/IPTables)
Linux comes equipped with a built-in native firewall which Knocknoc orchestrates via "IPSets". IPSets are a powerful and highly efficient way of making a dynamic firewall on a normal Linux machine. A native feature of the Netfilter code, an IPset is an in-memo...
v6.0
We're excited to announce the release of Knocknoc 6, a major leap forward in attack surface reduction, implemented at speed. This release brings a host of new features and improvements that make Knocknoc even more efficient, user-friendly, and adaptable within...
Allowlist (EDLs)
The Allowlist backend makes a list of active IP address grants available via the Knocknoc server API. This allows integration with appliances or clients that can be configured to poll a URL without the need for a Knocknoc agent to be deployed. This is sometime...
Keycloak
Keycloak supports multiple authentication realms, so you must first select the appropriate realm for your organization. Do not make any of the below changes in the Keycloak/master realm. In this example our realm is called "Acme" and Keycloak is hosted at http...
BYO PostgreSQL
Knocknoc server v8.5+ installs with a local installation of PostgreSQL by default. However, you may bring your own PostgreSQL instance (such as AWS RDS, Azure Database for PostgreSQL or a local cluster) by choosing to enter an alternate database connection str...