knockd: Port-Knocking Daemon for Linux

knockd is a lightweight port-knocking daemon for Linux. It listens to network traffic and looks for a predefined sequence of connection attempts, known as a port-knocking sequence. When the expected sequence is received from a client, knockd can execute a configured command or action.

Port knocking is a technique designed to provide an additional layer of access control for network services. Instead of leaving a service such as SSH openly accessible through the firewall, an administrator can configure the firewall to keep the service inaccessible until the correct sequence of network packets is detected.

The basic idea is similar to a secret knock on a door. The server does not normally respond to the protected service, but a client that knows the correct sequence can send the required network requests. knockd recognizes the sequence and performs the configured action.

Understanding Port Knocking

Port knocking is a method of communicating a simple authentication signal through network traffic.

A server might be configured with a sequence such as:

7000 → 8000 → 9000

A client that wants to gain temporary access sends connection attempts to those ports in the correct order. The ports do not necessarily have to host actual services. Instead, knockd observes the attempts and uses them as signals.

Once the complete sequence is detected, knockd can run a command.

For example, an administrator could configure it to add a firewall rule allowing the client’s IP address to access SSH. A reverse sequence could subsequently remove that rule and close access again.

The important point is that the port sequence itself is not the protected service. It is a trigger that tells knockd to perform a predefined action.

How knockd Works

The operation of knockd can be understood as a sequence of steps.

1. knockd Starts Listening

The daemon runs on a Linux system and monitors network traffic through a specified network interface.

2. A Client Sends Network Attempts

A client sends connection attempts to the ports specified in the server’s configuration.

The client does not necessarily need to establish successful connections. The relevant packets themselves can be detected by knockd.

3. knockd Compares the Sequence

The daemon compares the incoming traffic against the sequence configured in its configuration file.

A sequence might contain several ports and can also have a time limit in which the complete sequence must be received.

4. The Sequence Is Validated

If the expected ports arrive in the correct order within the configured timeout, knockd considers the sequence successful.

If the sequence is incorrect or takes too long, the attempt can fail and the expected sequence must be started again.

5. A Command Is Executed

After a successful knock, knockd can execute a predefined command.

That command can interact with a firewall, service, script, or another system component.

This is what makes knockd more than simply a packet monitor: it connects the detection of a network sequence to an administrator-defined action.

knockd Configuration

The primary configuration file is commonly /etc/knockd.conf on Linux systems.

The configuration defines options and one or more knock sequences.

A conceptual configuration might specify:

  • The network interface to monitor
  • The expected port sequence
  • The amount of time allowed for the sequence
  • Packet or TCP flag requirements
  • The command to execute
  • An optional command for closing access
  • Command execution timeouts

A typical configuration might use a sequence such as 7000,8000,9000 and specify a firewall command to permit access from the IP address that successfully completed the sequence. Examples of this configuration pattern are documented in Linux port-knocking guides.

The actual values should be selected by the system administrator according to the network environment.

Opening a Protected Service

One of the most common uses for knockd is protecting SSH.

SSH is a powerful remote-administration service. If it is exposed directly to the public internet, it can be discovered by automated scanning and become a target for password attacks and other unwanted connection attempts.

With port knocking, an administrator can configure the firewall so that SSH is inaccessible until the correct sequence has been received.

For example, the conceptual workflow is:

Client → knock sequence → knockd → firewall rule → SSH access

After successful authentication using the knock sequence, the firewall can temporarily permit SSH access for the client’s source IP address.

The access can later be removed through another configured sequence or an automatic timeout.

Opening and Closing Sequences

knockd can be configured with separate sequences for opening and closing access.

For example, an administrator might define one sequence to activate SSH access and another sequence in reverse order to remove it.

A simplified concept could be:

Open: 7000 → 8000 → 9000

Close: 9000 → 8000 → 7000

The commands associated with those sequences can add and remove the corresponding firewall rule.

This arrangement provides a simple mechanism for temporarily changing network access without manually modifying firewall rules every time remote access is required.

Sequence Timeouts

Timing is an important part of port knocking.

A configuration can specify a sequence timeout, which determines how long the client has to complete the required sequence.

For example, if the configured timeout is 15 seconds, the client must send the expected sequence within that period.

A timeout prevents a partially completed sequence from remaining valid indefinitely.

The precise timeout should be selected according to the network conditions and the desired security model. A sequence that takes too long to complete may be inconvenient, while an extremely short timeout can make legitimate connections unreliable.

TCP Flags

knockd can also use packet characteristics such as TCP flags when determining whether a network event matches the configured sequence.

For example, configurations commonly specify the SYN flag when looking for TCP connection attempts.

This allows the administrator to make the detection criteria more specific rather than simply reacting to any type of traffic involving a particular port.

Firewall Integration

knockd does not have to be responsible for the entire access-control system itself.

One of its most useful characteristics is its ability to execute commands after detecting a successful sequence. Those commands can interact with firewall systems such as iptables or UFW, depending on the Linux distribution and configuration.

For example, a successful sequence could cause a firewall rule to allow TCP traffic to port 22 from the source IP that performed the knock.

After the access period ends, another command can remove that rule.

This creates a separation between two functions:

knockd: Detects the authentication sequence.

Firewall: Determines whether the protected service is actually accessible.

Client-Side Port Knocking

A client needs a way to send the correct sequence.

The knockd software package commonly includes a knock client, which can be used to send a series of port requests to a remote server.

A conceptual command looks like:

knock server 7000 8000 9000

After receiving the sequence, the server’s knockd daemon can perform the configured action.

The client can then connect to the newly accessible service.

For example, the overall workflow might be:

  1. Send the knock sequence.
  2. Wait for the server’s firewall rule to become active.
  3. Connect to the protected service.
  4. Finish the session.
  5. Send a closing sequence if one is configured.

This approach can be particularly convenient for administrators who regularly access systems remotely.

Advantages of knockd

Port knocking offers several potential benefits.

Reduced Visibility

A protected service can remain inaccessible to ordinary connection attempts until the correct sequence has been received.

This can reduce exposure to automated scans and opportunistic attacks.

Temporary Access

Administrators can configure access to open only when needed.

This is particularly useful for services that do not need to be publicly accessible all the time.

Lightweight Design

knockd is a relatively focused daemon rather than a large security platform. Its core purpose is simply to detect port-knocking sequences and trigger configured commands.

Firewall Compatibility

Because successful sequences can trigger firewall commands, knockd can work alongside existing network access-control mechanisms.

Automation

The command-based configuration makes it possible to integrate port knocking with custom scripts and administrative workflows.

Limitations and Security Considerations

Port knocking should not be treated as a replacement for proper authentication or a complete network-security strategy.

A fixed port sequence can potentially be observed by an attacker who can monitor the relevant network traffic. If the sequence is discovered, knowing it may allow the attacker to reproduce the same knock.

For this reason, port knocking is better understood as an additional access-control layer, rather than a substitute for strong authentication.

For SSH, administrators should still use appropriate security practices such as strong authentication, preferably cryptographic keys where appropriate, sensible firewall rules, and timely security updates.

A security guide describing knockd similarly characterizes port knocking as an additional layer rather than a replacement for strong authentication.

Port Knocking and Port Scanning

One of the primary motivations for port knocking is to reduce the visibility of protected services during ordinary scanning.

If SSH is normally blocked by the firewall, a conventional scan may not reveal that the service is available behind the firewall.

Only after the correct sequence has been received does the firewall temporarily permit the authorized source IP to connect.

This does not make the server invisible in an absolute sense. Port knocking should therefore not be confused with complete network anonymity or a guarantee that a service cannot be discovered.

Alternative Approaches

Port knocking is one of several techniques that can be used to control access to network services.

Modern environments may instead use:

  • VPNs
  • WireGuard
  • Tailscale
  • IP allowlists
  • Bastion hosts
  • Zero-trust access systems
  • Multi-factor authentication
  • Firewall policies

For some networks, these approaches may provide stronger or more manageable access control.

The appropriate choice depends on the environment, threat model, administrative requirements, and services being protected.

knockd in Modern Linux Administration

Although network-security practices have evolved considerably, knockd remains an interesting example of a lightweight Linux security tool.

It demonstrates an unusual but effective concept: using apparently ordinary network traffic as an authentication signal.

Instead of providing a web interface or separate authentication protocol, the daemon watches for a sequence of network events. Once the correct pattern appears, it can trigger an action defined by the administrator.

This simplicity has helped make port knocking a recognizable technique in Linux system administration and network security.

The knockd package continues to be available in Linux-related software repositories; for example, current Termux package listings identify knockd as a port-knocking daemon.

Conclusion

knockd is a Linux port-knocking daemon that listens for predefined sequences of network connection attempts and executes configured commands when those sequences are detected.

Its most common conceptual application is protecting services such as SSH. A firewall can keep the service inaccessible, while knockd watches for a secret sequence of network events. When the correct sequence arrives within the configured time, knockd can execute a command that temporarily permits access.

The technology is lightweight and flexible, but it should be considered an additional security mechanism rather than a replacement for strong authentication, firewalls, VPNs, or modern access-control systems.

For Linux administrators interested in controlling when network services become reachable, knockd provides a distinctive approach: access is activated by the correct sequence of network “knocks.”