7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

fwknop

Open source

Single Packet Authorization tool that hides services such as SSH behind a default-drop firewall until a client sends an encrypted, authenticated packet.

cipherdyne.org
fwknop homepage screenshot
GitHub stars
1.5k
Last commit
4 mo ago
Repository age
15 years
Version
2.6.11
Licence
GPL-2.0
Self-hosted
Yes

About fwknop

fwknop implements Single Packet Authorization (SPA), a way to conceal network services so that they are invisible until an authorized client asks for access. A single encrypted, non-replayable packet authenticated with an HMAC tells the server to open a firewall rule for that client. Services such as SSH stay behind a default-drop firewall, which makes exploitation of both unknown and unpatched vulnerabilities harder and means the services cannot be found by port scanners such as Nmap.

The README presents SPA as the next generation of port knocking. Port knocking struggles with replay attacks, cannot easily use asymmetric ciphers or HMACs, and can be disrupted by spoofed packets, while SPA addresses these problems and still keeps the default-drop policy. The server acquires SPA data passively, usually through libpcap, and uses standard cryptographic operations to authenticate and decrypt packets.

The project supports four firewalls, iptables, firewalld, PF and ipfw, across Linux, OpenBSD, FreeBSD and macOS, and custom scripts allow other infrastructure such as ipset or nftables. It is released under GPL-2.0 and runs entirely on your own systems, so it suits administrators who want a zero-trust layer in front of remote-access services.

Key features

  • Single Packet Authorization for service concealment
  • Encrypted, non-replayable, HMAC-authenticated packets
  • Works with iptables, firewalld, PF and ipfw
  • Supports Linux, BSD and macOS
  • Passive packet capture via libpcap
  • Custom scripts for ipset and nftables

Good fit for

  • →Hiding SSH from internet scans
  • →Adding a zero-trust access gate to remote services
Built with
Perl
Tags
firewall
spa
port-knocking
zero-trust
ssh
authentication
network-security
hmac

fwknop: questions and answers

What is fwknop used for?
fwknop is a single Packet Authorization tool that hides services such as SSH behind a default-drop firewall until a client sends an encrypted, authenticated packet. It is a good fit for hiding SSH from internet scans and adding a zero-trust access gate to remote services.
Is fwknop open source?
Yes. fwknop is open source under the GPL-2.0 licence. Its source code is on GitHub at mrash/fwknop and is written mainly in Perl.
Is fwknop free?
Yes. fwknop is open source, so the software itself is free to use.
Can I self-host fwknop?
Yes. fwknop can be self-hosted on your own server or infrastructure; there is no official hosted version.
What are some alternatives to fwknop?
Similar open-source tools in the Security category include fail2ban, pfSense and ModSecurity. SaaS products in the same category include Cato Networks, Check Point and Fortinet.
Is fwknop actively maintained?
The most recent commit to fwknop was on 1 June 2026, and the latest release is 2.6.11, published on 7 February 2024. The project has 1.5k stars on GitHub.

Open-source alternatives to fwknop

See all

SaaS alternatives to fwknop

See all