Skip to main content

Port Knocking and SPA for Hidden SSH Access

Security · 29.09.2026

Why hide the SSH port from scanners

Bots scan the entire IPv4 range several times a day looking for an open port 22 and immediately start guessing passwords. Fail2ban and changing the port reduce the number of hits in the logs, but they do not remove the port from scan results — the service still answers the SYN packet and hands out the SSH version banner. Port knocking and Single Packet Authorization (SPA) solve a different problem: the port does not respond at all until the client sends the correct sequence.

This is not a replacement for passwords and keys but an extra layer: even if an attacker has a valid key, without knowing the sequence they cannot reach sshd.

How classic port knocking works

The idea is simple: the client sends packets to closed ports in a set order, for example TCP 7000, 8000, 9000. A firewall daemon watches these packets through logs or a raw socket and, on seeing the correct sequence within a limited time, temporarily opens the needed port for the sender's IP address.

The downside of the classic approach is that the sequence is easy to capture with a sniffer on an open network, and replaying it will open the port for the attacker. That is why modern deployments use SPA — a version with a cryptographic packet signature instead of a bare port sequence.

Installing knockd: basic port knocking

sudo apt install knockd

Configuration in /etc/knockd.conf:

[openSSH]
    sequence    = 7000,8000,9000
    seq_timeout = 5
    command     = /sbin/iptables -A INPUT -s %IP% -p tcp --dport 22 -j ACCEPT
    tcpflags    = syn

[closeSSH]
    sequence    = 9000,8000,7000
    seq_timeout = 5
    command     = /sbin/iptables -D INPUT -s %IP% -p tcp --dport 22 -j ACCEPT
    tcpflags    = syn

Port 22 in the baseline iptables rules should be closed by default — knockd only temporarily adds an allow rule for the IP that sent the correct sequence.

fwknop: Single Packet Authorization

SPA transmits all the information in one encrypted UDP packet instead of a series of connections, which removes the risk of the sequence being captured. The packet carries a timestamp and a one-time identifier — resending the same packet is rejected.

sudo apt install fwknop-server fwknop-client

On the server, /etc/fwknop/access.conf sets the access key and the allowed action:

SOURCE: ANY
OPEN_PORTS: tcp/22
KEY_BASE64: generated_base64_key
FW_ACCESS_TIMEOUT: 30

The client sends the packet and gets access for 30 seconds to establish an SSH session:

fwknop -A tcp/22 -a $(curl -s ifconfig.me) -D vps.example.com

Limitations of the approach

Port knocking and SPA do not protect against an attack on the firewall rule itself and do not remove the need for strong SSH authentication. If the server sits behind NAT with a shared external IP for several users, opening the port for one client will temporarily open it for everyone behind that IP. If the fwknop client key is lost, the server key must be reissued manually and redistributed.

For cloud servers with frequent infrastructure rebuilds, it is simpler to use a VPN — for example WireGuard — and close the SSH port to everyone except the VPN subnet.

Rollout checklist

  • The SSH port is closed in the firewall by default, and access opens only through knockd or fwknop.
  • SPA (fwknop) is used instead of a bare port sequence whenever the network could be sniffed.
  • The open-access timeout does not exceed 30-60 seconds.
  • Port knocking supplements, not replaces, SSH keys, disabled password login, and fail2ban.
  • Keys and sequences are stored outside the repository and known only to trusted administrators.
← Back to Knowledge Base Ask Support