From Free Software Directory
Jump to: navigation, search


Adds an additional layer of security to services such as SSH

'fwknop' implements an authorization scheme that requires only a single encrypted packet to communicate various pieces of information, including desired access through a Netfilter policy and/or specific commands to execute on the target system. Its main use is to protect services such as SSH with an additional layer of security, which makies exploitation of vulnerabilities much more difficult. The authorization server works by passively monitoring authorization packets via libpcap.


User manpage available in HTML format from http://www.cipherdyne.org/projects/fwknop/docs.html


Download version 2.6.9 (stable)
released on 8 June 2016


Related Projects


LicenseVerified byVerified onNotes
License:GPLv2Janet Casey29 July 2005

Leaders and contributors

Michael Rash Maintainer
See the CREDITS file in the distribution for a complete list Contributor

Resources and communication

AudienceResource typeURI
DeveloperVCS Repository Webviewhttp://www.cipherdyne.org/cgi/viewcvs.cgi/fwknop/
Bug Tracking,Developer,SupportE-mailmailto:mbr@cipherdyne.org

Software prerequisites

This entry (in part or in whole) was last reviewed on 26 February 2017.


Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.3 or any later version published by the Free Software Foundation; with no Invariant Sections, no Front-Cover Texts, and no Back-Cover Texts. A copy of the license is included in the page “GNU Free Documentation License”.

The copyright and license notices on this page only apply to the text on this page. Any software or copyright-licenses or other similar notices described in this text has its own copyright notice and license, which can usually be found in the distribution or license text itself.