Skip to main content

Welcome to the PortGuard Documentation Site

The purpose of this site is to help more people understand Single Packet Authorization (SPA) and provide actionable solutions for implementing it with PortGuard and fwknop-compatible workflows.

What is PortGuard?​

PortGuard is a fwknop-compatible SPA solution for hiding service ports until an authorised packet is received.

PortGuard has two parts:

  • PortGuard Client: a cross-platform client that supports the fwknop SPA protocol and sends compatible authorisation packets to fwknopd or PortGuard Server.
  • PortGuard Server: a server component/distribution modified from the upstream fwknop project, with PortGuard-specific packaging and workflow improvements.

The compatibility foundation is fwknop. PortGuard keeps the familiar SPA model, keys, access definitions, and QR/config workflow while making daily operation easier for desktop and mobile users. You can find the PortGuard source code on GitHub.

Background on fwknop​

fwknop is an open-source port knocking system that implements Single Packet Authorization (SPA) to secure network services. Unlike traditional port knocking, which relies on a sequence of packets, fwknop uses a single encrypted, non-replayable packet authenticated via HMAC to dynamically open firewall ports for authorised clients. This approach hides services from port scanners (e.g., Nmap) and protects against unauthorised access, including zero-day exploits and brute-force attacks. fwknop supports multiple firewalls (iptables, firewalld, PF, and ipfw) across Linux, OpenBSD, FreeBSD, and macOS, and integrates with tools like libpcap for passive packet sniffing.

Why Choose PortGuard?​

  • fwknop protocol compatibility: PortGuard Client sends fwknop-compatible SPA packets, so existing fwknop concepts remain usable.
  • Modified fwknop-based server: PortGuard Server is based on upstream fwknop with PortGuard-specific changes.
  • Hide service ports: Services remain closed by default and only open temporarily after authorisation.
  • Cross-platform client: PortGuard Client supports Windows, macOS, iOS, Android, and related desktop/mobile workflows.
  • Encryption and authentication: SPA packets use encryption, HMAC, and timestamp validation to resist replay and tampering.

What You Will Learn​

On this site, you will learn the following:

  1. PortGuard deployment process: Step-by-step instructions for installing and configuring PortGuard Server or fwknop-compatible server workflows.
  2. PortGuard Client operation: How to import .fwknoprc/QR configuration and send fwknop-compatible SPA packets.
  3. SPA implementation principles: A practical view of encryption, HMAC authentication, timestamp validation, and packet transmission.
  4. PortGuard use cases: Protect SSH, NAS, VPN, admin panels, and cloud services by keeping ports hidden until authorisation.
  5. Advantages over traditional port knocking: Learn why single-packet authorization is safer and faster than sequence-based knocking.
  6. Tool Introduction: Discover cross-platform GUI tools that make fwknop-compatible SPA easier to use.

Who Should Use PortGuard?​

  • System Administrators: Protect servers from unauthorised access.
  • Network Security Engineers: Enhance network security and prevent port scanning and brute-force attacks.
  • Developers and DevOps: Ensure service security during development and operations.
  • Individual Users: Anyone with a need for network security.

Where can I find the different platform GUI client?​

To find the GUI client for different platforms, navigate to the GUI Tools section of this documentation site. This section provides detailed information and download links for PortGuard Client on Windows, macOS, iOS, and Android.

Getting Started with PortGuard​

If you're new to fwknop or SPA, start with the Deployment Guide to learn how to install and configure the server side. If you're already familiar with fwknop, you can jump directly to Use Cases or the PortGuard Client tools.

Ready to get started?
Click here to check out the PortGuard deployment guide.