PortGuard: Keep Your Services Invisible to Scanners
PortGuard combines a modified fwknop-based server with a cross-platform client that supports the fwknop SPA protocol. Ports stay closed by default and open temporarily only after a valid AES/GPG-signed packet is verified.
Quick Server Install
Installs the latest open-source package built by GitHub Actions from the PortGuard server repository.
curl -fsSL https://portguard.net/install.sh | sudo bash
Traditional Exposure Mode (Risk)
- ✕Ports remain open all day and are continuously probed by global scanners.
- ✕Exposed services face brute-force attempts and exploit attacks directly.
- ✕Firewall allowlists become complex to maintain and lack dynamic flexibility.
PortGuard Mode (Solution)
- ✓Default Deny: Ports are completely invisible before authorization (stealth).
- ✓SPA Auth: Only specially formatted encrypted single packets can trigger access.
- ✓Dynamic Access: Temporarily allow only the source IP, then close automatically.
Core Features
Core Security Features
Strong defaults for teams that want SSH, admin panels, and private services to disappear until authorization is intentional.
Efficient SPA Communication
Send fwknop-compatible single-packet authorization without TCP handshake overhead, with strong stealth.
AES/GPG + HMAC
Integrated SHA256 integrity checks ensure commands are authentic and untampered.
Full Port Stealth
Default DROP behavior makes services appear unreachable to scanners.
Replay Attack Resistance
Time-window validation plus integrity checks quickly invalidates old packets.
Výukový program PortGuardu
A cleaner fwknop-compatible client for every device.
PortGuard Client supports the fwknop SPA protocol. Profiles, one-tap SPA, QR import, encrypted export, and activation stay compatible with fwknopd and PortGuard Server workflows.
How It Works
Security Workflow
PortGuard runs at the firewall edge of protected servers. It continuously inspects network traffic for authorization packets without exposing service handshakes externally.
Generate Authorization Packet
The client uses keys and a timestamp to generate an encrypted single packet.
Handshake-less Delivery
The packet is sent via UDP and similar methods, making handshake-based probing ineffective.
Dynamic Open
After validation, the server temporarily allows the source IP and then automatically removes the rule.
Use Cases
SSH Remote Operations
Protect port 22 and make it visible only briefly after an admin sends SPA.
Multi-Cloud Security
Unified access control across AWS/Azure and more to reduce exposure.
IoT Device Management
Protect IoT control interfaces and avoid direct public exposure.
ACL Automation
Combine scripts and rule cycles to automate temporary authorization.
Downloads and Installation
Supports multi-platform clients and server-side packages
Server Packages
Install PortGuard Server on Debian, Ubuntu, Rocky, CentOS, and OpenWrt
Use the quick installer for supported Linux servers, or download the latest package generated from the open-source GitHub Actions release pipeline.
Quick Install
One command server setup
curl -fsSL https://portguard.net/install.sh | sudo bash
The script detects the operating system, selects the matching package from the GitHub release manifest, verifies SHA256, installs dependencies, and leaves fwknopd ready for configuration export to PortGuard Client.
Open Source Release
Packages synced from GitHub
These packages are built automatically by GitHub Actions from the public PortGuard server source code.
| System | Version | Architecture | Package | Stiahnuť |
|---|---|---|---|---|
| Loading packages from GitHub release... | ||||
Related Products
Product
OpenAT
Secure, time-locked data storage powered by drand's mathematical certainty. Encrypt your future today without a central authority.
Visit website
Product
Lockmem
End-to-end encrypted personal media vault for your NAS. Privacy-first management for your self-hosted infrastructure.
Visit websiteFAQ i przypadki użycia
Ostatnia aktualizacja:
What is the relationship between PortGuard and fwknop?
PortGuard is built around the fwknop SPA protocol. PortGuard Client is a cross-platform client that sends fwknop-compatible SPA packets, while PortGuard Server is a modified server based on the upstream fwknop project. Compared with traditional sequence-based port knocking, this single encrypted packet model is faster, stealthier, and resistant to replay attacks.
Môžem vygenerovať jeden profil a pomocou jedného klepnutia povoliť konkrétnej IP prístup ku každému portu služby?
áno. Nakonfigurujte sekciu prístupu na server pomocou OPEN_PORTS ANY a použite profil klienta so ACCESS ANY. Profil je možné vygenerovať a importovať raz a potom znova použiť. Každé platné zaklopanie vytvorí dočasné pravidlo zdrojovej IP, ktoré umožní IP vybratej ALLOW_IP dosiahnuť všetky servisné porty TCP a UDP, kým nevyprší platnosť FW_TIMEOUT. Po uplynutí platnosti pošlite nový ťuk. Toto je režim s vysokými právami: použite krátky časový limit, chráňte profil a kľúče a pamätajte, že stále platia upstream cloudové firewally, pravidlá smerovača a overovanie služby.
Jak fwknop wypada w porównaniu z tnock?
Oba narzędzia ukrywają porty sieciowe, ale fwknop to bardziej zaawansowane SPA. tnock i podobne demony sekwencyjne wykrywają określony wzorzec prób połączeń na wielu zamkniętych portach, co trwa dłużej i jest podatne na replay. fwknop rozwiązuje to, wysyłając pojedynczy kryptograficznie podpisany ładunek ze znacznikiem czasu. Zalety: wyraźnie wyższe bezpieczeństwo, odporność na replay i płynna integracja z nowoczesnymi firewallami.
Jak sprawić, aby moja strona lub usługa prywatna była dostępna tylko dla konkretnych osób?
By default, PortGuard Server, modified from fwknop, configures your server's firewall to block all inbound traffic to your service port. The service appears completely offline to the public. When an authorized user needs access, they use PortGuard Client with their unique cryptographic key to send a fwknop-compatible Single Packet Authorization (SPA) packet. Once verified, the server dynamically whitelists their current IP address for a brief period.
Jak zapewnić bezpieczeństwo i prywatność NAS wystawionego do sieci publicznej bez wycieku danych?
Bezpośrednie wystawienie NAS do Internetu jest bardzo ryzykowne z powodu ciągłych prób botnetów i skanerów. Zwykle są dwa bezpieczne rozwiązania:
- Plan 1: Cloudflare Zero Trust (Tunnels) Ruch NAS przechodzi przez sieć Cloudflare bez otwierania portów przychodzących. Plusy: bardzo łatwa konfiguracja, brak wymogu publicznego IP, dodatkowa warstwa WAF. Minusy: ruch przechodzi przez stronę trzecią, więc zależysz od polityki prywatności Cloudflare; prędkości często ogranicza routing planu darmowego, co nie jest idealne do streamingu dużych mediów.
- Plan 2: Własne publiczne IP + fwknop Port Knocking Otwierasz port na routerze, ale chronisz go przez fwknop (SPA). Port pozostaje niewidoczny w publicznym Internecie i otwiera się tylko po wysłaniu poprawnego kryptograficznie podpisanego pakietu dostępowego. Plusy: maksymalna prywatność danych bez stron trzecich i najwyższe prędkości sprzętowe dzięki połączeniu bezpośredniemu (świetne do wideo). Minusy: wymagany prawdziwy publiczny IP i nieco bardziej techniczna konfiguracja startowa.
Czy fwknop PortGuard spowalnia połączenie po otwarciu portu?
No. The fwknop-compatible PortGuard Server only handles the initial authorization packet. Once the firewall rule is dynamically created and your IP is authorized, your connection via SSH, WireGuard, or directly to your NAS operates directly between your client and the server at full line speed.
Trusted by DevOps and Security Experts Worldwide
Official Contact
Need help with PortGuard?
For purchase recovery, activation issues, deployment questions, or security reports, contact the official PortGuard support mailbox.
[email protected]