summaryrefslogtreecommitdiffstats
path: root/network/knock/README
blob: c439f9ced42847faef081e1500a6da0764750411 (plain)
1
2
3
4
5
6
7
8
9
Knockd and knock are a port-knock server and client,
respectively. Knockd listens to all traffic on an ethernet (or PPP)
interface, looking for special "knock" sequences of port-hits. A
client makes these port-hits by sending a TCP (or UDP) packet to a
port on the server. This port need not be open -- since knockd listens
at the link-layer level, it sees all traffic even if it's destined
for a closed port. When the server detects a specific sequence of
port-hits, it runs a command defined in its configuration file. This
can be used to open up holes in a firewall for quick access.