Back to articles
Technology Insight

Implementing Zero-Trust VPS Security: A Deep Dive into Single Packet Authorization (SPA) with fwknop

May 26, 2026

Introduction to Modern VPS Vulnerabilities

In the current cybersecurity landscape, traditional network defense mechanisms are increasingly proving inadequate. For years, securing a Virtual Private Server (VPS) relied heavily on perimeter defenses: changing default ports, enforcing strong SSH keys, and deploying rate-limiting tools like Fail2ban. While these practices are still valuable, they leave a fundamental vulnerability unaddressed—the port remains open to the internet.

An open port, such as port 22 for SSH, invites constant reconnaissance. Malicious actors utilize automated bots to scan the entire IPv4 address space continuously. Even if your authentication is robust, an open port exposes your system to zero-day vulnerabilities within the SSH daemon itself and generates massive amounts of log clutter. To eliminate this attack surface, enterprise security has shifted toward a Zero-Trust Architecture (ZTA), operating on a simple principle: never trust, always verify. This blog post explores how to achieve a Zero-Trust state for your VPS using Single Packet Authorization (SPA) via the open-source utility fwknop (FireWall KeNOPen).

Understanding Single Packet Authorization (SPA)

Before diving into the technical implementation, it is crucial to understand what Single Packet Authorization is and how it differs from older technologies like Port Knocking.

Traditional Port Knocking requires a client to send a specific sequence of connection attempts to closed ports (e.g., knocking on port 1000, then 2000, then 3000). The firewall monitors these logs and opens the target port when the correct sequence is detected. However, this method is highly vulnerable to replay attacks and packet sniffing, as an attacker observing the network traffic can easily replicate the sequence.

Single Packet Authorization (SPA) solves these inherent flaws. Instead of a sequence of connections, SPA relies on a single, heavily encrypted, and authenticated packet sent via UDP (or occasionally TCP/ICMP). This packet contains encrypted metadata, including:

  • The identity of the requesting client.
  • A timestamp to prevent replay attacks.
  • The specific port access being requested.
  • A cryptographic signature or HMAC for integrity verification.

When the fwknop daemon (fwknopd) running on the VPS receives this packet, it decrypts and verifies it. If valid, the daemon dynamically alters the system's firewall rules (iptables, nftables, or UFW) to allow the client's specific IP address access to the requested port for a limited window of time. To the rest of the world, the port remains completely closed and invisible.

The Architecture of an fwknop Deployment

An fwknop deployment consists of two primary components operating in a non-traditional client-server model:

  1. The Client (fwknop): Runs on your local administration machine. It generates, encrypts, and transmits the SPA packet before you attempt to establish a standard SSH connection.
  2. The Daemon (fwknopd): Runs on the VPS. It acts as a passive network sniffer, utilizing libpcap to inspect incoming traffic without actively listening on a standard socket. This means fwknopd does not show up on a standard port scan, maintaining a zero-visibility profile.
Note on Zero-Trust: By utilizing fwknop, your VPS achieves default-drop status. All unsolicited packets are discarded immediately. Your server effectively disappears from the public internet, rendering automated port scanners completely ineffective.

Step-by-Step Implementation Guide

This guide demonstrates how to configure fwknop on a Debian/Ubuntu-based VPS utilizing UFW (Uncomplicated Firewall) or standard iptables. We assume you already have SSH access configured on the server.

Step 1: Install fwknop on the Server and Client

First, update your package repositories and install the required components. On your VPS server, execute the following commands:

sudo apt update
sudo apt install fwknop-server iptables

Next, install the fwknop client software on your local workstation. If you are using a Debian/Ubuntu-based local machine, run:

sudo apt install fwknop-client

For macOS users, the client can be easily installed via Homebrew:

brew install fwknop

Step 2: Generate Cryptographic Keys

SPA relies on robust encryption to secure authorization packets. You can use either symmetric pre-shared keys (PSK) or asymmetric keys (GnuPG). For the scope of this guide, we will use symmetric keys combined with an HMAC (Hash-based Message Authentication Code) for enhanced security against modification.

On your local client machine, generate the required keys by running the following command:

fwknop --key-gen

The output will resemble the following structure:

KEY_BASE64: dGhpcyBpcyBhIHNhbXBsZSBrZXkgZm9yIGRlbW9uc3RyYXRpb24=
HMAC_KEY_BASE64: bW9yZSBzYW1wbGUgaG1hYyBrZXlzIGZvciBzZWN1cml0eQ==

Keep these strings secure. You will need to copy them to both your client configuration file and the server configuration file.

Step 3: Configure the fwknop Daemon on the VPS

With the keys generated, log back into your VPS to configure the daemon. The primary configuration files are located within the /etc/fwknop/ directory.

First, edit the main configuration file /etc/fwknop/fwknopd.conf to specify which network interface fwknopd should monitor. Find the PCAP_INTF directive and set it to your public network interface (e.g., eth0 or enp1s0):

PCAP_INTF    eth0;

Next, configure the access permissions and keys in /etc/fwknop/access.conf. Append or modify the following block at the bottom of the file, replacing the placeholder keys with the exact strings generated in Step 2:

SOURCE              ANY
REQUIRE_SOURCE_ADDRESS  Y
KEY_BASE64          dGhpcyBpcyBhIHNhbXBsZSBrZXkgZm9yIGRlbW9uc3RyYXRpb24=
HMAC_KEY_BASE64     bW9yZSBzYW1wbGUgaG1hYyBrZXlzIGZvciBzZWN1cml0eQ==
OPEN_PORTS          tcp/22
FW_ACCESS_TIMEOUT   30

In this configuration, FW_ACCESS_TIMEOUT 30 dictates that once an authentic SPA packet is verified, the firewall will open port 22 to the client's IP address for exactly 30 seconds. This is ample time for the client to initiate an SSH connection. Once established, the firewall closes the port again, but existing active connections are preserved.

Step 4: Restrict SSH Access at the Firewall Level

To see fwknop in action, you must now configure your system firewall to deny all standard incoming SSH traffic by default. If you are using UFW, execute the following commands:

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw delete allow 22/tcp
sudo ufw enable

Warning: Do not close your current SSH session yet. Keep it open as a lifeline in case you made a configuration error, and open a new terminal window on your local machine to test the configuration.

Step 5: Configure the Local Client and Test Connection

On your local machine, define your VPS target profile within the ~/.fwknoprc file for ease of use. Open or create the file and add the following configuration:

[my_vps]
ALLOW_ANONYMOUS_SOURCE  Y
ACCESS                  tcp/22
SPA_SERVER              your_vps_public_ip
KEY_BASE64              dGhpcyBpcyBhIHNhbXBsZSBrZXkgZm9yIGRlbW9uc3RyYXRpb24=
HMAC_KEY_BASE64         bW9yZSBzYW1wbGUgaG1hYyBrZXlzIGZvciBzZWN1cml0eQ==

Now, test the complete Zero-Trust implementation. If you attempt to connect via SSH directly without an SPA packet, the connection should completely time out:

ssh user@your_vps_public_ip
# Result: Connection timed out

To successfully connect, issue the SPA packet first using the client runtime configuration profile name defined in your .fwknoprc, then initiate your SSH session:

fwknop -n my_vps
ssh user@your_vps_public_ip

The first command transmits an encrypted UDP packet to port 62201 (the default SPA port). The daemon detects it, dynamically alters the netfilter rules to allow your specific external IP, and allows the subsequent SSH command to succeed seamlessly.

Conclusion and Best Practices

Implementing Single Packet Authorization via fwknop elevates your VPS security posture to an enterprise-grade Zero-Trust level. By ensuring that your management ports remain invisible to unauthorized scanners, you effectively eliminate entire classes of automated cyber threats. As you maintain this configuration, ensure you adhere to these long-term best practices:

  • Automate Client Execution: Use SSH configuration aliases (e.g., the ProxyCommand or LocalCommand directives in ~/.ssh/config) to trigger fwknop automatically whenever you run the standard ssh command.
  • Monitor Server Logs: Regularly check /var/log/syslog or use journalctl -u fwknop-server on your VPS to audit successfully authenticated access events.
  • Implement Redundant Keys: Maintain secure backups of your deployment keys and configurations in a secure password manager to prevent accidental lockouts.
Implementing Zero-Trust VPS Security: A Deep Dive into Single Packet Authorization (SPA) with fwknop | DPTCloud