Back to articles
Technology Insight

Invisible Infrastructure: Mastering Single Packet Authorization (SPA) with Fwknop for VPS Security

May 27, 2026

Introduction: The Vulnerability of Visibility

In the modern digital landscape, visibility is a liability. Every server connected to the public internet is under constant surveillance by automated bots, script kiddies, and sophisticated threat actors. Traditionally, securing a Virtual Private Server (VPS) involved closing unused ports and using tools like Fail2Ban to mitigate brute-force attacks on open services like SSH. However, even with these measures, the port remains 'Open' or 'Filtered,' signaling its existence to anyone with an IP scanner like Nmap.

Enter Single Packet Authorization (SPA). This advanced cryptographic technique allows you to close all ports on your firewall—including SSH—while maintaining the ability to access them. By using the Fwknop (FireWall Knock Operator) suite, you can render your server effectively invisible to the outside world. This blog post provides a professional, technical deep dive into configuring SPA to achieve 'default-drop' perfection.

What is Single Packet Authorization (SPA)?

To understand SPA, we must first distinguish it from its predecessor: Port Knocking. Traditional port knocking requires a specific sequence of connection attempts to closed ports (e.g., hitting port 1000, then 2000, then 3000) to trigger a firewall rule change. This method is susceptible to replay attacks and packet inspection.

SPA improves upon this by using a single, non-replayable, encrypted packet to communicate authorization. The packet is sent over UDP (typically) and contains an encrypted payload that includes the requester's intent and a timestamp. Because the firewall drops all packets by default, the Fwknop daemon monitors the raw packet stream via libpcap. If it detects a valid SPA packet, it dynamically modifies the iptables or nftables rules to allow the sender's IP address for a brief window.

The Benefits of Fwknop

  • Zero Visibility: IP scanners show 0 open ports.
  • Asymmetric Encryption: Uses GnuPG or Rijndael for high-level security.
  • Replay Prevention: Each packet contains a unique SHA-256 digest and timestamp.
  • Reduced Attack Surface: Eliminates vulnerabilities in the SSH daemon (SSHD) from being exploitable by unauthenticated users.

Prerequisites for Configuration

Before proceeding with the installation, ensure your environment meets the following criteria:

  • A VPS running a Linux distribution (Ubuntu 22.04 or Debian 12 recommended).
  • Root or sudo privileges.
  • A client machine (your local laptop) to send the SPA packets.
  • Basic familiarity with the command line and firewall management.

Step 1: Installing Fwknop on the Server

The first step is to install the server-side daemon. On Ubuntu/Debian systems, use the following commands:

sudo apt update
sudo apt install fwknop-server

Once installed, we must configure the daemon to listen to the correct network interface. Open the main configuration file:

sudo nano /etc/fwknop/fwknopd.conf

Locate the PCAP_INTF variable and set it to your server's public interface (e.g., eth0 or ens3). Ensure the ENABLE_IPT_FORWARDING is set appropriately if you intend to use SPA for NAT traversal, though for a standard VPS, the defaults are usually sufficient.

Step 2: Defining Access Rules (access.conf)

The /etc/fwknop/access.conf file is where the 'magic' happens. This file defines who can access the server and what keys are required. For a professional setup, we recommend using GnuPG (GPG) keys, but for this guide, we will demonstrate the Rijndael (AES) symmetric key approach for clarity.

Warning: In a production environment, always prefer GPG keys to prevent the risks associated with shared secrets.

Add the following block to your access.conf:

SOURCE: ANY
REQUIRE_SOURCE_ADDRESS: Y
KEY_ASCII: YourSecurePassword123
FW_ACCESS_TIMEOUT: 30
ENABLE_OPMSG_GPC: Y

This configuration tells the server: "Allow any source to send an SPA packet, but only grant access to the specific IP that sent it. The access window remains open for 30 seconds to allow the SSH connection to establish."

Step 3: Hardening the Firewall

Now, we must configure the firewall to drop all incoming traffic. This is the stage where the server becomes 'invisible.' Using iptables, execute the following:

sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 22 -j DROP
sudo iptables -P INPUT DROP

At this point, your SSH connection may drop if you haven't permitted your current IP. Always ensure you have out-of-band console access via your VPS provider (like VNC) before locking down the firewall.

Step 4: Client-Side Configuration and Testing

On your local machine, install the fwknop-client. You will then generate the SPA packet to 'knock' on your server's door:

fwknop -A tcp/22 -D [Your_VPS_IP] --access-key YourSecurePassword123

If successful, the Fwknop daemon on the server will detect the packet, verify the signature, and execute a command similar to:
"iptables -I INPUT 1 -s [Your_Local_IP] -p tcp --dport 22 -j ACCEPT"

You now have 30 seconds to initiate your SSH connection:

ssh user@your_vps_ip

Best Practices for Enterprise Security

While the basic setup provides immense security, enterprise-grade deployments should consider the following enhancements:

  1. Use GPG Keys: Asymmetric encryption ensures that even if the server is compromised, the attacker cannot forge authorization packets for other users.
  2. Change the Default UDP Port: By default, Fwknop listens on UDP port 62201. Change this in fwknopd.conf to a non-standard port to further obfuscate the service.
  3. Monitor Logs: Regularly check /var/log/syslog for SPA authorization attempts. Fwknop provides detailed logging for both successful and failed attempts.
  4. Automated Scripts: Create a local alias or shell script that combines the SPA knock and the SSH command for a seamless user experience.

Conclusion

Implementing Single Packet Authorization with Fwknop represents a paradigm shift in server security. By moving from a "Permit then Filter" model to a "Drop then Authorize" model, you effectively remove your infrastructure from the public eye. In an era where zero-day vulnerabilities in common services are frequently exploited, being invisible is the ultimate defense. Obscurity, when paired with robust cryptography, is a powerful layer in a defense-in-depth strategy.

Invisible Infrastructure: Mastering Single Packet Authorization (SPA) with Fwknop for VPS Security | DPTCloud