Back to articles
Technology Insight

Network Layer Security: How to Configure Single Packet Authorization (SPA) with fwknop on Linux VPS

June 3, 2026

Introduction to Modern Network Layer Security

In the contemporary digital landscape, securing a Virtual Private Server (VPS) goes far beyond setting strong passwords or changing the default SSH port. As automated bots and malicious actors continuously scan the global IPv4 and IPv6 address spaces, leaving any management port open to the public internet introduces unnecessary risk. Traditional firewalls act as barriers, but they still acknowledge connections, revealing the existence of a service. To achieve true network stealth, enterprise security architects are turning to Single Packet Authorization (SPA).

This comprehensive guide will demonstrate how to implement cutting-edge network layer security by configuring SPA using fwknop (FireWall Knock Operator) on a Linux VPS. By the end of this article, your management ports will remain entirely closed to unauthorized scanners, opening dynamically only for authenticated cryptographic packets.

The Evolution: From Port Knocking to Single Packet Authorization (SPA)

Before diving into the configuration, it is essential to understand why traditional Port Knocking has been superseded by SPA. While both techniques aim to keep ports closed until requested, their underlying mechanisms and security profiles differ drastically.

The Limitations of Legacy Port Knocking

Traditional port knocking relies on a sequence of connection attempts to predefined, closed ports (e.g., knocking on port 1000, then 2000, then 3000). A daemon monitoring the firewall logs detects this specific sequence and opens the target service port (like SSH port 22).

  • Susceptibility to Replay Attacks: An attacker monitoring network traffic can capture the sequence of connection attempts and replay them to gain unauthorized access.
  • Network Overhead and Latency: Sending multiple TCP SYN packets takes time and can be disrupted by network congestion or out-of-order packet delivery.
  • Port Scanning Visibility: Simple port knocking sequences can sometimes be guessed or accidentally triggered by full-spectrum port scanners.

The SPA Advantage

Single Packet Authorization solves these structural flaws by condensing the authentication process into a single, heavily encrypted packet. Typically sent over UDP, this packet contains encrypted data including a timestamp, cryptographic digest, and the requested access parameters.

Key Benefit: Because the packet is encrypted using symmetric or asymmetric keys (such as GnuPG), an attacker sniffing the network sees only a single, non-descript UDP packet that looks like background noise. Without the correct decryption key, it is impossible to replay, manipulate, or even identify as an authorization request.

Anatomy of an fwknop Deployment

The open-source utility fwknop is the industry standard for implementing SPA. It utilizes Netfilter/iptables or nftables on Linux to maintain a default-drop stance for incoming connections, manipulating firewall rules in real-time only when a valid SPA packet is verified.

The deployment consists of two primary components:

  1. The fwknop Client: Generates and transmits the encrypted SPA packet to the destination VPS.
  2. The fwknop Daemon (fwknopd): Runs silently on the VPS, sniffing raw network packets via libpcap before they hit the firewall application layer. If a valid packet is detected, it temporarily modifies the firewall to allow the client's specific IP address.

Step-by-Step Guide: Configuring fwknop on a Linux VPS

Let us walk through a complete deployment scenario. For this guide, we assume a server running Ubuntu or Debian Linux, though the concepts translate seamlessly to RHEL or Rocky Linux enterprise distributions.

Step 1: Prerequisites and Initial Firewall Setup

Before installing fwknop, we must ensure the firewall is configured to block SSH connections by default. We will use iptables for this demonstration.

# Drop all incoming SSH traffic by default
sudo iptables -A INPUT -p tcp --dport 22 -j DROP

# Allow established and related connections
sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

At this stage, if you disconnect your current SSH session without an active SPA setup, you will be locked out. Ensure you maintain your current session open or have out-of-band console access via your VPS provider.

Step 2: Installing fwknop on Server and Client

Install the necessary packages on both machines. On the Linux VPS server:

sudo apt update
sudo apt install fwknop-server

On your local administration machine (the client), install the client utility:

sudo apt install fwknop-client

Step 3: Generating Cryptographic Keys

SPA requires strong keys to encrypt the authorization payload. We will utilize symmetric encryption keys generated by the fwknop client utility on your local machine:

fwknop --key-gen

This command outputs two vital strings: the KEY_BASE64 (encryption key) and the HMAC_KEY_BASE64 (identity verification key). Copy these values safely; they must match exactly on both the client and server.

Step 4: Configuring the Server Daemon

On your Linux VPS, edit the primary configuration files located in /etc/fwknop/.

First, open /etc/fwknop/access.conf to define who can access the system and define their cryptographic credentials:

SOURCE: ANY
REQUIRE_SOURCE_ADDRESS: Y
KEY_BASE64: [Insert your generated KEY_BASE64 here]
HMAC_KEY_BASE64: [Insert your generated HMAC_KEY_BASE64 here]
FW_ACCESS_TIMEOUT: 30
RESTRICT_PORTS: tcp/22

Next, configure the global daemon settings in /etc/fwknop/fwknopd.conf. Ensure the daemon listens to the correct public network interface (e.g., eth0 or ens3):

PCAP_INTF: eth0
ENABLE_IPT_FORWARDING: N

Start and enable the fwknopd service to ensure it runs automatically on system boot:

sudo systemctl restart fwknop-server
sudo systemctl enable fwknop-server

Step 5: Testing Client Authorization

On your local machine, you can now send the single packet required to open the SSH port. Replace YOUR_VPS_IP with your actual server IP address:

fwknop -A tcp/22 -D YOUR_VPS_IP --named-config vps_auth

Alternatively, you can pass the keys directly or save them into your local ~/.fwknoprc file for simplified execution. Once executed, fwknopd on the server intercepts the UDP packet (default port 62201), validates the HMAC, decrypts the payload, verifies the timestamp to prevent replay attacks, and injects a temporary iptables rule:

sudo iptables -I INPUT 1 -s YOUR_CLIENT_IP -p tcp --dport 22 -j ACCEPT

You now have exactly 30 seconds (as defined by FW_ACCESS_TIMEOUT) to establish your SSH connection. Once established, the state tracking engine ensures your connection remains active even after fwknopd removes the temporary rule from the firewall hierarchy.

Enterprise Best Practices for SPA Deployments

To maximize the efficacy of your network layer security architecture, consider implementing these production-grade strategies:

  • Asymmetric Encryption (GnuPG): For high-security environments, switch from symmetric keys to GPG key pairs. This adds another layer of mathematical complexity and non-repudiation.
  • Custom UDP Ports: Change the default SPA listening port from 62201 to an uncommon or high-numbered port within fwknopd.conf to completely evade naive automated scanners.
  • Multi-Factor Authentication Compatibility: Use SPA as a gatekeeper to hide the service, but keep your underlying standard SSH security controls active, such as SSH keys combined with Time-based One-Time Passwords (TOTP).

Conclusion

By implementing Single Packet Authorization via fwknop, you successfully shift your security strategy from reactive defense to complete network invisibility. Port scanners will see your VPS as entirely dark, with no indicators that an SSH daemon is running. This defense-in-depth practice minimizes your attack surface, thwarts zero-day exploits targeting the SSH protocol, and provides a robust foundation for secure infrastructure management.

Network Layer Security: How to Configure Single Packet Authorization (SPA) with fwknop on Linux VPS | DPTCloud