Back to articles
Technology Insight

Ultimate SSH Security: How Single Packet Authorization (SPA) and fwknop Stop Port Scanning Entirely

June 2, 2026

Introduction: The Vulnerability of the Open Port

In the modern enterprise infrastructure landscape, Secure Shell (SSH) is the standard for remote server management. However, relying on standard SSH configurations introduces a fundamental security paradox: to accept legitimate connections, the SSH port (typically port 22) must remain open to the public internet. This open gateway continuously attracts malicious actors, automated bots, and relentless port scanners probing for vulnerabilities.

Traditional defense mechanisms, such as changing the default port or deploying Fail2ban, offer only reactive protection. They mitigate the frequency of brute-force attempts but do not hide the service itself. A determined attacker can still discover the open port via advanced scanning tools like Nmap, analyze the SSH banner to finger-print the operating system, and exploit potential zero-day vulnerabilities. To achieve absolute resilience, organizations must adopt a Zero-Trust Network Access (ZTNA) posture where services are completely invisible until authenticated. This is precisely what Single Packet Authorization (SPA) via the open-source tool fwknop achieves.

Understanding Single Packet Authorization (SPA)

Single Packet Authorization represents the next evolution of Port Knocking. While traditional port knocking requires a sequential sequence of connection attempts to multiple closed ports to trigger a firewall rule, it suffers from severe limitations. Traditional port knocking is slow, easily monitored via packet sniffers, and susceptible to replay attacks.SPA solves these vulnerabilities by utilizing a single, heavily encrypted, and authenticated packet to grant access. When a user wishes to connect to an SSH server protected by SPA, the client machine generates a single UDP (or sometimes TCP/ICMP) packet containing an encrypted payload. This payload includes:

  • A timestamp to prevent replay attacks.
  • A cryptographic digest (HMAC) to ensure data integrity and authenticity.
  • The specific IP address requesting access.
  • The desired destination service and port.

The server running the SPA daemon (fwknopd) constantly monitors the network interface at the packet filter level (using libpcap) without actually binding to an open socket. When it intercepts a valid SPA packet, it decrypts the payload, verifies the credentials, and dynamically alters the local firewall rules (such as iptables, nftables, or firewalld) to temporarily allow connections from the client's specific IP address. To the rest of the internet, the port remains entirely closed and unresponsive.

The Architecture of fwknop (FireWall Knock Operator)

The most robust and widely trusted implementation of SPA is fwknop (FireWall Knock Operator). Built on the principle of default-drop firewall policies, fwknop utilizes asymmetric or symmetric encryption (Rijndael or GnuPG) combined with HMAC-SHA256 authentication to secure authorization messages.

Key Architectural Components:

  1. The Client (fwknop-client): Installed on the administrator's local machine. It generates the encrypted SPA packet and transmits it to the destination server immediately before initiating the SSH handshake.
  2. The Packet Sniffer (libpcap): The fwknop daemon does not open a listening socket on the server. Instead, it utilizes libpcap to passively inspect raw incoming network frames. This means an Nmap scan will see the port as filtered or closed, as there is no active network stack listener to respond.
  3. The Daemon (fwknopd): Runs on the target server. It processes intercepted packets, validates them against strict cryptographic criteria, and interacts directly with the netfilter/iptables subsystem to create ephemeral access rules.
"By combining passive packet inspection with strong cryptography, fwknop ensures that your SSH gateway becomes completely invisible to unauthorized entities, effectively neutralizing targeting phases of modern cyber attacks."

Why SPA Outperforms Traditional SSH Defense

To fully appreciate the value of Single Packet Authorization, it is essential to contrast it with standard defense-in-depth measures utilized by system administrators:

Security MetricStandard SSH + Fail2banTraditional Port Knockingfwknop (SPA)
Port VisibilityVisible (Open)Closed (Opens during sequence)Always Closed/Filtered
Replay Attack ResistanceNot ApplicableVulnerableAbsolute (Timestamped & Signed)
Protocol OverheadLowHigh (Requires multiple connection attempts)Minimal (Single Packet)
Cryptographic SecurityHigh (At handshake phase)None (Simple port sequences)Excellent (AES or GnuPG + HMAC)

As illustrated, fwknop provides a superior security abstraction layer. It ensures that the cryptographic verification phase occurs before any TCP handshake with the SSH daemon can take place. Even if an unauthenticated user discovers a critical remote code execution (RCE) flaw in OpenSSH, they cannot exploit it because they cannot route a single TCP packet to the service.

Step-by-Step Implementation Strategy

Deploying fwknop across an enterprise environment involves a systematic configuration of both the server daemon and the administrative clients. Below is an architectural blueprint for implementation:

1. Establishing the Default-Drop Policy

The fundamental prerequisite for fwknop is a strict firewall policy. The server must be configured to drop all unsolicited traffic to port 22. Only loopback traffic and already established connections should be permitted initially.

2. Configuring the Server Daemon (fwknopd)

The configuration resides within two primary files: fwknopd.conf (global settings) and access.conf (user-specific access definitions). In access.conf, administrators define the encryption keys, HMAC keys, permitted source networks, and the maximum lifespan of the dynamically generated firewall rule (typically 30 seconds, allowing ample time for the SSH session to establish before the window closes).

3. Client-Side Orchestration

On the management workstation, keys are stored securely within the local configuration. Initiating a connection becomes a streamlined two-step workflow, often aliased into a single command sequence:

fwknop -n server_profile && ssh user@server_ip

The first command dispatches the encrypted UDP packet. The server instantly processes the packet and inserts a kernel-level rule allowing the client's IP. The subsequent SSH command connects seamlessly, after which the server immediately tears down the rule while retaining the active state tracking of the established SSH tunnel.

Conclusion: Embracing Invisible Infrastructure

Relying on obfuscation or reactive IP blocking is no longer sufficient in an era characterized by automated, ubiquitous threat landscapes. By implementing Single Packet Authorization via fwknop, you transform your infrastructure from a visible target into an invisible citadel. Port scanners pass over your servers without detecting a sign of life, brute-force logs drop to zero, and the attack surface of your SSH daemon is mitigated entirely. Transitioning to an SPA-protected paradigm is one of the most impactful, mathematically verifiable security upgrades an enterprise can deploy to protect its critical access gateways.

Ultimate SSH Security: How Single Packet Authorization (SPA) and fwknop Stop Port Scanning Entirely | DPTCloud