[options] logfile = /var/log/knockd.log # interface = eth-intel interface = eth-realtek [SSH] sequence = 52966,14256,22827,17238,45857,31846,45236,14444,29713,1305 seq_timeout = 20 start_command = /usr/bin/ufw allow from %IP% to any port 22 tcpflags = syn stop_command = /usr/bin/ufw delete allow from %IP% to any port 22 [Nginx] sequence = 32596,33256,1123 seq_timeout = 30 start_command = /usr/bin/ufw allow from %IP% to any port 1935 tcpflags = syn stop_command = /usr/bin/ufw delete allow from %IP% to any port 1935