Skip to content

fn-knockOne secure gateway for your HomeLab

Put your NAS, photo library, download stack, and self-hosted apps behind one gateway. Authenticate first, then connect—directly over a public IP or through FRP and Cloudflare Tunnel when you are behind CGNAT.

fn-knock

First-time setup

Bring one service online in this order. Verify the complete path before onboarding the rest of your stack:

  1. Choose fnOS, Docker, OpenWrt, Linux, Synology DSM, or Windows and complete the installation.
  2. Match the access pattern to your home network: route subdomains over a public IP, or use FRP / Cloudflare Tunnel for NAT traversal.
  3. Configure authentication. Keep a recoverable TOTP authenticator, then add a passkey or external identity provider if needed.
  4. Onboard one test service, configure a TLS certificate, and verify the entire sign-in flow over a mobile connection.
  5. Once the path is stable, use service discovery to onboard more services and export an application backup.

Do not leave a route that bypasses the gateway

fn-knock can protect only traffic that passes through it. If your router, container platform, or cloud firewall still exposes the NAS admin UI or an application's original port, those requests bypass fn-knock authentication, WAF rules, and request logging.

Continue from your current setup

Community QQ group: 1081609274