Skip to content

System Settings and Maintenance

System settings brings together runtime modes, tunnel resources, certificate tools, gateway and session controls, feature switches, and maintenance actions. Tabs appear dynamically according to the runtime mode and deployment capabilities. If a tab is missing, check the current platform and runtime mode before repeatedly refreshing the page.

Deployment Capability Differences

CapabilityNative fnOS FPKDockerOpenWrtLinux servicemacOSSynology DSM 7 SPKWindows x86_64
Direct mode and host firewallSupported; the process needs host permissionsNot supportedNot supportedNot supportedNot supportedNot supportedNot supported
Smart ConnectSupportedNot supportedNot supportedNot supportedNot supportedNot supportedNot supported
Web TerminalRemote SSH + optional local PTYRemote SSH onlyRemote SSH + optional local PTYRemote SSH + optional local PTYRemote SSH + optional local PTYRemote SSH onlyRemote SSH only
Built-in FRP / CloudflaredSupportedSupportedSupportedSupportedSupportedSupportedNot supported
SSH SecuritySupportedNot supportedNot supportedNot supportedNot supportedNot supportedNot supported
Automatic HTTPSSupportedNot supportedNot supportedSupported; requires an available port 80Supported; firewall and inbound access remain manualNot supportedSupported; the Windows inbound path must still be opened
ACME DNS-01SupportedSupportedSupportedSupportedSupportedSupportedSupported; uses the built-in client
System clock syncSupportedNot supportedSupportedNot supportedNot supportedNot supportedNot supported
fnOS SSL certificate store syncSupportedNot supportedNot supportedNot supportedNot supportedNot supportedNot supported
Update installationUpdate in the web UIPull a new imageInstall an IPK or APK matching the firmwareUpdate manually according to the installation methodsudo knock updateInstall the SPK in DSM Package CenterWindows manager
Separate admin panel passwordUses the fnOS/CGI entry pointSupportedSupportedSupportedSupported; local 127.0.0.1 admin entry onlyUses the DSM desktop CGI entry pointSupported; local 127.0.0.1 admin entry only

The table reflects runtime capabilities reported by the server. Some unavailable features remain visible with an explanation, while others are hidden entirely. OpenWrt no longer provides Direct mode, host-firewall management, or Smart Connect. It can still run Host routing, Protocol mappings, and built-in tunnels, but OpenWrt's own firewall must allow the ports. Windows does not provide direct mode, built-in FRP / Cloudflared, Smart Connect, or SSH Security. Its gateway listens on all interfaces at 7999 by default, but public reachability still depends on firewall rules, NAT, and network policy. Synology DSM 7 SPK also does not provide direct mode, host-firewall management, Smart Connect, or SSH Security. Remote SSH targets remain available on every platform. A local PTY is available, disabled by default, on the standard fnOS FPK, OpenWrt, Linux, and macOS; it runs with the fn-knock service identity. Docker, Synology, Windows, development runtimes, and Knock Lite provide remote SSH only.

If the app on an fnOS device is named Knock Lite, it is a native non-root package rather than the full FPK shown in the table. It supports Host proxying, authentication, DDNS, certificates, WAF, built-in tunnels, monitoring, and remote-SSH Web Terminal, but not a local PTY, Direct mode and the host firewall, network optimization, fnOS certificate-store sync, or in-app updates. To gain full host integration, export a Lite backup and stop Lite before installing the standard FPK from the official website and importing the archive. Do not let both instances compete for the same ports.

Settings Map

Tab or sectionWhen it appears and what it managesDetails
ModeAlways visible; selects direct, reverse-proxy, or subdomain mode and its routing methodChoose a Runtime Mode
FRP, CloudflaredVisible in reverse proxy mode when the platform has the corresponding capability; downloads and installs tunnel binariesNAT Traversal and Tunnels
ACMEVisible when the platform supports it and is not Windows; manages the acme.sh resource and default CATLS Certificates and HTTPS
LocationConfigures the IP geolocation database and CIDR location databaseIP Geolocation
fnOSManages fnOS Share Bypass, port-icon takeover, available network optimizations, and FN Connect WAF ingress on the standard FPKfnOS Share Bypass, WAF
BlockingConfigures the scanner firewall, trigger window, thresholds, and exemptionsAutomated Scan Blocking
FeaturesControls date/time display, home-page entry status, the fnOS console application bar, Passkey binding prompts, automatic HTTPS, SSH Security, protocol mappings, Wake-on-LAN, sidebar ordering, and the Smart Connect entryWake-on-LAN and the corresponding feature documentation
GatewayManages authentication caching, reverse-proxy throttling, crawler blocking, the portal, visibility, and Host-level forwarding optionsSee below
WAF, LogsManages HTTP rule protection and structured request logsWeb Application Firewall (WAF), Request Logs
TerminalVisible on every package; manages remote SSH targets and sessions, plus the optional local PTY where supportedWeb Terminal
SessionsManages standard sessions, Remember me, post-login IP authorization, and IP driftSessions, Source-IP Authorization, and IP Changes
PanelVisible on Docker, OpenWrt, Linux, and Windows; changes or resets the separate admin panel passwordSee below
ChallengeUses PoW or Cloudflare Turnstile before sign-inChallenge
MaintenanceManages automatic backups, manual exports, imports, and data cleanupSee below

Under System settings → Features → Sidebar menu order, drag menu items to change the order of the left navigation for this instance. The order saves automatically when a drag ends. Select Restore default order to remove all custom ordering.

The page lists only entries visible under the current runtime mode and feature switches. Temporarily hidden entries keep their place in the full order and return to the same relative position when the feature is enabled or the mode changes; they are not appended arbitrarily. This setting changes navigation order only and does not enable, disable, or grant access to any feature.

Date and Time Display

System settings → Features → Date and time display controls time fields that use the shared display component in the admin console:

  • Human-friendly is the default and shows relative values such as “a few minutes ago” or “yesterday.” Hover, or tap on a touch device, to see the full date and time.
  • Full time shows the localized full date and time directly. Hovering or tapping instead provides the relative value.

The selection is stored in instance configuration and applied throughout the admin console. It does not change the server time zone, system clock, original log timestamps, or protocol-mapping schedules. Use server time and time zone when troubleshooting scheduled tasks.

fnOS Console Application Bar

The standard fnOS FPK and Knock Lite can enable Show application list at the top of the console under System settings → Features. It is off by default. When enabled, a horizontally scrollable shortcut bar appears above the admin content and opens each gateway application in a new tab. Docker, OpenWrt, Linux, Synology, and Windows do not show this switch.

With Host routing, the bar lists enabled, non-authentication Host mappings and follows the portal's application labels, icon-display setting, and group order. If no eligible Host item exists, a path-mode configuration falls back to saved path mappings. Links are generated from the current admin-page protocol and configured public entry port. They are shortcuts only and do not replace DNS, port forwarding, or certificate configuration.

The switch does not enable, publish, or alter a mapping, nor does it bypass login or service scope. If the bar is empty, confirm that the current mode has eligible mappings. If a link opens but access is denied, troubleshoot the corresponding mapping's authentication and entry path.

Runtime mode switching and Smart Connect fallback

Changing runtime mode saves a candidate configuration, then synchronizes Smart Connect, gateway routes, and platform runtime state in sequence while preventing those synchronization steps from waiting on one another. Keep the page open while switching, then verify the new entry path as instructed by the result message.

On the standard fnOS FPK with Smart Connect support, if the local IP or dnsmasq cannot synchronize during the change, fn-knock completes the mode switch but automatically disables Smart Connect and shows a warning instead of letting DNS split-horizon failure block the entire operation. Check the local IP, root domain, and dnsmasq write access before enabling Smart Connect again under System settings → Features. A failure while applying gateway routes or firewall state still triggers an attempted rollback to the previous configuration. Keep a LAN or console entry available, read the error, and do not switch repeatedly through several modes.

Additional Firewall Ports on the Standard fnOS FPK

The standard fnOS FPK with host-firewall capability can preserve ports outside fn-knock's automatically managed set under System settings → Mode → Actions → Additional allowed ports. Docker, OpenWrt, Linux, Synology, Windows, and fn-knock Lite do not show this action; manage their ports in the host, router, or cloud firewall instead.

The dialog separates ports opened automatically for the current mode—such as gateway, protocol-mapping, or Smart Connect ports—from user-added ports. The additional list accepts at most 128 unique integers from 1 through 65535. Each port opens both TCP and UDP and cannot be split by protocol. Add only services that must be reachable from outside the firewall.

Saving follows the runtime mode currently saved by the backend:

  • Direct or Subdomain mode immediately rebuilds FN-KNOCK-FW and merges automatic and additional ports.
  • Reverse-proxy mode does not create FN-KNOCK-FW; it retains the list and applies it after switching to Direct or Subdomain mode.
  • If Automatically manage the system firewall is disabled, switching to Subdomain mode requires a manual reset from Actions; Direct mode still manages the firewall.
  • An unsaved mode selection on the page does not affect this operation. The dialog's Current saved mode is authoritative.

Saving rebuilds fn-knock's managed chain as a whole. It does not replace router port forwarding, cloud security groups, or authentication in the upstream service. Before removing a port, confirm that no remote administration path depends on it.

Basic Gateway Settings

Settings at the top of System settings → Gateway are synchronized directly to the Go gateway. The Host-level editor is available only for Host routing in subdomain mode, and the auth service Host does not appear in the editable list.

SettingBehavior and considerations
Successful auth cache durationCaches a successful result for the same client and authentication target; 0 validates every request in real time
Failed auth cache durationCaches a failed authentication result; 0 does not reuse denials. When troubleshooting a recent permission change, account for an earlier failed result that may not have expired
Enable gateway reverse proxy throttlingLimits traffic per client IP using requests per second and burst tokens, then closes connections directly for the configured penalty period
Block crawler requestsBlocks requests recognized as crawlers by the gateway; it does not replace WAF or stop requests that bypass the gateway
Unmatched routesShow error page returns a friendly page; Reset connection terminates requests that match no configured route
Show error information when the upstream failsDefaults to Show less; choose Show more, or Block connection to abort failed requests without an error page
Portal settingsControls the app switcher shown after sign-in
VisibilityLimits which sources can reach the gateway by region or CIDR
Proxy headersControls whether the gateway sends X-Forwarded-* to specified Targets
Host responseControls whether the gateway preserves the visitor's requested Host for specified Targets
Path responsesAdds path-level proxying or fixed responses to application Hosts

The initial reverse-proxy throttling configuration allows 100 requests per second and 200 burst tokens per client IP, with a 30-second penalty after exceeding the limit. Requests terminated directly by throttling are not written to request logs. If a client connection closes without a corresponding log entry, check this layer as well. Host-level switches in the UI are ultimately compiled by Target: when multiple Hosts point to the exact same Target, they share proxy-header and Host-preservation behavior.

Unmatched routes and upstream errors

Unmatched routes default to Show error page, which returns a welcome, selection, or error page. With Reset connection, HTTP/1.x connections are reset and the current HTTP/2 stream is aborted. Default-domain fallback is temporarily disabled, but its saved configuration is retained and resumes when you switch back to the error page. Request logs label these requests as unmatched-route blocks.

Show error information when the upstream fails defaults to Show less: visitors see only that the upstream is unavailable, without its internal IP, port, or connection failure. Show more returns the complete connection error and can expose network topology, so use it only briefly in a controlled environment. With Block connection, an upstream connection failure produces no error page: the gateway resets HTTP/1.x connections or aborts the current HTTP/2 stream. This suits an entry point that should not reveal a gateway page to probes, but clients will see an abrupt disconnect.

Verification Order After Changing Settings

  1. Keep one working admin entry point available on the LAN.
  2. After changing the runtime mode, Host, certificate, or gateway settings, wait for the page to confirm that runtime synchronization has completed.
  3. Test the authentication flow in a private browsing window, then test the application Host from a real external network.
  4. Check the client IP, route type, authentication result, and upstream Target in request logs.
  5. Check Event Center for synchronization, certificate, tunnel, or notification errors.

For gateway throttling, WAF, and scan blocking, begin in observation mode or with a permissive configuration. These controls may affect health checks, third-party callbacks, application updates, or long-lived client connections.

Backup and Restore

Automatic and manually exported .knock archives contain configuration, certificate private keys, TOTP seeds, and several types of service credentials. Treat them as plaintext backups of secret material. Automatic backups are disabled by default; when enabled, they are stored in the server data directory with a configurable interval and retention period. If that directory is on the same disk or container volume as the active data, it is not a substitute for an off-device backup. Import is replacement, not merge: it replaces the current fn-knock application data and then synchronizes gateway, WAF, SSL, and other runtime state. A synchronization warning does not trigger an automatic full rollback.

See Backup, Restore, and Data Cleanup for archive security, versions, the 128 MiB limit, platform entry points, full restoration acceptance testing, and failure handling. An application backup is not a filesystem or container-volume backup, and it does not include external DNS, host-firewall configuration, or upstream application data.

Clear All Data

System settings → Maintenance → Cleanup → Clear all data completely reinitializes the current instance. You must enter Clear all data to confirm. The operation clears server-side configuration, accounts, sessions, logs, and other application storage, then clears local data in the current browser and reloads the page.

The database schema and previously exported backup files do not restore content automatically. This action cannot be undone; use it only after verifying that a usable backup exists and intentionally deciding to reinitialize the instance.

Admin Panel Password

The admin panel password on Docker, OpenWrt, Linux, and Windows is separate from visitors' gateway sign-in credentials. If you forget it, use the reset command or manager documented for that deployment. A reset clears only the panel password, panel sessions, and sign-in backoff; it does not delete application mappings or certificate configuration.

Community QQ group: 1081609274