Authenticated port knocking

Letmein is a simple port knocker with a simple and secure authentication mechanism.

It can be used to hide services on a server behind a knock authentication to reduce the attack surface of a service. The service will not be accessible unless a knock authentication is successful. In case of a successful knock, the letmeind server will only open the knocked port for the client IP address that performed the knocking. Machines with different IP addresses still won't have access to the protected service.

Machines that can't successfully authenticate the knock sequence won't be able to access the protected service.

Letmein requires an `nftables` based firewall. It will *not* work with `iptables`.

The development source code of letmein can be downloaded using the Git version control system as follows:

git clone

If you want to contribute to letmein, please read the contribution guidelines first.

letmein is stable/production quality software.
That means its features are well tested and the remaining amount of bugs probably is minor. The software does include a reasonable amount of documentation.

Copyright (C) Michael Büsch
Licensed under the terms of the MIT license or under the terms of the Apache License version 2.0, at your option. See the sourcecode for details.

