---
title: "Software-Defined Perimeter (SDP) Dynamic Knocking | Zero-Trust Architecture Canon"
description: "Zero-visibility infrastructure architecture using Software-Defined Perimeter (SDP) and Single Packet Authorization (SPA), keeping server ports completely closed (drop 100%) until cryptographically authenticated."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/architectures/software-defined-perimeter-appgate"
locale: "en"
---

# Software-Defined Perimeter (SDP) Dynamic Knocking (`zt-arch-17`)

> **Pillar**: NETWORKS | **Archetype**: NETWORK_MICROSEGMENTATION
> **Blocked MITRE ATT&CK Techniques**: T1046, T1190, T1133

## Architecture Summary

Zero-visibility infrastructure architecture using Software-Defined Perimeter (SDP) and Single Packet Authorization (SPA), keeping server ports completely closed (drop 100%) until cryptographically authenticated.

## Adversary Model

Adversary executes port scans (nmap / masscan) across public IP ranges, attempting to locate open administrative ports.

## NIST SP 800-207 Core Tenets

- All communication is secured regardless of network location.
- All data sources and computing services are considered resources.

## 3-Tier Maturity Configurations

### INITIAL Maturity Target

- **Implementation Scope**: Traditional bastion host with SSH keys and restricted IP allowlists.
- **Authentication Enforcement**: Static firewall rules updated manually.
- **Network Isolation**: Port 22 open to corporate office IP ranges.

### ADVANCED Maturity Target

- **Implementation Scope**: Single Packet Authorization (SPA) client sending encrypted HMAC packet before opening temporary port.
- **Authentication Enforcement**: Port opens strictly for caller IP for exactly 30 seconds to complete handshake.
- **Network Isolation**: Default state of all external firewalls is 100% DROP.

### OPTIMAL Maturity Target

- **Implementation Scope**: Full Software-Defined Perimeter mesh with dynamic mTLS session brokering and zero public IP exposure.
- **Authentication Enforcement**: Continuous multi-attribute posture attestation required throughout session duration.
- **Network Isolation**: Infrastructure completely invisible to unauthorized internet scanners.

## Terraform HCL Manifest

```hcl
resource "aws_security_group" "sdp_gateway" {
  name        = "sdp-dark-gateway"
  description = "Closed to all unauthenticated ingress"
  vpc_id      = var.vpc_id

  # Zero default inbound rules; ports opened dynamically via SPA
  egress {
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: v1
kind: ConfigMap
metadata:
  name: fwknopd-config
  namespace: security
data:
  access.conf: |
    SOURCE              ANY
    OPEN_PORTS          tcp/22, tcp/443
    KEY_BASE64          +k9PEXAMPLEBASE64KEY==
    HMAC_KEY_BASE64     hmacEXAMPLEKEY12345678==
    FW_ACCESS_TIMEOUT   30
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Software-Defined Perimeter (SDP) Dynamic Knocking | Zero-Trust Architecture Canon",
  "description": "Zero-visibility infrastructure architecture using Software-Defined Perimeter (SDP) and Single Packet Authorization (SPA), keeping server ports completely closed (drop 100%) until cryptographically authenticated.",
  "url": "https://tinycto.tv/zero-trust/architectures/software-defined-perimeter-appgate"
}
```
