If someone intercepts the traffic to my server, they could see the knock sequence and re-use it. Is there any way to get knockd to use a google authenticator-like sequence of port knocks?
I use fwknop[0] on my servers. It does single-packet authorization rather than straight port knocking, which solves the replay issue.
You block a MITM attack with public key cryptography. Port knocking is not meant to stop MITM attacks.
Yes, take a look at the manual page for knockd and search for "One_Time_Sequences". It does what you are asking by using a one-time valid sequence of port knocks, but it is like HOTP rather than TOTP.