For example, 443/TCP is blocked from world. However if someone opens web page, it returns <html><body>Access request from IP xxx.xxx.xxx.xxx has been submitted</body></html> (or maybe a form where you put port number you'd like to access) and from server-side I can somehow see those requests, useragents and accept/deny and just ignore bots.
Use-case: Some photoalbum is locked down, accessed by particular IPs/countries/vpn (to reduce or prevent bruteforcing, automated hacking and such) - however I'd like to give access to someone (who doesn't know his IP) by just giving him a domain name. https://photos.example.com - yeah, he sees that unfriendly page. After a while I call him and say - try again and poof, next time he opens the page, he penetrates the firewall and gets pictures.
The thing is:
- VPN is too much of an ask to a person I want to send a link to some data
- Country block is very rough filter, just helps to reduce some log traffic from uninteresting countries with loads of bots.
- Asking person his IP is very manual: "please open/google up such phrase, send me that address and I'll look up my notes to copy/paste that iptables command and I'll modify it slightly (or add some config entry to .htaccess) to put your IP in and then you'll have access until you reconnect to your mobile network or your ISP gives you new DHCP address and then we'll repeat"
"Knockwall" doesn't return much results, eh.