My understanding is that fwknopd listens on port 62201 for the SPA, however I cannot see a port forward or firewall rule that allows this.
I see references to “pcap” interfaces. Does fwknopd run “outside” of the remit of the firewall? Is this implicit in its function/design (ie having access via the firewall would make it show up)?