Port knocking is considered 'security by obscurity' - which is no real protection. Just looks like it. The discussions about this have been lenghty here on the forum.
As for SSH, better disallow logon by name/password and hit the 'by certificate only' checkbox.
Personally I use RDC only through an OpenVPN tunnel. This way I avoid exposing my Windows server ports to the internet. This can be considered secure.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.