To be honest - this tool isn't intended to run on a firewall, isn't it?
A version number 0.1 makes me believe that it is a very stable program worth to integrate it immediately in our product. I will spend all my time to convince the management team to implement it asap
I'd have to agree about possible security issues. However, if your really wanting to use it, here's how I'd set it up. Grab another low-end machine to stick knockd on, put that machine BETWEEN Astaro (on the DMZ) & the computer you want outside access to (knockd client). Using ASL, port-forward the needed knockd ports to the knockd computer and then your ready to go. You'd still have some security provided by ASL (depending on how & what ports you forward), and if the Knockd computer gets taken over, its still on the DMZ, so its isolated (for the most part), from the rest of your network.