Port Knocking packets can have strong crypto payload. So yes, it's not really any different than using VPN. (Yes it is technically yes, but it allows you to open access from one IP address, using strong authentication for service, which still got strong authenticaiton. TOTP, private key and password.) It's just front blocking access to that tcp port without the right opening packet.