# Linux Platform and Kernel Requirements `nx9-wg` is built for modern Linux systems and relies directly on kernel networking features. --- ## 1. Kernel Requirements - **Linux Kernel Version**: 5.6 or newer (WireGuard module is included in mainline kernel 5.6+). - **Kernel Module**: `wireguard.ko` (`modprobe wireguard`). - **Sysctl IP Forwarding**: - `/proc/sys/net/ipv4/ip_forward` (must be `1` for VPN client internet routing). - `/proc/sys/net/ipv6/conf/all/forwarding` (optional, for IPv6 dual-stack). --- ## 2. Firewall and Packet Filtering - **`nftables`**: `nx9-wg` requires `nftables` in the kernel. - **Isolated Table**: All rules are scoped inside `table inet nx9_wg`. `nx9-wg` does not alter or flush tables created by Docker, Kubernetes, or other firewall utilities. --- ## 3. Capability Requirements When running without full root privileges, the process requires: - `CAP_NET_ADMIN`: For configuring network links, routes, and packet filter tables. - `CAP_NET_BIND_SERVICE`: If binding to low UDP ports (< 1024). --- ## 4. Unsupported Environments - macOS and Windows do not support the Linux in-tree WireGuard kernel module. For local testing on non-Linux platforms, `nx9-wg` automatically engages the built-in `SimulatedWireGuardEngine` and `SimulatedNetworkEngine`.