Files
nx9-wg/docs/linux_requirements.md
T
thakaresandCopilot 2ac6c81dfe cli: avoid data-dir initialization for version; create db parent dirs; redact generated passwords in CLI output
- Prevent 'nx9-wg version' from creating data directories by avoiding database initialization.
- Create parent directories when an explicit --database path is provided.
- Redact printed generated administrator passwords; announce file path or redact instead.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-16 16:26:24 +05:30

1.3 KiB

Linux Platform and Kernel Requirements

nx9-wg is built for modern Linux systems and relies directly on kernel networking features.


1. Kernel Requirements

  • Linux Kernel Version: 5.6 or newer (WireGuard module is included in mainline kernel 5.6+).
  • Kernel Module: wireguard.ko (modprobe wireguard).
  • Sysctl IP Forwarding:
    • /proc/sys/net/ipv4/ip_forward (must be 1 for VPN client internet routing).
    • /proc/sys/net/ipv6/conf/all/forwarding (optional, for IPv6 dual-stack).

2. Firewall and Packet Filtering

  • nftables: nx9-wg requires nftables in the kernel.
  • Isolated Table: All rules are scoped inside table inet nx9_wg. nx9-wg does not alter or flush tables created by Docker, Kubernetes, or other firewall utilities.

3. Capability Requirements

When running without full root privileges, the process requires:

  • CAP_NET_ADMIN: For configuring network links, routes, and packet filter tables.
  • CAP_NET_BIND_SERVICE: If binding to low UDP ports (< 1024).

4. Unsupported Environments

  • macOS and Windows do not support the Linux in-tree WireGuard kernel module. For local testing on non-Linux platforms, nx9-wg automatically engages the built-in SimulatedWireGuardEngine and SimulatedNetworkEngine.