- Prevent 'nx9-wg version' from creating data directories by avoiding database initialization. - Create parent directories when an explicit --database path is provided. - Redact printed generated administrator passwords; announce file path or redact instead. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
35 lines
1.3 KiB
Markdown
35 lines
1.3 KiB
Markdown
# Linux Platform and Kernel Requirements
|
|
|
|
`nx9-wg` is built for modern Linux systems and relies directly on kernel networking features.
|
|
|
|
---
|
|
|
|
## 1. Kernel Requirements
|
|
|
|
- **Linux Kernel Version**: 5.6 or newer (WireGuard module is included in mainline kernel 5.6+).
|
|
- **Kernel Module**: `wireguard.ko` (`modprobe wireguard`).
|
|
- **Sysctl IP Forwarding**:
|
|
- `/proc/sys/net/ipv4/ip_forward` (must be `1` for VPN client internet routing).
|
|
- `/proc/sys/net/ipv6/conf/all/forwarding` (optional, for IPv6 dual-stack).
|
|
|
|
---
|
|
|
|
## 2. Firewall and Packet Filtering
|
|
|
|
- **`nftables`**: `nx9-wg` requires `nftables` in the kernel.
|
|
- **Isolated Table**: All rules are scoped inside `table inet nx9_wg`. `nx9-wg` does not alter or flush tables created by Docker, Kubernetes, or other firewall utilities.
|
|
|
|
---
|
|
|
|
## 3. Capability Requirements
|
|
|
|
When running without full root privileges, the process requires:
|
|
- `CAP_NET_ADMIN`: For configuring network links, routes, and packet filter tables.
|
|
- `CAP_NET_BIND_SERVICE`: If binding to low UDP ports (< 1024).
|
|
|
|
---
|
|
|
|
## 4. Unsupported Environments
|
|
|
|
- macOS and Windows do not support the Linux in-tree WireGuard kernel module. For local testing on non-Linux platforms, `nx9-wg` automatically engages the built-in `SimulatedWireGuardEngine` and `SimulatedNetworkEngine`.
|