---
title: "calicoctl node checksystem"
description: "Reference for the calicoctl node check-system command in Calico Open Source, used to verify host kernel support for Calico features."
product: "Calico Open Source"
version: "3.33 (latest)"
section: "Reference"
canonical_url: "https://docs.tigera.io/calico/latest/reference/calicoctl/node/checksystem"
---

# calicoctl node checksystem

This section describes the `calicoctl node checksystem` command.

Read the [calicoctl Overview](https://docs.tigera.io/calico/latest/reference/calicoctl/overview.md) for a full list of calicoctl commands.

## Displaying the help text for 'calicoctl node checksystem' command

Run `calicoctl node checksystem --help` to display the following help menu for the command.

```text
Verify that this host meets the system requirements to run a Calico node instance.

Usage:
  calicoctl node checksystem [flags]

Examples:
  calicoctl node checksystem

Flags:
  -h, --help                   help for checksystem
  -f, --kernel-config string   Override the Kernel config file location.

Global Flags:
      --allow-version-mismatch   Allow client and cluster versions mismatch
      --context string           The name of the kubeconfig context to use
  -l, --log-level string         Set the log level (panic, fatal, error, warn, info, debug) (default "panic")
```

### Procedure

These are the steps that `calicoctl` takes to pinpoint what modules are available in your system.

1. `calicoctl` checks the kernel version.
2. By executing `lsmod` it tries to find out what modules are enabled.
3. Modules without a match in step 2 will be checked against `/lib/modules/<YOUR_KERNEL_VERSION>/modules.dep` file.
4. Modules without a match in step 2 & 3 will be checked against `/lib/modules/<YOUR_KERNEL_VERSION>/modules.builtin` file.
5. Modules without a match in previous steps will be tested against `kernelconfig` file `/usr/src/linux/.config`.
6. Any remaining module will be tested against loaded iptables modules in `/proc/net/ip_tables_matches`.

### Examples

```bash
calicoctl node checksystem
```

An example response follows.

```text
xt_conntrack                                            OK
xt_u32                                                  OK
WARNING: Unable to detect the xt_set module. Load with `modprobe xt_set`
WARNING: Unable to detect the ipip module. Load with `modprobe ipip`
```

It is possible to override the `kernel-config` file using `--kernel-config` argument. In this case `calicoctl` will try to resolve the modules against the provided file and skip the default locations.

```bash
calicoctl node checksystem --kernel-config /root/MYKERNELFILE
```
