> patpro--- via Postfix-users <[email protected]>: > [...] > I wish I could just create a Wireguard tunnel that my home server could use: > that way, everything runs at home, including signing before sending outside. > I could not make it work (not a postfix problem, just a routing problem).
There are two common options: 1) Containerized Create a container (systemd-nspawn, LXC, etc.) or a virtual machine for your home mail server. Then set up a WireGuard tunnel from inside the container to the VPS and configure the container's default route to use the WireGuard interface, with the VPS's WireGuard ip address as the gateway. This way connections that Postfix initiates as a client will be routed through the tunnel by default. On the VPS configure masquerading (or SNAT for the container's WireGuard ip) so that outgoing connections use the VPS's publicly routable ip address. For incoming connections configure DNAT on the VPS to forward port 25 to the container's WireGuard ip address. Make sure ip forwarding is enabled on the VPS otherwise routing won't work. (cat /proc/sys/net/ipv4/ip_forward should return 1) 2) Without a container For outgoing connections you'll need to set up policy routing (iproute2: ip rule, ip route add table xyz, etc.) so that traffic destined for port 25 is routed through the WireGuard tunnel. Make sure ip forwarding is enabled. Configure DNAT/SNAT/MASQUERADE on the VPS as described in option 1. You also need to make sure that Postfix's reply packets on your home mail server are routed back through the tunnel. You can do this either by adding an extra SNAT rule on the VPS (since DNAT only rewrites the destination address) or by using your home server's firewall connection tracking (iptables/nftables) to set a connection mark which you can then match with an ip rule entry to route those flows via WireGuard. As a safety net consider adding a firewall rule on your home server that drops outbound port 25 traffic on the default (non-WireGuard) interface in case the tunnel goes down. 3) SOCKS5 (uncommon) This approach requires tools like socksify or proxychains which use LD_PRELOAD to intercept system calls to make apps SOCKS5 compatible. On the VPS side you'd need a SOCKS5 server such as Dante or just use sshd's SOCKS5 proxy (ssh -D), which also encrypts the otherwise plaintext SOCKS5 traffic. I don't know if LD_PRELOAD is inherited by child processes spawned by Postfix. Best regards, Gerald _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
