> patpro--- via Postfix-users <[email protected]>:
> [...]
> I wish I could just create a Wireguard tunnel that my home server could use: 
> that way, everything runs at home, including signing before sending outside. 
> I could not make it work (not a postfix problem, just a routing problem).

There are two common options:

1) Containerized

Create a container (systemd-nspawn, LXC, etc.) or a virtual machine
for your home mail server. Then set up a WireGuard tunnel from inside
the container to the VPS and configure the container's default route
to use the WireGuard interface, with the VPS's WireGuard ip address
as the gateway. This way connections that Postfix initiates as a client
will be routed through the tunnel by default. On the VPS configure
masquerading (or SNAT for the container's WireGuard ip) so that outgoing
connections use the VPS's publicly routable ip address.

For incoming connections configure DNAT on the VPS to forward port 25
to the container's WireGuard ip address.

Make sure ip forwarding is enabled on the VPS otherwise routing won't work.
(cat /proc/sys/net/ipv4/ip_forward should return 1)


2) Without a container

For outgoing connections you'll need to set up policy routing (iproute2:
ip rule, ip route add table xyz, etc.) so that traffic destined for
port 25 is routed through the WireGuard tunnel. Make sure ip forwarding
is enabled.

Configure DNAT/SNAT/MASQUERADE on the VPS as described in option 1.

You also need to make sure that Postfix's reply packets on your home mail
server are routed back through the tunnel. You can do this either by adding
an extra SNAT rule on the VPS (since DNAT only rewrites the destination address)
or by using your home server's firewall connection tracking (iptables/nftables)
to set a connection mark which you can then match with an ip rule entry to route
those flows via WireGuard.

As a safety net consider adding a firewall rule on your home server that drops
outbound port 25 traffic on the default (non-WireGuard) interface in case the
tunnel goes down.


3) SOCKS5 (uncommon)

This approach requires tools like socksify or proxychains which use LD_PRELOAD
to intercept system calls to make apps SOCKS5 compatible. On the VPS side you'd
need a SOCKS5 server such as Dante or just use sshd's SOCKS5 proxy (ssh -D),
which also encrypts the otherwise plaintext SOCKS5 traffic.

I don't know if LD_PRELOAD is inherited by child processes spawned by Postfix.

Best regards,
Gerald
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to