September 22, 2026 at 00:25, "Gerald Galster via Postfix-users" <[email protected] mailto:[email protected]?to=%22Gerald%20Galster%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E > wrote: > There are two common options: > > 1) Containerized > > Create a container (systemd-nspawn, LXC, etc.) or a virtual machine > for your home mail server. Then set up a WireGuard tunnel from inside > the container to the VPS and configure the container's default route > to use the WireGuard interface, with the VPS's WireGuard ip address > as the gateway. This way connections that Postfix initiates as a client > will be routed through the tunnel by default. On the VPS configure > masquerading (or SNAT for the container's WireGuard ip) so that outgoing > connections use the VPS's publicly routable ip address. > > For incoming connections configure DNAT on the VPS to forward port 25 > to the container's WireGuard ip address. > > Make sure ip forwarding is enabled on the VPS otherwise routing won't work. > (cat /proc/sys/net/ipv4/ip_forward should return 1)
Thank you Gerald for this detailed reply. I’m running FreeBSD both at home and on VPS, but it’s the idea I tried to implement with a Jail and Wireguard. I was not able to exclude local traffic from outbound traffic. Full traffic in VPN works, but I need the Jail to access local network too. This is something I need to investigate again. > 2) Without a container ../.. I will definitely run my email stack in one or more Jails. > 3) SOCKS5 (uncommon) > > This approach requires tools like socksify or proxychains which use LD_PRELOAD > to intercept system calls to make apps SOCKS5 compatible. On the VPS side > you'd > need a SOCKS5 server such as Dante or just use sshd's SOCKS5 proxy (ssh -D), > which also encrypts the otherwise plaintext SOCKS5 traffic. > > I don't know if LD_PRELOAD is inherited by child processes spawned by Postfix. Years ago I used socksify in a long-forgotten context, I could try again. patrick _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
