> patpro--- via Postfix-users <[email protected]>: > > September 22, 2026 at 00:25, "Gerald Galster via Postfix-users" wrote: > >> There are two common options: >> >> 1) Containerized >> >> Create a container (systemd-nspawn, LXC, etc.) or a virtual machine >> for your home mail server. Then set up a WireGuard tunnel from inside >> the container to the VPS and configure the container's default route >> to use the WireGuard interface, with the VPS's WireGuard ip address >> as the gateway. This way connections that Postfix initiates as a client >> will be routed through the tunnel by default. On the VPS configure >> masquerading (or SNAT for the container's WireGuard ip) so that outgoing >> connections use the VPS's publicly routable ip address. >> >> For incoming connections configure DNAT on the VPS to forward port 25 >> to the container's WireGuard ip address. >> >> Make sure ip forwarding is enabled on the VPS otherwise routing won't work. >> (cat /proc/sys/net/ipv4/ip_forward should return 1) > > > Thank you Gerald for this detailed reply. > > I’m running FreeBSD both at home and on VPS, but it’s the idea I tried to > implement with a Jail and Wireguard. > I was not able to exclude local traffic from outbound traffic. > Full traffic in VPN works, but I need the Jail to access local network too. > This is something I need to investigate again.
IIRC FreeBSD jails are somewhat similar to namespaces on Linux. If WireGuard is the only interface inside the jail, could you add a second interface for local connections? Either way, once a local interface is present, you should just need to add a specific route for your local network. Traffic will use the default 0.0.0.0/0 route via WireGuard unless a more specific route for a smaller subnet (like 192.168.0.0/16) exists. Smaller networks (= larger netmasks) take precedence and bypass the tunnel. Best regards, Gerald _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
