> patpro--- via Postfix-users <[email protected]>:
> 
> September 22, 2026 at 00:25, "Gerald Galster via Postfix-users" wrote:
> 
>> There are two common options:
>> 
>> 1) Containerized
>> 
>> Create a container (systemd-nspawn, LXC, etc.) or a virtual machine
>> for your home mail server. Then set up a WireGuard tunnel from inside
>> the container to the VPS and configure the container's default route
>> to use the WireGuard interface, with the VPS's WireGuard ip address
>> as the gateway. This way connections that Postfix initiates as a client
>> will be routed through the tunnel by default. On the VPS configure
>> masquerading (or SNAT for the container's WireGuard ip) so that outgoing
>> connections use the VPS's publicly routable ip address.
>> 
>> For incoming connections configure DNAT on the VPS to forward port 25
>> to the container's WireGuard ip address.
>> 
>> Make sure ip forwarding is enabled on the VPS otherwise routing won't work.
>> (cat /proc/sys/net/ipv4/ip_forward should return 1)
> 
> 
> Thank you Gerald for this detailed reply.
> 
> I’m running FreeBSD both at home and on VPS, but it’s the idea I tried to 
> implement with a Jail and Wireguard. 
> I was not able to exclude local traffic from outbound traffic. 
> Full traffic in VPN works, but I need the Jail to access local network too. 
> This is something I need to investigate again.

IIRC FreeBSD jails are somewhat similar to namespaces on Linux.
If WireGuard is the only interface inside the jail, could you add
a second interface for local connections?

Either way, once a local interface is present, you should just need to
add a specific route for your local network. Traffic will use the default
0.0.0.0/0 route via WireGuard unless a more specific route for a smaller
subnet (like 192.168.0.0/16) exists. Smaller networks (= larger netmasks)
take precedence and bypass the tunnel.

Best regards,
Gerald
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to