On 22/09/2026 15:10, Gerald Galster via Postfix-users wrote:

I’m running FreeBSD both at home and on VPS, but it’s the idea I tried to 
implement with a Jail and Wireguard.
I was not able to exclude local traffic from outbound traffic.
Full traffic in VPN works, but I need the Jail to access local network too. 
This is something I need to investigate again.

IIRC FreeBSD jails are somewhat similar to namespaces on Linux.
If WireGuard is the only interface inside the jail, could you add
a second interface for local connections?

Either way, once a local interface is present, you should just need to
add a specific route for your local network. Traffic will use the default
0.0.0.0/0 route via WireGuard unless a more specific route for a smaller
subnet (like 192.168.0.0/16) exists. Smaller networks (= larger netmasks)
take precedence and bypass the tunnel.

I’m using a particular type of Jail: vnet Jail. They have a proper iface.

root@testwg:~ # ifconfig
lo0: flags=1008049<UP,LOOPBACK,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu 16384
        options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6>
        inet 127.0.0.1 netmask 0xff000000
        inet6 ::1 prefixlen 128
        inet6 fe80::1%lo0 prefixlen 64 scopeid 0x12
        groups: lo
        nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
vnet0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
        description: jail interface for bridge0
        options=200009<RXCSUM,VLAN_MTU,RXCSUM_IPV6>
        ether 58:9c:fc:08:f4:6b
        hwaddr 02:40:57:db:e7:0b
        inet 192.168.2.111 netmask 0xffffff00 broadcast 192.168.2.255
        groups: epair
        media: Ethernet 10Gbase-T (10Gbase-T <full-duplex>)
        status: active
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
wg1: flags=10080c1<UP,RUNNING,NOARP,MULTICAST,LOWER_UP> metric 0 mtu 1420
        options=80000<LINKSTATE>
        inet 10.1.0.2 netmask 0xffffff00
        inet6 2001:xxx:xxx:xxx:4000::2 prefixlen 66
        groups: wg
        nd6 options=101<PERFORMNUD,NO_DAD>


The (current) wireguard client config includes:

AllowedIPs = 10.1.0.0/24

so traffic does not go inside the tunnel, unless it’s meant for the WG network. I could use that to send emails from my local email stack to a remote postfix relay on the other end of the tunnel.

I tried something like this to tunnel everything except LAN communication (192.168.0.0/16):

AllowedIPs = 0.0.0.0/0, !192.168.0.0/16

but the FreeBSD Wireguard does not allow for that syntax.
Then I tried many things like this:

AllowedIPs = 0.0.0.0/5, 8.0.0.0/7, 11.0.0.0/8, 12.0.0.0/6, 16.0.0.0/4, 32.0.0.0/3, 64.0.0.0/2, 128.0.0.0/2, 192.0.0.0/9, 192.128.0.0/11, 192.160.0.0/13, 192.169.0.0/16, 192.170.0.0/15, 192.172.0.0/14, 192.176.0.0/12, 192.192.0.0/10, 193.0.0.0/8, 194.0.0.0/7, 196.0.0.0/6, 200.0.0.0/5, 208.0.0.0/4

This is supposed to route most things into the tunnel, except 10.0.0.0/8, 192.168.0.0/16 and broadcast. This failed totally and at some point I even managed to create a network loop on Wireguard (host kernel logged `wg1: loop detected`).

This particular bloc list is produced by:
netmask -c 0.0.0.0:9.255.255.255
netmask -c 11.0.0.0:192.167.255.255
netmask -c 192.169.0.0:223.255.255.255


I’ll give a try to your proposal of `AllowedIPs = 0.0.0.0/0` plus a static route in the Jail for 192.168.0.0/16

Thanks,
patrick
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to