On 22/09/2026 15:10, Gerald Galster via Postfix-users wrote:
I’m running FreeBSD both at home and on VPS, but it’s the idea I tried to
implement with a Jail and Wireguard.
I was not able to exclude local traffic from outbound traffic.
Full traffic in VPN works, but I need the Jail to access local network too.
This is something I need to investigate again.
IIRC FreeBSD jails are somewhat similar to namespaces on Linux.
If WireGuard is the only interface inside the jail, could you add
a second interface for local connections?
Either way, once a local interface is present, you should just need to
add a specific route for your local network. Traffic will use the default
0.0.0.0/0 route via WireGuard unless a more specific route for a smaller
subnet (like 192.168.0.0/16) exists. Smaller networks (= larger netmasks)
take precedence and bypass the tunnel.
I’m using a particular type of Jail: vnet Jail. They have a proper iface.
root@testwg:~ # ifconfig
lo0: flags=1008049<UP,LOOPBACK,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu
16384
options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6>
inet 127.0.0.1 netmask 0xff000000
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x12
groups: lo
nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
vnet0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP>
metric 0 mtu 1500
description: jail interface for bridge0
options=200009<RXCSUM,VLAN_MTU,RXCSUM_IPV6>
ether 58:9c:fc:08:f4:6b
hwaddr 02:40:57:db:e7:0b
inet 192.168.2.111 netmask 0xffffff00 broadcast 192.168.2.255
groups: epair
media: Ethernet 10Gbase-T (10Gbase-T <full-duplex>)
status: active
nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
wg1: flags=10080c1<UP,RUNNING,NOARP,MULTICAST,LOWER_UP> metric 0 mtu 1420
options=80000<LINKSTATE>
inet 10.1.0.2 netmask 0xffffff00
inet6 2001:xxx:xxx:xxx:4000::2 prefixlen 66
groups: wg
nd6 options=101<PERFORMNUD,NO_DAD>
The (current) wireguard client config includes:
AllowedIPs = 10.1.0.0/24
so traffic does not go inside the tunnel, unless it’s meant for the WG
network. I could use that to send emails from my local email stack to a
remote postfix relay on the other end of the tunnel.
I tried something like this to tunnel everything except LAN
communication (192.168.0.0/16):
AllowedIPs = 0.0.0.0/0, !192.168.0.0/16
but the FreeBSD Wireguard does not allow for that syntax.
Then I tried many things like this:
AllowedIPs = 0.0.0.0/5, 8.0.0.0/7, 11.0.0.0/8, 12.0.0.0/6, 16.0.0.0/4,
32.0.0.0/3, 64.0.0.0/2, 128.0.0.0/2, 192.0.0.0/9, 192.128.0.0/11,
192.160.0.0/13, 192.169.0.0/16, 192.170.0.0/15, 192.172.0.0/14,
192.176.0.0/12, 192.192.0.0/10, 193.0.0.0/8, 194.0.0.0/7, 196.0.0.0/6,
200.0.0.0/5, 208.0.0.0/4
This is supposed to route most things into the tunnel, except
10.0.0.0/8, 192.168.0.0/16 and broadcast. This failed totally and at
some point I even managed to create a network loop on Wireguard (host
kernel logged `wg1: loop detected`).
This particular bloc list is produced by:
netmask -c 0.0.0.0:9.255.255.255
netmask -c 11.0.0.0:192.167.255.255
netmask -c 192.169.0.0:223.255.255.255
I’ll give a try to your proposal of `AllowedIPs = 0.0.0.0/0` plus a
static route in the Jail for 192.168.0.0/16
Thanks,
patrick
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]