> patpro--- via Postfix-users <[email protected]>: > > On 22/09/2026 15:10, Gerald Galster via Postfix-users wrote: > >>> I’m running FreeBSD both at home and on VPS, but it’s the idea I tried to >>> implement with a Jail and Wireguard. >>> I was not able to exclude local traffic from outbound traffic. >>> Full traffic in VPN works, but I need the Jail to access local network too. >>> This is something I need to investigate again. >> IIRC FreeBSD jails are somewhat similar to namespaces on Linux. >> If WireGuard is the only interface inside the jail, could you add >> a second interface for local connections? >> Either way, once a local interface is present, you should just need to >> add a specific route for your local network. Traffic will use the default >> 0.0.0.0/0 route via WireGuard unless a more specific route for a smaller >> subnet (like 192.168.0.0/16) exists. Smaller networks (= larger netmasks) >> take precedence and bypass the tunnel. > > I’m using a particular type of Jail: vnet Jail. They have a proper iface. > > root@testwg:~ # ifconfig > lo0: flags=1008049<UP,LOOPBACK,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu 16384 > options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6> > inet 127.0.0.1 netmask 0xff000000 > inet6 ::1 prefixlen 128 > inet6 fe80::1%lo0 prefixlen 64 scopeid 0x12 > groups: lo > nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> > vnet0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric > 0 mtu 1500 > description: jail interface for bridge0 > options=200009<RXCSUM,VLAN_MTU,RXCSUM_IPV6> > ether 58:9c:fc:08:f4:6b > hwaddr 02:40:57:db:e7:0b > inet 192.168.2.111 netmask 0xffffff00 broadcast 192.168.2.255
Netmask 0xffffff00 translates to 255.255.255.0, so other IPv4 addresses within 192.168.2.0/24 should already ping. Check your routing table (netstat -rn), there should be an entry for 192.168.2.0/24. > wg1: flags=10080c1<UP,RUNNING,NOARP,MULTICAST,LOWER_UP> metric 0 mtu 1420 > options=80000<LINKSTATE> > inet 10.1.0.2 netmask 0xffffff00 > inet6 2001:xxx:xxx:xxx:4000::2 prefixlen 66 > groups: wg > nd6 options=101<PERFORMNUD,NO_DAD> > The (current) wireguard client config includes: > > AllowedIPs = 10.1.0.0/24 This probably won't work in your case as AllowedIPs also acts like a firewall (see Cryptokey Routing: https://www.wireguard.com/#cryptokey-routing). Example: A mailserver (mx.example.com, IPv4 1.2.3.4) connects to port 25/TCP on your VPS. The firewall alters the destination address using DNAT to 10.1.0.2 to send the traffic through the WireGuard tunnel. The packet's source IPv4 address remains 1.2.3.4 which is not allowed by your config, hence it's dropped. > I tried something like this to tunnel everything except LAN communication > (192.168.0.0/16): > > AllowedIPs = 0.0.0.0/0, !192.168.0.0/16 Just allow 0.0.0.0/0 and use your regular firewall to filter access on the wg1 interface. > but the FreeBSD Wireguard does not allow for that syntax. > Then I tried many things like this: > > AllowedIPs = 0.0.0.0/5, 8.0.0.0/7, 11.0.0.0/8, 12.0.0.0/6, 16.0.0.0/4, > 32.0.0.0/3, 64.0.0.0/2, 128.0.0.0/2, 192.0.0.0/9, 192.128.0.0/11, > 192.160.0.0/13, 192.169.0.0/16, 192.170.0.0/15, 192.172.0.0/14, > 192.176.0.0/12, 192.192.0.0/10, 193.0.0.0/8, 194.0.0.0/7, 196.0.0.0/6, > 200.0.0.0/5, 208.0.0.0/4 In principle that should work. Did you verify that the routes are available (netstat -rn)? Is IP forwarding enabled (on the hardware node and inside the jail)? A quick search for FreeBSD and IP forwarding suggests: sysctl -w net.inet.ip.forwarding=1 or gateway_enable="YES" in rc.conf Use tcpdump to check all interfaces (wg* and vnet*) on your home mail server and the VPS to see if packets are being sent as intended. > I’ll give a try to your proposal of `AllowedIPs = 0.0.0.0/0` plus a static > route in the Jail for 192.168.0.0/16 Check netstat -rn, a route for 192.168.2.0/24 should already be present. A route to 192.168.0.0/16 via vnet0 and (presumably) gateway 192.168.2.1 should only be necessary to reach 192.16.*.* outside of 192.168.2.*. Best regards, Gerald _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
