On 22/09/2026 19:26, Gerald Galster via Postfix-users wrote:

patpro--- via Postfix-users <[email protected]>:

Then I tried many things like this:

AllowedIPs = 0.0.0.0/5, 8.0.0.0/7, 11.0.0.0/8, 12.0.0.0/6, 16.0.0.0/4, 
32.0.0.0/3, 64.0.0.0/2, 128.0.0.0/2, 192.0.0.0/9, 192.128.0.0/11, 
192.160.0.0/13, 192.169.0.0/16, 192.170.0.0/15, 192.172.0.0/14, 192.176.0.0/12, 
192.192.0.0/10, 193.0.0.0/8, 194.0.0.0/7, 196.0.0.0/6, 200.0.0.0/5, 208.0.0.0/4

In principle that should work. Did you verify that the routes are available 
(netstat -rn)?

Is IP forwarding enabled (on the hardware node and inside the jail)?
A quick search for FreeBSD and IP forwarding suggests:
sysctl -w net.inet.ip.forwarding=1 or gateway_enable="YES" in rc.conf

Use tcpdump to check all interfaces (wg* and vnet*) on your home mail server and
the VPS to see if packets are being sent as intended.


I’ll give a try to your proposal of `AllowedIPs = 0.0.0.0/0` plus a static 
route in the Jail for 192.168.0.0/16

Check netstat -rn, a route for 192.168.2.0/24 should already be present.
A route to 192.168.0.0/16 via vnet0 and (presumably) gateway 192.168.2.1
should only be necessary to reach 192.16.*.* outside of 192.168.2.*.


Thank you Gerald for your help. I feel like it’s really off-topic so I’ll try to keep it short.

Routes are ok and I feel like it’s a problem with Wireguard. In my test Jail, if I do not start Wireguard, I can ping google, I can ping the host and other systems on the same network (192.168.0.1/24). I can ping other networks too (192.168.2.1/24, 192.168.3.0/24 ...).

If I start Wireguard, I can ping google, I cannot ping the host nor any other systems on the same LAN (192.168.0.1/24). I can ping Jail’s network (192.168.2.1/24) but I cannot ping other networks (192.168.3.0/24) even if I add dedicated routes:

 # netstat -rn
Routing tables

Internet:
Destination        Gateway            Flags         Netif Expire
0.0.0.0/1          link#20            US              wg1
default            192.168.2.1        UGS           vnet0
VPS.ADD.RE.SS      192.168.2.1        UGHS          vnet0
10.1.0.0/24        link#20            U               wg1
10.1.0.2           link#18            UHS             lo0
127.0.0.1          link#18            UH              lo0
128.0.0.0/1        link#20            US              wg1
192.168.0.0/24     link#17            US            vnet0
192.168.2.0/24     link#17            U             vnet0
192.168.2.111      link#18            UHS             lo0
192.168.3.0/24     link#17            US            vnet0

Odd.

patrick
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to