On 22/09/2026 19:26, Gerald Galster via Postfix-users wrote:
patpro--- via Postfix-users <[email protected]>:
Then I tried many things like this:
AllowedIPs = 0.0.0.0/5, 8.0.0.0/7, 11.0.0.0/8, 12.0.0.0/6, 16.0.0.0/4,
32.0.0.0/3, 64.0.0.0/2, 128.0.0.0/2, 192.0.0.0/9, 192.128.0.0/11,
192.160.0.0/13, 192.169.0.0/16, 192.170.0.0/15, 192.172.0.0/14, 192.176.0.0/12,
192.192.0.0/10, 193.0.0.0/8, 194.0.0.0/7, 196.0.0.0/6, 200.0.0.0/5, 208.0.0.0/4
In principle that should work. Did you verify that the routes are available
(netstat -rn)?
Is IP forwarding enabled (on the hardware node and inside the jail)?
A quick search for FreeBSD and IP forwarding suggests:
sysctl -w net.inet.ip.forwarding=1 or gateway_enable="YES" in rc.conf
Use tcpdump to check all interfaces (wg* and vnet*) on your home mail server and
the VPS to see if packets are being sent as intended.
I’ll give a try to your proposal of `AllowedIPs = 0.0.0.0/0` plus a static
route in the Jail for 192.168.0.0/16
Check netstat -rn, a route for 192.168.2.0/24 should already be present.
A route to 192.168.0.0/16 via vnet0 and (presumably) gateway 192.168.2.1
should only be necessary to reach 192.16.*.* outside of 192.168.2.*.
Thank you Gerald for your help. I feel like it’s really off-topic so
I’ll try to keep it short.
Routes are ok and I feel like it’s a problem with Wireguard. In my test
Jail, if I do not start Wireguard, I can ping google, I can ping the
host and other systems on the same network (192.168.0.1/24). I can ping
other networks too (192.168.2.1/24, 192.168.3.0/24 ...).
If I start Wireguard, I can ping google, I cannot ping the host nor any
other systems on the same LAN (192.168.0.1/24). I can ping Jail’s
network (192.168.2.1/24) but I cannot ping other networks
(192.168.3.0/24) even if I add dedicated routes:
# netstat -rn
Routing tables
Internet:
Destination Gateway Flags Netif Expire
0.0.0.0/1 link#20 US wg1
default 192.168.2.1 UGS vnet0
VPS.ADD.RE.SS 192.168.2.1 UGHS vnet0
10.1.0.0/24 link#20 U wg1
10.1.0.2 link#18 UHS lo0
127.0.0.1 link#18 UH lo0
128.0.0.0/1 link#20 US wg1
192.168.0.0/24 link#17 US vnet0
192.168.2.0/24 link#17 U vnet0
192.168.2.111 link#18 UHS lo0
192.168.3.0/24 link#17 US vnet0
Odd.
patrick
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]