> Viktor Dukhovni via Postfix-users <[email protected]>: > On Wed, Sep 23, 2026 at 01:56:00PM +0200, Gerald Galster via Postfix-users > wrote: > >>> Yes, the tunnel involves additional moving parts, with a Postfix secure >>> channel you just need to ensure that each side knows the other's public >>> key: >> >> I disagree on the moving parts: >> >> - it's static routing (once set up, you're good) > > The TLS secure channel is equally static. > >> - once the tunnel is up, it fails only when the underlying network fails, >> which would break TLS delivery too > > Same, for TLS, but without the addtional requirement to configure > WireGuard, and make sure that only Postfix SMTP traffic is forwarded > via the tunnel.
We're talking about different setups: Option 1) Internet -> VPS data center (DNAT) -> wg tunnel -> local server -> jail (Postfix) Option 2) Internet -> VPS data center (Postfix) -> TLS/SMTP -> local server -> jail (Postfix) I'm talking about Option 1 where the VPS merely routes traffic to a single Postfix instance (a FreeBSD jail) on a local server behind a firewall. You seem to refer to Option 2 which requires two Postfix instances — one on the VPS and one on the local server — which is inherently more work to configure and maintain than Option 1. In this case Option 1 is the better solution because it needs just one Postfix instance on a single server: everything - user management, antispam/antivirus, blacklists, user access (submission/POP/IMAP) - lives on that one server. There is no split setup where you have to configure antispam, blocklists, and hostname checks on the VPS while user management, DKIM signing, spam filtering for user submissions and data storage (IMAP/POP) live on the local server. And since there's no IMAP/POP on the VPS anyway, the local server has to be reachable regardless so users can access their mail. Best regards, Gerald _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
