September 23, 2026 at 15:26, "Gerald Galster via Postfix-users" 
<[email protected] 
mailto:[email protected]?to=%22Gerald%20Galster%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E
 > wrote:

> We're talking about different setups:
> 
> Option 1)
> Internet -> VPS data center (DNAT) -> wg tunnel -> local server -> jail 
> (Postfix)
> 
> Option 2)
> Internet -> VPS data center (Postfix) -> TLS/SMTP -> local server -> jail 
> (Postfix)

That’s not exactly right (for me at least).
Following my exchange here with Mel it appeared that doing:

jail (Postfix + signing) -> local server -> internet -> VPS (Postfix)

would be OK : no negative impact on deliverability for signing then relaying 
via VPS.

If this is confirmed, I would have 2 options to secure the transfer of my 
messages between the 2 Postfix.
Either I use Wireguard and do «plain text» between Postfix, or I ditch 
Wireguard and secure the traffic with TLS inside Postfix config.

This is what I meant when I wrote: «I’ll evaluate later if I go the wireguard 
road to secure a point-to-point tunnel or I go «on the open» with TLS 
restrictions». Sorry for the misunderstanding. 

And my fear is that a network hicup could kill the Wireguard tunnel and that 
tunnel would not come back for some reasons. With the TLS solution inside 
Postfix config, a network hicup can only delay an email for some time.

patrick
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to