September 23, 2026 at 15:26, "Gerald Galster via Postfix-users" <[email protected] mailto:[email protected]?to=%22Gerald%20Galster%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E > wrote:
> We're talking about different setups: > > Option 1) > Internet -> VPS data center (DNAT) -> wg tunnel -> local server -> jail > (Postfix) > > Option 2) > Internet -> VPS data center (Postfix) -> TLS/SMTP -> local server -> jail > (Postfix) That’s not exactly right (for me at least). Following my exchange here with Mel it appeared that doing: jail (Postfix + signing) -> local server -> internet -> VPS (Postfix) would be OK : no negative impact on deliverability for signing then relaying via VPS. If this is confirmed, I would have 2 options to secure the transfer of my messages between the 2 Postfix. Either I use Wireguard and do «plain text» between Postfix, or I ditch Wireguard and secure the traffic with TLS inside Postfix config. This is what I meant when I wrote: «I’ll evaluate later if I go the wireguard road to secure a point-to-point tunnel or I go «on the open» with TLS restrictions». Sorry for the misunderstanding. And my fear is that a network hicup could kill the Wireguard tunnel and that tunnel would not come back for some reasons. With the TLS solution inside Postfix config, a network hicup can only delay an email for some time. patrick _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
