> patpro--- via Postfix-users <[email protected]>:
> 
> September 23, 2026 at 15:26, "Gerald Galster via Postfix-users" 
> <[email protected] 
> mailto:[email protected]?to=%22Gerald%20Galster%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E
>  > wrote:
> 
>> We're talking about different setups:
>> 
>> Option 1)
>> Internet -> VPS data center (DNAT) -> wg tunnel -> local server -> jail 
>> (Postfix)
>> 
>> Option 2)
>> Internet -> VPS data center (Postfix) -> TLS/SMTP -> local server -> jail 
>> (Postfix)
> 
> That’s not exactly right (for me at least).

My intent was to help with your initial request:

> I wish I could just create a Wireguard tunnel that my home server could use
and
> So I guess I can rent a VPS and send my SMTP flow through the VPS IP address.

That is Option 1) and Postfix on the VPS is unnecessary in it.


> Following my exchange here with Mel it appeared that doing:
> 
> jail (Postfix + signing) -> local server -> internet -> VPS (Postfix)

This is Option 2. I hope this is not about direction, because for smtp sessions
packets flow between both peers, so jail -> vps is the same as vps -> jail.

> would be OK : no negative impact on deliverability for signing then relaying 
> via VPS.

Signing locally is OK as long as any relay (VPS) does not alter the email,
e.g. by adding a footer or modifying signed headers.

> If this is confirmed, I would have 2 options to secure the transfer of my 
> messages between the 2 Postfix.

Choose the one that suits you better.

> Either I use Wireguard and do «plain text» between Postfix,

Why "between" Postfix? With Option 1) there is no need for Postfix on the VPS 
at all.

> or I ditch Wireguard and secure the traffic with TLS inside Postfix config.

If you need to run Postfix on the VPS for any other reason, then ditch 
Wireguard.
Configuring Wireguard in addition to Postfix on the VPS adds unnecessary
complexity, as Victor wrote. Otherwise the second Postfix instance adds 
unnecessary
complexity and maintenance (including updates for dependencies like OpenSSL, 
LMDB, ...).

> This is what I meant when I wrote: «I’ll evaluate later if I go the wireguard 
> road to secure a point-to-point tunnel or I go «on the open» with TLS 
> restrictions». Sorry for the misunderstanding. 
> 
> And my fear is that a network hicup could kill the Wireguard tunnel

With WireGuard you connect "peers" using (stateless) UDP. Packets just
start to flow again after an outage as peers stay configured. Besides
you're probably using the WireGuard kernel module and kernels don't tend
to crash that often, though there are user-space implementations that could
crash in theory. In my experience that hasn't happened and even then, FreeBSD
surely has mechanisms to restart a daemon on failure.

As an alternative there is OpenVPN which supports TCP as a transport,
but its configuration is more complex.

> and that tunnel would not come back for some reasons. With the TLS solution 
> inside Postfix config, a network hicup can only delay an email for some time.

If the tunnel is down, the mail simply remains in the local mail queue with
a temporary error. Postfix periodically retries delivery, which will succeed
as soon as connectivity is restored. So with WireGuard the failure behaviour
you describe is identical (delay, not loss).

Besides there are companies like tailscale.com that base their network and
product on WireGuard, IIRC. So stability is generally not an issue.

Best regards,
Gerald
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to