> patpro--- via Postfix-users <[email protected]>: > > September 23, 2026 at 17:24, "Gerald Galster via Postfix-users" > <[email protected] > mailto:[email protected]?to=%22Gerald%20Galster%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E > > wrote: > >>> Following my exchange here with Mel it appeared that doing: >>> >>> jail (Postfix + signing) -> local server -> internet -> VPS (Postfix) >>> >> This is Option 2. I hope this is not about direction, because for smtp >> sessions >> packets flow between both peers, so jail -> vps is the same as vps -> jail. > > it’s about my outbound email traffic ;) > this setup is only for emails I send.
Thanks for clarification. Then I understood it correctly: a SMTP session inherently has bidirectional packet flow between peers, e.g. you send "MAIL FROM" and receive "status code" in reply before sending "RCPT TO" and so on. The tricky part is routing the replies back to your local mail server. That needs a mechanism like DNAT, MASQUERADE or connection tracking. That's why I reversed the order in my path notation, but it is essentially the same as what you wrote. >> With WireGuard you connect "peers" using (stateless) UDP. Packets just >> start to flow again after an outage as peers stay configured. Besides >> you're probably using the WireGuard kernel module and kernels don't tend >> to crash that often, though there are user-space implementations that could >> crash in theory. In my experience that hasn't happened and even then, FreeBSD >> surely has mechanisms to restart a daemon on failure. > > > I have another WireGuard VPN on the host for my mobility needs, and once or > twice it failed me while I was away from home. This is a totally different use case. Mobile connections can be unstable and be affected by fragmentation/MTU issues and packet loss due wireless network characteristics and available signal strength. UDP is not always the best option in that scenario, which is why I mentioned OpenVPN with TCP transport as a (in this regard) more stable alternative. > I could ssh to the server and IIRC I had to reboot to restore VPN. But > FreeBSD got updates since then, and may be I’m beeing paranoid ;) You're not, just use the right tool for the job :-) >> As an alternative there is OpenVPN which supports TCP as a transport, >> but its configuration is more complex. > > > Nah, I like WG more than OpenVPN (I used OpenVPN before switching to WG). > > Anyway, now my VPN + static routes seems to be working as intended thanks to > you. So the option with no postfix on the VPS is back on the table. Glad we could fix the routing issues. Just choose the option you think is best for your situation. Best regards, Gerald _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
