On 2026-09-23 08:39, Viktor Dukhovni via Postfix-users wrote:
A Postfix secure channel, with fixed keys is not difficult to set up,
and requires no active maintenance.  There's no need for a separate
WireGuard tunnel.

maybe. my experience is that if I run Postfix (or almost any server) listening on an internet reachable port, my server gets scanned and all sorts of unauthorized attempts at taking advantage of whatever yet unknown vulnerability affect it bogs down my resources.

on the other hand, when the server (e.g. SSHd) is behind a Wireguard connection, the hostile scanner is answered with a refreshing silence. including on the Wireguard port on which the Wireguard server only reacts after the cryptographic credentials of the client are verified.

In 2026, my general rule is to put anything that needs not to be publicly/anonymously accessed behind Wireguard. always willing to consider exceptions to that rule.

Yuv
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to