{ config, pkgs, ... }: {
  services.fail2ban = {
    enable = true;
    package = pkgs.fail2ban;
    packageFirewall = pkgs.nftables;
    bantime-increment.enable = true;
    ignoreIP = [ "10.0.0.0/24" "10.3.0.0/24" ];
  };
}