{ config, pkgs, ... }: { services.fail2ban = { enable = true; package = pkgs.fail2ban; packageFirewall = pkgs.nftables; bantime-increment.enable = true; ignoreIP = [ config.pepe.core.network.interfaces.tailscale.net config.pepe.core.network.interfaces.lan.net ]; }; }