{ config, ... }: { networking.firewall = { allowPing = false; extraInputRules = '' ip saddr { ${config.ips.server}, ${config.ips.wgSpan}.1 } accept comment "Accept Server" ''; }; }