{ hosts, ... }:
{
  imports = [
    ../../nixos/profiles/services/fail2ban.nix
  ];
  services.fail2ban = {
    enable = true;
    ignoreIP = [
      hosts.mermet._module.args.ipv4
      "losurdo.sourcephile.fr"
    ];
    jails = {
      sshd.settings = {
        enabled = true;
        bantime = "5m";
        findtime = "1d";
        maxretry = "1";
        mode = "aggressive";
      };
      postfix.settings = {
        enabled = true;
        bantime = "5m";
        filter = "postfix";
        findtime = "10d";
        mode = "aggressive";
        port = 465;
      };
      postgresql.settings = {
        enabled = true;
        bantime = "5m";
        filter = "postgresql";
        findtime = "1d";
        port = 5432;
      };
    };
  };
}