{ config, pkgs, ... }: { services.openssh = { enable = true; settings = { Port = 22; PasswordAuthentication = false; PermitRootLogin = "no"; Protocol = 2; X11Forwarding = true; LoginGraceTime = 30; MaxAuthTries = 3; PermitEmptyPasswords = false; IgnoreRhosts = true; HostbasedAuthentication = false; LogLevel = "INFO"; ClientAliveInterval = 300; ClientAliveCountMax = 2; }; authorizedKeysFiles = [ ".ssh/authorized_keys" ]; }; networking.firewall.allowedTCPPorts = [ 22 ]; }